Known malicious kithighother

Crypto task-scam (刷单) app — a76e9b67 module (content anchor)

family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

Provenance

Added: 2026-07-17 21:33
2026-07-17: content-anchor for the webapp-run.us TP class (health-alert audit). Pairs with DB pattern crypto_task_scam_app (migration 20260701) + bedrock v114 unranked-gated floor. node_count>=32 anchors only (generic-helper-safe).

Sightings (3)

HostScanScriptMatchWhen
webapp-run.usa306f270https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:appBootstrapstructure2026-07-17 22:27
webapp-run.us993bbf29https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:appBootstrapstructure2026-07-17 21:48
webapp-run.us5785c102https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:appBootstrapstructure2026-07-17 21:41