EN ES PT
Back to Stats

Visual Capture

Screenshot of phishpds.com

Detection Info

https://phishpds.com/general-phishing/landing/bd5e149e-e760-4c/
Detected Brand
Microsoft
Country
International
Confidence
95%
HTTP Status
200
Report ID
f1159c4f-fe5…
Analyzed
2026-02-04 00:07

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1718164B2B040243F13C7C9B973B6BA40BBACC109D5095F797AED529E2CDBF156A62740
CONTENT ssdeep
48:nVogO7hYOn+w/cIg4+cd9oeum1ra/wd7jvl5Zpbqx1h7lWNWk7j63eqf73U47I3m:nVoFi10dg4+Teu2uWvz3W946vLcKQQ

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9c49f326cc99d926
VISUAL aHash
18001818171f1fbf
VISUAL dHash
7161713325717d78
VISUAL wHash
39181818171f1fff
VISUAL colorHash
07000000180
VISUAL cropResistant
7161713325717d78

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Credential Phishing
• Target: Microsoft users
• Method: Imitates Microsoft login page.
• Exfil: /general-phishing/submit/bd5e149e-e760-4c/
• Indicators: Domain mismatch, form, JavaScript, obfuscation.
• Risk: HIGH

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • base64_strings

📤 Form Action Targets

  • /general-phishing/submit/bd5e149e-e760-4c/

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain mismatch
The domain phishpds.com is unrelated to Microsoft.
Impersonation of Brand
The page attempts to look like a legitimate Microsoft login.
Form submission and Exfiltration
The page has a form, and extracted intel show data exfiltration is detected.

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
Microsoft users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
HTTP POST to backend
Risk Assessment
MEDIUM - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 1 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Microsoft
Official Website
https://www.microsoft.com/
Fake Service
Microsoft account login

⚔️ Attack Methodology

Primary Method: Credential Phishing

The attacker creates a fake login page that mirrors Microsoft's sign-in page, designed to trick users into entering their credentials.

Secondary Method: Obfuscation

The attacker may use base64 encoding to obfuscate malicious JavaScript code.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
phishpds.com
Registered
2024-03-05
Registrar
None
Status
ACTIVE

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.