EN ES PT
Back to Stats

Visual Capture

Screenshot of sicrediexpoabf.com.br

Detection Info

https://sicrediexpoabf.com.br
Detected Brand
Sicredi
Country
International
Confidence
100%
HTTP Status
200
Report ID
a355a7ae-25f…
Analyzed
2026-03-01 21:37
Final URL (after redirects)
https://sicrediexpoabf.com.br/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T176C29830204067BB656B4DE872A0F3AB61E9970DC45BD006F7B882A62BCECF1C713785
CONTENT ssdeep
768:CfajONX8XjX9X4XBX71XCfYS9HKEzGdTdnH5b88m9:U8KvNc

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
d338c33acb363cc1
VISUAL aHash
00000000000e7e7e
VISUAL dHash
19989030702cc8c0
VISUAL wHash
88c898b8187e7e7e
VISUAL colorHash
01040006200
VISUAL cropResistant
6dacad9594e8a425,19989030702cc8c0

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Sicredi Customers
• Method: Impersonation with a form to collect information and offering prize.
• Exfil: Form Submission
• Indicators: Domain mismatch, Javascript obfuscation, form for personal data.
• Risk: High

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • hex_escape
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • w
  • https://www.google.com/ccm/geo

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not match the legitimate Sicredi domain.
Active Phishing Kit
The site has a form for collecting personal information and javascript obfuscation.
Impersonation
The site uses Sicredi's branding to impersonate the brand
Reward Tactics
Offers a prize, which is a common phishing tactic.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Sicredi users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 72 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Sicredi
Fake Service
ABF Franchising Expo 2025

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker is using a fake website that imitates Sicredi's branding to lure victims into providing personal information via a form, which can be used for identity theft or further phishing attacks.

Secondary Method: Social Engineering

The promise of a prize and the use of the Sicredi logo are methods of social engineering, preying on users' trust.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
sicrediexpoabf.com.br
Registered
None
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.