EN ES PT
Back to Stats

Visual Capture

Screenshot of login.microsoftonline.us.office.rp1.abangaritest.govshn.net

Detection Info

https://login.microsoftonline.us.office.rp1.abangaritest.govshn.net/office365.us/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https://pod51500.office365.us.office.rp1.abangaritest.govshn.net/owa/&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=0&msaredir=0&client-request-id=1220ab59-f287-6f2a-5e38-e1c65cee26e6&protectedtoken=true&claims=%7B%22id_token%22:%7B%22xms_cc%22:%7B%22values%22:[%22CP1%22]%7D%7D%7D&domain_hint=office365.us.office.rp1.abangaritest.govshn.net&nonce=637772685616231379.d95cc639-2e44-4cf6-9cc0-0d98f6a0e15a&state=DctBDsIgEEBR0KM0cUcLDMx0Fo1nIQMkjTWTqNXry-L93bfGmOtwGawfMYRARBHXjAEjBCCeK2cRBHaxpeSSdHQs4p2vvHYsvoVc7HinRX9lub9aOZ6b9r5LA8zz-b5966bn51B9_AE
Detected Brand
Microsoft
Country
International
Confidence
100%
HTTP Status
200
Report ID
1b94a14e-4d3…
Analyzed
2025-12-28 20:15
Final URL (after redirects)
https://login.microsoftonline.us.office.rp1.abangaritest.govshn.net/office365.us/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https://pod51500.office365.us.office.rp1.abangaritest.govshn.net/owa/&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=0&msaredir=0&client-request-id=1220ab59-f287-6f2a-5e38-e1c65cee26e6&protectedtoken=true&claims=%7B%22id_token%22:%7B%22xms_cc%22:%7B%22values%22:[%22CP1%22]%7D%7D%7D&domain_hint=office365.us.office.rp1.abangaritest.govshn.net&nonce=637772685616231379.d95cc639-2e44-4cf6-9cc0-0d98f6a0e15a&state=DctBDsIgEEBR0KM0cUcLDMx0Fo1nIQMkjTWTqNXry-L93bfGmOtwGawfMYRARBHXjAEjBCCeK2cRBHaxpeSSdHQs4p2vvHYsvoVc7HinRX9lub9aOZ6b9r5LA8zz-b5966bn51B9_AE&sso_reload=true

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C552B5B0B040392FC28BC2FDF275F5415B66A244C306CB76ED9CC69D0AE6A28ED63750
CONTENT ssdeep
192:sjJ6YxHW9Zc7BQF4ERnMcV3JzimowUAO5PUISznkAieQAlz8G+J:vYl7BY4ElMa3DUNUIankjeQaJ+J

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
835974734e667319
VISUAL aHash
001c0c3f2f2f3f37
VISUAL dHash
88f0d8ebdbd8c6e6
VISUAL wHash
001c0e3f2f2f3737

Code Analysis

Risk Score 100/100
Threat Level CRITICAL
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing attack
• Target: Microsoft users, specifically those related to the 'office365.us' tenant
• Method: Presents a fake Microsoft sign-in page to steal credentials
• Exfil: Unknown, likely to a malicious server controlled by the attacker
• Indicators: Domain name doesn't match the official Microsoft domain; unusual domain structure; error message targeting 'office365.us' tenant.
• Risk: HIGH - Real-time credential theft possible; could lead to account compromise and data breach.
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.