EN ES PT
Back to Stats

Visual Capture

Screenshot of rootsystemsbd.com

Detection Info

http://rootsystemsbd.com/SharePointFileProposal
Detected Brand
Microsoft Sharepoint
Country
International
Confidence
100%
HTTP Status
200
Report ID
d11643cd-50f…
Analyzed
2026-01-01 15:57
Final URL (after redirects)
http://rootsystemsbd.com/SharePointFileProposal/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1BFD19036A020002216BB8B813DD9565972EBF348CF5144D095EDCBBD9FDADA4E8C72D7
CONTENT ssdeep
192:49kRUxCgHCg7JCgHCg7PP8bEiOkubE3cdbE3bbbKb07t5S/lbEroofdbr4bLkBCk:wkRUx3N3z8giOkug3Qg33Gmt5S/lgUo7

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b0646431cb9bcf9a
VISUAL aHash
c3c3c3ffffffdfff
VISUAL dHash
8696867179699979
VISUAL wHash
0000003c3c3c1c3c
VISUAL colorHash
07006000000
VISUAL cropResistant
8696867179699979,0c0c4c3392ca9aba

Code Analysis

Risk Score 95/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting Sharepoint users.
• Target: Microsoft Sharepoint users are targeted.
• Method: A fake Sharepoint notification with a login form attempts to steal user credentials.
• Exfil: Likely exfiltration through JavaScript form submission to an external server or database.
• Indicators: Domain mismatch, presence of a form, and JavaScript form submission detected.
• Risk: HIGH - Real-time credential theft is likely if a user submits their information.

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • POST
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.