EN ES PT
Back to Stats

Visual Capture

Screenshot of gov-declarar.com

Detection Info

https://gov-declarar.com/
Detected Brand
Governo de Portugal
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
c486b964-46a…
Analyzed
2026-04-08 00:14

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D782A4B05084DE33908743D8D279672732E58386E64A0209F7F8C7F897EECA5ED27569
CONTENT ssdeep
384:gdwgTseJceJeeJ+eJg46fHQ1wdDUeZvwM38vi4ezaDHxKumcHZ6J:gdwgTsmcmem+mg4MwWdDNiM3v9kKMAJ

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b1be4e9c19ce4c31
VISUAL aHash
ffffffffffff0000
VISUAL dHash
231c1c189c00c4c0
VISUAL wHash
81c7c7cfcfff0000
VISUAL colorHash
0e001000180
VISUAL cropResistant
330c1c1818940000,30c0c4e410483030

Code Analysis

Risk Score 65/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 Banking

📡 API Calls Detected

  • submit.php?action=partial
  • submit.php?action=final

📊 Risk Score Breakdown

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected kit types: Credential Harvester, Banking

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Governo de Portugal users
Attack Method
Phishing webpage
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, Banking

🏢 Brand Impersonation Analysis

Impersonated Brand
Governo de Portugal
Official Website
N/A
Fake Service
Banking/payment service

⚔️ Attack Methodology

Primary Method: Credential Harvesting

Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.

Secondary Method: Client-Side Form Interception

JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
gov-declarar.com
Registered
2026-04-04 08:31:22+00:00
Registrar
OwnRegistrar, Inc.
Status
Recently registered (3 days old)

Hosting Information

Provider
OwnRegistrar, Inc.
ASN

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.