EN ES PT
Back to Stats

Visual Capture

Screenshot of n12-pessoajuridican-et.planos-empresa.com

Detection Info

https://n12-pessoajuridican-et.planos-empresa.com/
Detected Brand
Bradesco
Country
Brazil
Confidence
100%
HTTP Status
200
Report ID
2d26c17d-8a0…
Analyzed
2026-01-25 09:19
Final URL (after redirects)
https://banco.bradesco/html/pessoajuridica/index.shtm

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T135B34221455B343722339F816BC5AB7D518B62D8A337CE07F6F44F2AABC4E54A94C21E
CONTENT ssdeep
768:SaZi4xAhMlQDXoo65ki96jL0xZoHP46JtA0+OI6:hi4xUDXoo6WiJxZoHPl+OI6

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
fc5c8b0135f848ee
VISUAL aHash
0080d0820200ff81
VISUAL dHash
1b65243666e00f2b
VISUAL wHash
01b8f082b37eff81
VISUAL colorHash
02000000006
VISUAL cropResistant
1849c9342999b136,ae8eaea2b2ae8ea6,9749858189c1c5c7,aa314d4d31452b2b,036b64343626e4aa,2b2b2b3b4c544e4b

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Bradesco banking phishing
• Target: Bradesco Net Empresa customers in Brazil
• Method: Fake Bradesco website stealing login credentials
• Exfil: Unknown where stolen credentials are sent, but likely to a malicious server
• Indicators: Domain does not contain brand name, Obfuscated JS, forms, JavaScript form submission, domain creation date is in the future
• Risk: CRITICAL - Real-time credential theft

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • js_packer
  • base64_strings

🎯 Kit Endpoints

  • https://www.ne12.bradesconetempresa.b.br/ibpjlogin/login.jsf
  • https://policies.google.com/technologies/partner-sites

📡 API Calls Detected

  • GET
  • POST
  • https://www.google.com/ccm/geo
  • get

📊 Risk Score Breakdown

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, Card Stealer, and Banking kits with real-time form interception capabilities.
High Obfuscation
1658 obfuscation techniques detected, indicating deliberate evasion of analysis and security tools.
Brand Impersonation
Impersonates Bradesco, a major Brazilian bank, targeting corporate clients (Pessoa Jurídica).
Large Malicious Payload
Total JavaScript size of 3.51 MB, suggesting complex malicious functionality.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Bradesco users (Brazil)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
CRITICAL - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 1658 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bradesco
Official Website
https://banco.bradesco/
Fake Service
Corporate Banking plans (Planos Empresa - Pessoa Jurídica)

⚔️ Attack Methodology

Primary Method: Credential Harvesting and OTP Interception

The phishing kit captures corporate Banking credentials through fake login forms. It then intercepts one-time passwords (OTPs) via a secondary form, enabling real-time account takeover and unauthorized transactions.

Secondary Method: Card and Personal Information Theft

Additional forms are designed to harvest credit card details and personal information, likely for financial fraud or identity theft.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
n12-pessoajuridican-et.planos-empresa.com
Registered
2025-01-18 04:27:13+00:00
Registrar
Sav.com, LLC
Status
Active (372 days old)

🦠 Malicious Files

Main File
File Size

Large JavaScript payload containing credential harvesting, OTP interception, and card stealing functionality.

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Sophistication Level
Advanced
Total Code Size
3.5 MB

🔗 API Endpoints Detected

Other
359
Backend API
2

🔐 Obfuscation Detected

  • : Moderate
  • : Heavy
  • : None
  • : Light
  • : Moderate
  • : Moderate
  • : Moderate
  • : Moderate
  • : Moderate
  • : Light
  • : Moderate
  • : Moderate
  • : Moderate
  • : Moderate

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.