EN ES PT
Back to Stats

Captura Visual

Screenshot of auditoria-talao.com

Información de Detección

https://auditoria-talao.com
Detected Brand
Bradesco
Country
Brazil
Confianza
100%
HTTP Status
N/A
Report ID
0cfb0c98-1ea…
Analyzed
2026-01-30 07:28
Final URL (after redirects)
https://auditoria-talao.com/acess.php?token=1289293598697792331d1e86.25250462&cliente_1289293598697792331d1e86.25250462

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T142B257A0C685683349A787D5A1F79B0772E6522EF7331A8103FAD79E4FCEC40E825574
CONTENT ssdeep
384:9FZivlEmVB9gYyUEvtLb1Q1YYSSArsErkyakKbEtieR/keDiUuSgxeeouBqSXWrJ:9Fv2+1gawutDQwreL1XWrxWOWYT

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
96676d989267c952
VISUAL aHash
0000363e0e0e0000
VISUAL dHash
3e5e4ccc5c3c767c
VISUAL wHash
06067e7e3e1e0e0f
VISUAL colorHash
0b006000000
VISUAL cropResistant
c7b4b55715b5ebca,8eb4b8f2bcb2b28c,3e5e4ccc5c3c767c

Análisis de Código

Risk Score 74/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer

🔬 Threat Analysis Report

• Amenaza: Kit de phishing para robo de credenciales
• Objetivo: Clientes de Bradesco en Brasil
• Método: Página falsa de auditoría de cheques que roba credenciales de inicio de sesión
• Exfil: Datos probablemente enviados al servidor del atacante
• Indicadores: Dominio no coincidente, registro de dominio reciente, JavaScript ofuscado
• Riesgo: ALTO - Robo inmediato de credenciales

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • board/chat/chat.php

📊 Desglose de Puntuación de Riesgo

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester and OTP Stealer kits with real-time form interception capabilities.
High Obfuscation
129 obfuscation techniques detected in JavaScript files, indicating deliberate evasion of analysis.
Brand Impersonation
Impersonates Bradesco, a major Brazilian bank, targeting sensitive financial credentials.
Form Fields
4 form fields detected, including 'Usuário' and 'Senha', designed to harvest login credentials.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Two-Factor Authentication Stealer
Objetivo
Bradesco users (Brazil)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer
  • 129 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Bradesco
Official Website
https://banco.bradesco
Fake Service
Bradesco account login portal

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The phishing kit captures user credentials (username and password) via fake login forms mimicking Bradesco's authentication portal. Submitted data is exfiltrated in real-time to attacker-controlled infrastructure.

Secondary Method: OTP Stealer

The kit includes functionality to intercept one-time passwords (OTPs) by prompting users to enter OTPs under the guise of 'security verification', enabling account takeover.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
auditoria-talao.com
Registered
2026-01-20 15:49:12+00:00
Registrar
HOSTINGER operations, UAB
Estado
Recently registered (6 days old)

🦠 Malicious Files

Main File
File Size

Highly obfuscated JavaScript file containing credential harvesting and OTP interception logic.

📊 Diagrama de Flujo de Ataque

┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL                         │
│    - Email mimics Bradesco branding                      │
│    - Contains link to fake Banking page                   │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BRADESCO PAGE                      │
│    - Fake login form appears legitimate                  │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - Victim enters Banking credentials                   │
│    - Form captures input data                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Data received by attacker-controlled server         │
└──────────────────────────────────────────────────────────┘

🔬 JavaScript Deep Analysis

Operator Language
Portuguese (1%)
Total Code Size
116,7 KB

🔐 Obfuscation Detected

  • : Light
  • : Light
  • : None
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL                         │
│    - Email mimics Bradesco branding                      │
│    - Contains link to fake Banking page                   │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BRADESCO PAGE                      │
│    - Fake login form appears legitimate                  │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - Victim enters Banking credentials                   │
│    - Form captures input data                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Data received by attacker-controlled server         │
└──────────────────────────────────────────────────────────┘

🎯 Malicious Files Identified

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.