EN ES PT
Back to Stats

Visual Capture

Screenshot of rootsystemsbd.com

Detection Info

http://rootsystemsbd.com/SharePointFileProposal
Detected Brand
Microsoft Sharepoint
Country
International
Confidence
100%
HTTP Status
200
Report ID
c63184e4-80e…
Analyzed
2026-01-23 23:43
Final URL (after redirects)
http://rootsystemsbd.com/SharePointFileProposal/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1BFD19036A020002216BB8B813DD9565972EBF348CF5144D095EDCBBD9FDADA4E8C72D7
CONTENT ssdeep
192:49kRUxCgHCg7JCgHCg7PP8bEiOkubE3cdbE3bbbKb07t5S/lbEroofdbr4bLkBCk:wkRUx3N3z8giOkug3Qg33Gmt5S/lgUo7

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b0646431cb9bcf9a
VISUAL aHash
c3c3c3ffffffdfff
VISUAL dHash
8696867179699979
VISUAL wHash
0000003c3c3c1c3c
VISUAL colorHash
07006000000
VISUAL cropResistant
8696867179699979,0c0c4c3392ca9aba

Code Analysis

Risk Score 85/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester šŸŽ£ OTP Stealer šŸŽ£ Card Stealer šŸŽ£ Banking šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Credential harvesting phishing kit
• Target: Microsoft Sharepoint users
• Method: Fake login form stealing user credentials
• Exfil: Data sent to unknown server
• Indicators: Domain mismatch, obfuscated JavaScript, form submission
• Risk: HIGH - Immediate credential theft

šŸ”’ Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unicode_escape
  • base64_strings

šŸŽÆ Kit Endpoints

  • https://miniblog.girondenumerique.fr
  • https://connect.girondenumerique.fr/realms/GlobalGN/login-actions/authenticate?session_code=LHaBGUsGWhFyoVsLg_Zl_uGBExM-nUBrOlWE8fIqQpw&execution=da9ddeda-4f53-429b-bfd6-f0d8edec9029&client_id=url-shortener&tab_id=Hj-oVdVszQg

šŸ“” API Calls Detected

  • POST
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.