EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://watco.microsoft-notifcation.com/wa4d1737192/78b65c00e4993df97452c88c/index.php
Detected Brand
Microsoft
Country
International
Confidence
100%
HTTP Status
200
Report ID
f91fdde5-8ee…
Analyzed
2026-08-16 22:17

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T17F81A591906C1F37614384D9B5A13B4F43D856C98702AF1CEFB854ED9ACFEA4992218E
CONTENT ssdeep
96:PxhkLq8Cfgv5y38TNuzduhkD1zkLYdwdDd/VkL93qh4:PJfgwzUn4

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
989cc9336767564c
VISUAL aHash
ffff1e0000000000
VISUAL dHash
f0f0f070f8f8d86a
VISUAL wHash
ffff7f08000000ff
VISUAL colorHash
13c00010000
VISUAL cropResistant
30e0e4e4e4e4c0c4,0240596312800000,f0f0f070f8f9d86a

Code Analysis

Risk Score 77/100
Threat Level BAJO
🎣 Credential Harvester 🎣 Banking

🔬 Threat Analysis Report

• Threat: None (Phishing Simulation)
• Target: Microsoft user credentials
• Method: Simulated login page
• Exfil: Internal simulation database
• Indicators: Clear disclaimer in footer identifying it as a training tool
• Risk: Low (Authorized internal testing)

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • base64_strings

📤 Form Action Targets

  • index.php

📊 Risk Score Breakdown

Total Risk Score
5/100

Contributing Factors

Security Training
Authorized simulation identified by footer disclosure

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Microsoft users (International)
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
HTTP POST to backend
Risk Assessment
HIGH - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, Banking
  • 36 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Microsoft
Official Website
https://www.microsoft.com
Fake Service
Simulated Microsoft Login

⚔️ Attack Methodology

Primary Method: Security Awareness Training

Controlled phishing simulation for employee testing.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
microsoft-notifcation.com
Registered
2022-01-06
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.