EN ES PT
Back to Stats

Captura Visual

Screenshot of auditoria-talao.com

Informações de Detecção

https://auditoria-talao.com
Detected Brand
Bradesco
Country
Brazil
Confiança
100%
HTTP Status
N/A
Report ID
0cfb0c98-1ea…
Analyzed
2026-01-30 07:28
Final URL (after redirects)
https://auditoria-talao.com/acess.php?token=1289293598697792331d1e86.25250462&cliente_1289293598697792331d1e86.25250462

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T142B257A0C685683349A787D5A1F79B0772E6522EF7331A8103FAD79E4FCEC40E825574
CONTENT ssdeep
384:9FZivlEmVB9gYyUEvtLb1Q1YYSSArsErkyakKbEtieR/keDiUuSgxeeouBqSXWrJ:9Fv2+1gawutDQwreL1XWrxWOWYT

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
96676d989267c952
VISUAL aHash
0000363e0e0e0000
VISUAL dHash
3e5e4ccc5c3c767c
VISUAL wHash
06067e7e3e1e0e0f
VISUAL colorHash
0b006000000
VISUAL cropResistant
c7b4b55715b5ebca,8eb4b8f2bcb2b28c,3e5e4ccc5c3c767c

Análise de Código

Risk Score 74/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer

🔬 Threat Analysis Report

• Ameaça: Kit de phishing para roubo de credenciais
• Alvo: Clientes do Bradesco no Brasil
• Método: Página falsa de auditoria de cheques que rouba credenciais de login
• Exfil: Dados provavelmente enviados para o servidor do atacante
• Indicadores: Domínio não coincidente, registro de domínio recente, JavaScript ofuscado
• Risco: ALTO - Roubo imediato de credenciais

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • board/chat/chat.php

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester and OTP Stealer kits with real-time form interception capabilities.
High Obfuscation
129 obfuscation techniques detected in JavaScript files, indicating deliberate evasion of analysis.
Brand Impersonation
Impersonates Bradesco, a major Brazilian bank, targeting sensitive financial credentials.
Form Fields
4 form fields detected, including 'Usuário' and 'Senha', designed to harvest login credentials.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Two-Factor Authentication Stealer
Alvo
Bradesco users (Brazil)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer
  • 129 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Bradesco
Official Website
https://banco.bradesco
Fake Service
Bradesco account login portal

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting

The phishing kit captures user credentials (username and password) via fake login forms mimicking Bradesco's authentication portal. Submitted data is exfiltrated in real-time to attacker-controlled infrastructure.

Secondary Method: OTP Stealer

The kit includes functionality to intercept one-time passwords (OTPs) by prompting users to enter OTPs under the guise of 'security verification', enabling account takeover.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
auditoria-talao.com
Registered
2026-01-20 15:49:12+00:00
Registrar
HOSTINGER operations, UAB
Estado
Recently registered (6 days old)

🦠 Malicious Files

Main File
File Size

Highly obfuscated JavaScript file containing credential harvesting and OTP interception logic.

📊 Diagrama de Fluxo de Ataque

┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL                         │
│    - Email mimics Bradesco branding                      │
│    - Contains link to fake Banking page                   │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BRADESCO PAGE                      │
│    - Fake login form appears legitimate                  │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - Victim enters Banking credentials                   │
│    - Form captures input data                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Data received by attacker-controlled server         │
└──────────────────────────────────────────────────────────┘

🔬 JavaScript Deep Analysis

Operator Language
Portuguese (1%)
Total Code Size
116,7 KB

🔐 Obfuscation Detected

  • : Light
  • : Light
  • : None
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL                         │
│    - Email mimics Bradesco branding                      │
│    - Contains link to fake Banking page                   │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BRADESCO PAGE                      │
│    - Fake login form appears legitimate                  │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - Victim enters Banking credentials                   │
│    - Form captures input data                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Data received by attacker-controlled server         │
└──────────────────────────────────────────────────────────┘

🎯 Malicious Files Identified

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.