Known malicious kithighphishing

ConsentFix — lure domains from the first public campaign (Dec 2025)

family: consentfix-oauth-code-2026-09

Lure domains published by Push Security for the first observed ConsentFix campaign, which gated the page behind a fake Cloudflare Turnstile asking for a business email address before showing the Azure CLI sign-in and the 'paste the localhost URL' instructions.

Anchors

SMQL queryrun
domain:trustpointassurance.com OR domain:fastwaycheck.com OR domain:previewcentral.com OR contacted_host:trustpointassurance.com OR contacted_host:fastwaycheck.com OR contacted_host:previewcentral.com

Provenance

Added: 2026-09-25 12:18
Matches a page scanned directly on one of these exact domains, or any page that requested one. Exact hostnames only. These domains are from late 2025 and are likely retired; the structural rule in this family is the durable anchor.

Sightings (3)

HostScanScriptMatchWhen
fastwaycheck.comf00e8657…—query2026-09-25 12:46
previewcentral.com34deb8a3…—query2026-09-25 12:46
trustpointassurance.comf5fb0c38…—query2026-09-25 12:46