EN ES PT
Back to Stats

Visual Capture

Screenshot of govptls.cfd

Detection Info

https://govptls.cfd/
Detected Brand
Portuguese Government
Country
Portugal
Confidence
100%
HTTP Status
200
Report ID
9da35a5c-14a…
Analyzed
2026-01-23 09:58
Final URL (after redirects)
https://govptls.cfd/#/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1B0532AFD914036F2941787E8E724B74AA157703FEB5E494CA3FC17802F99C762A8C9A4
CONTENT ssdeep
768:XFpmym6mDi3Cz3C73C+zQxaETXcTRBCapBfdR9BPqXJJv4yFcC+hppmhHVGhuuhK:VA2P3BCapBJBPqXJ5D4hPmhHkhuuhK

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c9b616493ca936cb
VISUAL aHash
ffffffd1f8f8f800
VISUAL dHash
330f2c1332321212
VISUAL wHash
ffe7ff80d0d0e000
VISUAL colorHash
0f0000001c0
VISUAL cropResistant
330f281332321212,000008b2b2320c10,32321232121212d2

Code Analysis

Risk Score 92/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing kit
• Target: Portuguese government service users
• Method: Fake login form stealing user credentials
• Exfil: Data sent to unknown server
• Indicators: Domain mismatch, newly registered domain, obfuscated JavaScript
• Risk: HIGH - Immediate credential theft

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • https://ipapi.co/json/
  • POST

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.