EN ES PT
Back to Stats
100 Risk Score

High Risk

Threat Level: ALTO • Impersonating: Microsoft

⚠ Risk Factors

  • Brand impersonation of Microsoft on non-official domain
  • JavaScript obfuscation detected (8 patterns)
  • Credential harvesting indicators detected
  • OTP/2FA stealing indicators detected
  • WebSocket connection for real-time C2 communication

Visual Capture

Screenshot of economic-poet-b50.notion.site

Detection Info

https://economic-poet-b50.notion.site/Microsoft-Office-365-7782e9e7e96e4bcd8a7a528b7505a1c3
Detected Brand
Microsoft
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
3fa881d0-dab…
Analyzed
2026-01-09 22:36

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T11AC2A320C211344D821BE654F5E2A34EA223D30FD70645F8ABB953A6D7CF9E408B36ED
CONTENT ssdeep
384:msXB9wcRvCTa8UjTRLLz2rmwwSbZVCEnyCjBYh0NNfzcGAqCwqCCcB9rzCSUuU5:1XXwS0VUnRLLz2rmwwupBYubcGtiT5

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
810151d59fdf9785
VISUAL aHash
0e0029ffffffffff
VISUAL dHash
dcd2cb6030600000
VISUAL wHash
0000003f0f3fffff
VISUAL colorHash
07000019040
VISUAL cropResistant
dcd2cb6030600000,0000000000000000,0105112326252602

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info
WebSocket C2

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings