EN ES PT
Back to Stats

Captura Visual

Screenshot of www.nova.investeicbank.com

Informações de Detecção

https://www.nova.investeicbank.com
Detected Brand
Nova.Investeic Bank
Country
International
Confiança
100%
HTTP Status
200
Report ID
ca540841-d04…
Analyzed
2026-01-26 11:38
Final URL (after redirects)
https://www.nova.investeicbank.com/

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D973567C62C1563A50CB87F2E6909F29D29DCBD9DF27AD8BF3ACC2471786C458E41260
CONTENT ssdeep
768:zPM4FfFqPW9bfXHwo4xBg28iUJd4ieGoPYnx1v3PZ8GEWbuDzdeL4E:zPfoPHgd4ieGoPYnx1v3PBEWbb

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a9add0b2c0ead2f2
VISUAL aHash
ff0b0b1303030100
VISUAL dHash
dbd7d3f3d7d79b90
VISUAL wHash
ff1b1b3b1303035a
VISUAL colorHash
07600008040
VISUAL cropResistant
cbd7d3d3f3d7d3b3,2040838b73a36393,dfd3d3f3d7d39b90

Análise de Código

Risk Score 85/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Phishing de credenciais bancárias
• Alvo: Clientes do Nova.Investeic Bank
• Método: Site falso com formulário de login projetado para roubar credenciais bancárias.
• Exfil: Os dados provavelmente são exfiltrados por meio do envio de formulários JavaScript.
• Indicadores: Novo domínio, domínio não corresponde ao site oficial, JavaScript ofuscado.
• Risco: CRÍTICO - Potencial para roubo imediato de credenciais e perdas financeiras.

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://www.nova.investeicbank.com/send-money
  • https://www.nova.investeicbank.com/verify
  • https://www.nova.investeicbank.com/login

📡 API Calls Detected

  • https://libretranslate.com/translate
  • GET
  • POST

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected multiple phishing kit types: Credential Harvester, OTP Stealer, Card Stealer, and Banking-specific modules.
Domain Impersonation
Domain 'nova.investeicbank.com' closely mimics a legitimate Banking brand (Nova.Investeic Bank) with high visual similarity.
Obfuscation Techniques
75 obfuscation techniques detected in JavaScript files, indicating evasion of static analysis.
Malicious JavaScript Payload
Large JavaScript files (1.33 MB total) with no legitimate functionality detected, consistent with phishing kits.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Nova.Investeic Bank users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltração
Unknown
Avaliação de Risco
CRITICAL - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 75 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Nova.Investeic Bank
Official Website
https://www.novainvesteicbank.com
Fake Service
Online Banking account access and new account registration

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting with OTP Interception

The phishing kit is designed to capture Banking credentials by mimicking the login portal of Nova.Investeic Bank. Upon submission, the kit intercepts one-time passwords (OTPs) via a fake OTP input field, enabling real-time account takeover.

Secondary Method: Card and Personal Information Theft

The kit includes modules to harvest credit card details and personal information (e.g., name, address, SSN) through fake forms or overlays, which are then exfiltrated to attacker-controlled infrastructure.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
www.nova.investeicbank.com
Registered
2025-12-17 15:45:16+00:00
Registrar
Cosmotown, Inc.
Estado
Active (39 days old)

🦠 Malicious Files

Main File
File Size

Large obfuscated JavaScript file containing credential harvesting and OTP interception logic.

📊 Diagrama de Fluxo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE                          │
│    - Fake Nova.Investeic Bank email/link                 │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BANKING SITE                       │
│    - Cloned login page presented                         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL HARVESTING                                 │
│    - Victim enters login credentials                     │
│    - One-time password requested                         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. OTP INTERCEPTION                                      │
│    - Victim enters OTP on fake page                      │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION                                     │
│    - Credentials and OTP sent via HTTP POST              │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Sophistication Level
Basic
Total Code Size
1,3 MB

🔗 API Endpoints Detected

Other
55

🔐 Obfuscation Detected

  • : None
  • : Light
  • : Heavy
  • : Moderate
  • : None
  • : None
  • : None
  • : Moderate
  • : Light
  • : Light
  • : Light
  • : Light
  • : Light
  • : None
  • : Light
  • : Light
  • : None

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE                          │
│    - Fake Nova.Investeic Bank email/link                 │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE BANKING SITE                       │
│    - Cloned login page presented                         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL HARVESTING                                 │
│    - Victim enters login credentials                     │
│    - One-time password requested                         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. OTP INTERCEPTION                                      │
│    - Victim enters OTP on fake page                      │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION                                     │
│    - Credentials and OTP sent via HTTP POST              │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.