brandreview-itau.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of brandreview-itau.app
The domain brandreview-itau.app appears to present itself as a Portuguese-language internal branding or review portal called "Brand Review." The page title ("Entrar — Brand Review"), the visible login form, and the wording about submitting and evaluating materials suggest a web application intended for account access rather than a public informational website.
Based on the domain string and the page design, the site appears to reference Itaú branding and may be attempting to look related to the Brazilian financial brand associated with itau.com.br. The screenshot shows an Itaú-style logo area, internal-use wording ("uso interno"), and a sign-in interface with email/password fields and a Google login option, which could indicate an employee or partner portal theme.
However, the domain itself is not the primary official Itaú domain shown in the similarity data. Combined with its very recent registration, the site may be presenting itself as a branded internal platform without clear public evidence on the page of official ownership or corporate attribution.
Safety Assessment for brandreview-itau.app
This domain shows several notable risk indicators at the time of this scan. It was flagged by 1 out of 91 security engines for phishing, and the domain closely resembles itau.com.br in a way that may indicate a look-alike website. The screenshot reinforces that concern: it uses Itaú-related branding cues while presenting a login page that asks for credentials, which is a common pattern in credential-harvesting campaigns.
Additional context increases the level of caution. The domain is only 1 day old, has no observed traffic ranking, and the similarity check marked it as suspect with multiple red flags. Although the malware scan did not detect malicious files and major threat databases were clean at the time of this scan, newly created phishing pages often appear before broader blocklist coverage catches up.
Taken together, the branding resemblance, login-focused design, and extremely recent registration outweigh the otherwise limited malware findings. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, expiring on 2026-09-25. It appears to be behind Cloudflare infrastructure, with the observed server IP geolocating to Frankfurt am Main, Germany. The domain uses Name.com nameservers and its DNSSEC status is unsigned.
From a technical scanning perspective, no malicious files, flagged external links, or iframe-based threats were detected in the sampled content, and blacklist checks were clean at the time of this scan. Even so, the combination of a newly registered domain, a credential-collection interface, and branding that appears to imitate a well-known financial institution may be more significant than the absence of file-based malware indicators alone.
Share your experience with this website. Was it safe? Did you encounter any issues?