EN ES PT
Back to Stats

Visual Capture

Screenshot of consultaonline.top

Detection Info

https://consultaonline.top/
Detected Brand
Receita Federal
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
7515bc9e-e59…
Analyzed
2026-06-15 10:39

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T17501209602444A2F469292C0887BD73F22C5C724EAAB5E50BBF903BC45DCE17CC7F489
CONTENT ssdeep
12:hRwMyLSLpAe2M0/7wl/MJ2N47Fmk7etjq51IhL7LHdK6:hR/OupBE/7weYkRW7LHdt

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
dd1972f3c8898933
VISUAL aHash
0000181818180000
VISUAL dHash
890c32323232cc84
VISUAL wHash
61821c1a3ebafee2
VISUAL colorHash
000000001c0
VISUAL cropResistant
b2cc8c9696332b9a,890c32323232cc84

Code Analysis

Threat Level ALTO
⚠️ Phishing Confirmed

📊 Risk Score Breakdown

Total Risk Score
40/100

🔬 Comprehensive Threat Analysis

Threat Type
Receita Federal Phishing Landing Page
Target
Receita Federal users
Attack Method
Phishing webpage
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
LOW - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

🏢 Brand Impersonation Analysis

Impersonated Brand
Receita Federal
Official Website
N/A
Fake Service
Credential harvesting service

⚔️ Attack Methodology

Primary Method: Brand Impersonation Redirect

Impersonates Receita Federal to build victim trust through search engine manipulation or malicious advertisements. Often redirects to credential theft pages or serves malware disguised as legitimate software.

Secondary Method: Standard Phishing Techniques

Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
consultaonline.top
Registered
2026-04-02 01:05:20+00:00
Registrar
NameSilo, LLC
Status
Active (74 days old)

Hosting Information

Provider
NameSilo, LLC
ASN

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.