EN ES PT
Back to Stats

Visual Capture

Screenshot of loginservice.app

Detection Info

https://loginservice.app/page/e1cf8597a15437bfe6294edfbccc4603594ada4f?systemclick=true&type=2
Detected Brand
Microsoft
Country
International
Confidence
95%
HTTP Status
200
Report ID
1fb5d198-b17…
Analyzed
2026-02-17 07:37
Final URL (after redirects)
https://www.loginservice.app/page/e1cf8597a15437bfe6294edfbccc4603594ada4f?systemclick=true&type=2

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1EAB1947B131887EBCAC4978C3F993B9D33618584F6B20280879358D6AC49EB7F439D20
CONTENT ssdeep
96:nrlHlJ4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDmttK/8P5d:5HkoSBjlevudl9nH45d

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9c4b6326d999e466
VISUAL aHash
180018181d1f0f9f
VISUAL dHash
7161713331347939
VISUAL wHash
191818181f1f1fff
VISUAL colorHash
07001000180
VISUAL cropResistant
7161713331347939

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Microsoft users
• Method: Credential harvesting
• Exfil: Unknown (likely via base64 encoded strings)
• Indicators: Domain mismatch, login form
• Risk: HIGH

🔒 Obfuscation Detected

  • base64_strings

🎯 Kit Endpoints

  • /assets/landingpage/2dc441f89965559f8d3abb4701b1a38cd67e931e/login/

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not belong to Microsoft.
Impersonation
The page mimics Microsoft's login interface.
Form with sensitive fields
The form requests a password.
Obfuscation Detected
Use of base64 strings detected.

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
Microsoft users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 1 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Microsoft
Official Website
https://www.microsoft.com/
Fake Service
Microsoft Login

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker attempts to steal Microsoft account credentials by presenting a fake login form that redirects to their server. Users entering their login details have them captured.

Secondary Method: Obfuscation

JavaScript code (likely used for exfiltration) uses base64 encoding to conceal its malicious functionality, making it more difficult to analyze and detect.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
loginservice.app
Registered
Unknown
Registrar
Unknown
Status
Unknown

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.