Known malicious kithighother
Crypto task-scam (刷单) app — 5fa7c18e module (content anchor)
family: crypto-task-scam-appflow
Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.
Anchors
Provenance
Added: 2026-07-17 21:33
2026-07-17: content-anchor for the webapp-run.us TP class (health-alert audit). Pairs with DB pattern crypto_task_scam_app (migration 20260701) + bedrock v114 unranked-gated floor. node_count>=32 anchors only (generic-helper-safe).
Sightings (3)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| webapp-run.us | a306f270… | https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:updateDepositStatus | structure | 2026-07-17 22:27 |
| webapp-run.us | 993bbf29… | https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:updateDepositStatus | structure | 2026-07-17 21:48 |
| webapp-run.us | 5785c102… | https://webapp-run.us/assets/index-BKJUIWv9.js#webpack-module:updateDepositStatus | structure | 2026-07-17 21:41 |