EN ES PT
Back to Stats

Visual Capture

Screenshot of lead.simuladorbndes.com

Detection Info

https://lead.simuladorbndes.com/
Detected Brand
BNDES
Country
Brazil
Confidence
95%
HTTP Status
200
Report ID
d2bc0035-804…
Analyzed
2026-06-18 10:39
Final URL (after redirects)
https://lead.simuladorbndes.com/onboarding

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T111412E3165E1016B063B9AC07765AB2FA4D2D708EA538E4953BD47CBDBD1C80DCE21B4
CONTENT ssdeep
48:D8a9uVWMbaVDwZg21orQ7wNUntO2OXfmJ:D8a9sPuBSor3NUcjXeJ

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b0251b4f4f64656d
VISUAL aHash
00ffc3ffffffffef
VISUAL dHash
d610961600b0b49e
VISUAL wHash
00c3c3ffffff0000
VISUAL colorHash
070000001c0
VISUAL cropResistant
9e16960004b0969e,0000400020004000,0010083032300810

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Financial Phishing
• Target: BNDES users
• Method: Impersonation to collect lead data
• Exfil: JavaScript based submission
• Indicators: New domain, obfuscated code
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • /privacy

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

Recent Domain
Domain is only 4 days old
Brand Impersonation
Unauthorized use of BNDES branding
Code Obfuscation
Use of fromCharCode to hide logic

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
BNDES users (Brazil)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 6 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
BNDES
Official Website
https://www.bndes.gov.br
Fake Service
Loan Simulation

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential/Data Harvesting

Uses a 'loan simulator' funnel to trick users into entering business and contact details for illicit solicitation.

Secondary Method: Brand Impersonation

Mimics the visual identity of BNDES to establish false trust.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
simuladorbndes.com
Registered
2026-06-13
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.