EN ES PT
Back to Stats

Captura Visual

Screenshot of loginservice.app

Información de Detección

https://loginservice.app/page/e1cf8597a15437bfe6294edfbccc4603594ada4f?systemclick=true&type=2
Detected Brand
Microsoft
Country
International
Confianza
95%
HTTP Status
200
Report ID
1fb5d198-b17…
Analyzed
2026-02-17 07:37
Final URL (after redirects)
https://www.loginservice.app/page/e1cf8597a15437bfe6294edfbccc4603594ada4f?systemclick=true&type=2

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1EAB1947B131887EBCAC4978C3F993B9D33618584F6B20280879358D6AC49EB7F439D20
CONTENT ssdeep
96:nrlHlJ4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDmttK/8P5d:5HkoSBjlevudl9nH45d

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9c4b6326d999e466
VISUAL aHash
180018181d1f0f9f
VISUAL dHash
7161713331347939
VISUAL wHash
191818181f1f1fff
VISUAL colorHash
07001000180
VISUAL cropResistant
7161713331347939

Análisis de Código

Risk Score 53/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Amenaza: Phishing
• Objetivo: Usuarios de Microsoft
• Método: Recopilación de credenciales
• Exfil: Desconocido (probablemente a través de cadenas codificadas en base64)
• Indicadores: Discordancia de dominio, formulario de inicio de sesión
• Riesgo: ALTO

🔒 Obfuscation Detected

  • base64_strings

🎯 Kit Endpoints

  • /assets/landingpage/2dc441f89965559f8d3abb4701b1a38cd67e931e/login/

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not belong to Microsoft.
Impersonation
The page mimics Microsoft's login interface.
Form with sensitive fields
The form requests a password.
Obfuscation Detected
Use of base64 strings detected.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Credential Harvesting Kit
Objetivo
Microsoft users (International)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 1 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Microsoft
Official Website
https://www.microsoft.com/
Fake Service
Microsoft Login

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The attacker attempts to steal Microsoft account credentials by presenting a fake login form that redirects to their server. Users entering their login details have them captured.

Secondary Method: Obfuscation

JavaScript code (likely used for exfiltration) uses base64 encoding to conceal its malicious functionality, making it more difficult to analyze and detect.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
loginservice.app
Registered
Unknown
Registrar
Unknown
Estado
Unknown

🤖 AI-Extracted Threat Intelligence

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.