Report ID: MFR-S001 Report Date: 22-03-2026 Investigated By: Subhadeep Chakraborty Investigation Period: 21-03-2026 to 22-03-2026
This report documents the findings of a digital forensics investigation into a suspected phishing email to compromise banking credentials of legitimate clients. The mail originates from US impersonating Bradesco Bank of Brazil to gather credentials. The mail's subject line implies urgency by notifying the user to immediately redeem expiring 92,990 points on the card.
Analysis of the mail headers, attachments and metadata indeed indicates that the mail did not originate from the bank's original infrastructure. The sender spoofed the mail structure of the actual Bradesco Bank (Brazil).
Conclusion: The mail was an mass phishing campaign targeted towards the legitimate clients of Bradesco Bank (Brazil) to compromise banking credentials.
- Identify the true origin of the mail.
- Extract IOC's, artifacts and evidences from the mail header, body and attachment(s).
- Preserve artefacts in a forensically sound manner using hashes.
- The
.emlphishing mail including headers, body and attachments. - Domains and IP addresses part of the attacker's infrastructure.
- Third-party cloud IP's being part of the campaign.
- Personally identifiable indicators of the users, if mentioned within the mail.
The original mail was gathered from phish-tank's public phishing repository hosted on github. A SHA-256 hash of the .eml file was created to preserve the original contents of the file and to prevent modifications of the original file.
| File | SHA-256 Hash |
|---|---|
| banking_phishing_campaign.eml | aa54196256075340e18adb9a85f24a0e33612faf33dd06d38a59334bf1130634 |
| Tool | Version | Purpose |
|---|---|---|
| MXToolbox Header Analysis | Online | Email header analysis |
| VirusTotal | Online | URL & attachment analysis |
| WHOIS (ICANN) | Online | Domain & IP lookup |
| Cyberchef | Online | SHA-256 hashing and decrypting |
| Claude | Sonnet 4.6 | Report outline & formatting |
| Field | Value |
|---|---|
| From (spoofed) | banco[.]bradesco@atendimento[.]com[.]br |
| Actual From (Return-Path) | root@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (Mis-configured VPS) |
| Sender's IP | 137.184.34.4 |
| To | phishing@pot |
| Subject (English Translation) | PRIME CLIENT - BRADESCO LIVELO: Your card has 92,990 LIVELO points expiring today! |
| Date | Tue, 19 Sep 2023 18:35:49 +0000 UTC |
| Message-ID | 20230919183549.39DEA3F725@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 |
Note: The IP address (137.184.34.4) is part of DigitalOcean's ASN14061 of 137.184.00/16 CIDR network range. Domain lookup indicates that the domain (atendimento[.]com[.]br) was registered on 20-09-2018 19:21:39 UTC under the email kaerjek@yahoo[].com[.]br.
The full raw headers are reproduced in Appendix A. Key findings are summarized below.
Received: from SA3PR19MB7370.namprd19.prod.outlook.com (::1) by
MN0PR19MB6312.namprd19.prod.outlook.com with HTTPS; Tue, 19 Sep 2023 18:36:46
+0000
Received: from BN0PR03CA0023.namprd03.prod.outlook.com (2603:10b6:408:e6::28)
by SA3PR19MB7370.namprd19.prod.outlook.com (2603:10b6:806:317::17) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.27; Tue, 19 Sep
2023 18:36:45 +0000
Received: from BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
(2603:10b6:408:e6:cafe::23) by BN0PR03CA0023.outlook.office365.com
(2603:10b6:408:e6::28) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.28 via Frontend
Transport; Tue, 19 Sep 2023 18:36:45 +0000
Authentication-Results: spf=temperror (sender IP is 137.184.34.4)
smtp.mailfrom=ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06; dkim=none (message not
signed) header.d=none;dmarc=temperror action=none
header.from=atendimento.com.br;compauth=fail reason=001
Received-SPF: TempError (protection.outlook.com: error in processing during
lookup of ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06: DNS Timeout)
Received: from ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (137.184.34.4) by
BN8NAM11FT066.mail.protection.outlook.com (10.13.177.138) with Microsoft SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.6813.19 via Frontend Transport; Tue, 19 Sep 2023 18:36:44 +0000
The email was sent from the IP 137.184.34.4. This IP is associated with DigitalOcean's 14061 ASN and is flagged as malicious by 1/91 VirusTotal security vendors. (see Section 4.3).
| Check | Result | Detail |
|---|---|---|
| SPF | FAIL | atendimento.com.br has no published SPF record |
| DKIM | NONE | No DKIM signature found |
| DMARC | FAIL | No DMARC policy on spoofed domain; alignment failed against atendimento.com.br |
All three authentication mechanisms failed, confirming the email did not originate from Bradesco Bank's authorized mail infrastructure.
The From: header used the display name BANCO DO BRADESCO LIVELO translating to BANK OF BRADESCO LIVELO with a fraudulent domain. Many email clients show only the display name to end users, making this deception effective to casual inspection.
IP Address: 137.184.34.4
| Attribute | Detail |
|---|---|
| ASN | AS 14061 (DigitalOcean, LLC) |
| Geolocation | United States |
| Abuse contact | abuse@digitalocean.com |
Domain: atendimento.com.br
| Attribute | Detail |
|---|---|
| Registrar | Hostgator. |
| Registered On | 09-12-2018 |
| Registrant | REDACTED |
| Name Servers | ns822.hostgator.com.br, ns823.hostgator.com.br |
| MX Record | mail.atendimento.com.br |
The email had an embedded URL foe the register button: https://blog1seguimentmydomaine2bra.me
| Attribute | Detail |
|---|---|
| Full URL | https://blog1seguimentmydomaine2bra.me |
| Host | Can't be confirmed (Offline) |
| Protocol | HTTPS (encrypted) |
| VirusTotal | Not Flagged |
| URL Status | Not active at the time of investigation |
-
The email was intended to spoof Bradesco Bank of Brazil, and was targeted towards legitimate clients of the bank to compromise their credentials.
-
The faked sender's domain
atendimento.com.brbeing entirely different from the actual bank's domain with no attempt of domain masking - indicates an amateur attacker. -
The email attempts to raise urgency by notifying the clients of expiring credit points, using the subject line "PRIME CLIENT - BRADESCO LIVELO: Your card has 92,990 LIVELO points expiring today!"
-
The IP address
137.184.34.4associated with the sender's mail is registered with DigitalOcean's ASN range in San Francisco implying a temporary an easy to replace infrastructure. -
No attempts were made to spoof or bypass the spam-filtering and content-integrity checks for both the mail authentication and Microsoft's spam filters.
-
The phishing domain used in the register button's link
blog1seguimentmydomaine2bra.meis absolutely different and doesn't even attempt to match the actual bank's domain - again indicating an amateur attacker. -
At the time of investigation the domains - both including the sender's and the email body are offline and has not been changed since 2025 (Register button's domain).
The investigation concludes with high confidence that the email was an bulk phishing campaign targeted towards the legitimate clients of Bradesco Bank. The external attacker relied on cloud infrastructure to setup and send mails from an incomplete configuration as implied by the missing Return-Path field of the mail headers. During the time of investigation the domains associated with the attacker are not online and neither are they updated/changed after 2025 (As per the WHOIS registration information).
Recommendations:
- Report the fraudulent domains to Namecheap or other phishing report website.
- The IP address associated with the attacker should be reported to the DigitalOcean for phishing attempt.
- The bank should conduct an phishing awareness programme for its clients to better differentiate such attacks in the future.
Received: from SA3PR19MB7370.namprd19.prod.outlook.com (::1) by
MN0PR19MB6312.namprd19.prod.outlook.com with HTTPS; Tue, 19 Sep 2023 18:36:46
+0000
Received: from BN0PR03CA0023.namprd03.prod.outlook.com (2603:10b6:408:e6::28)
by SA3PR19MB7370.namprd19.prod.outlook.com (2603:10b6:806:317::17) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.27; Tue, 19 Sep
2023 18:36:45 +0000
Received: from BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
(2603:10b6:408:e6:cafe::23) by BN0PR03CA0023.outlook.office365.com
(2603:10b6:408:e6::28) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.28 via Frontend
Transport; Tue, 19 Sep 2023 18:36:45 +0000
Authentication-Results: spf=temperror (sender IP is 137.184.34.4)
smtp.mailfrom=ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06; dkim=none (message not
signed) header.d=none;dmarc=temperror action=none
header.from=atendimento.com.br;compauth=fail reason=001
Received-SPF: TempError (protection.outlook.com: error in processing during
lookup of ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06: DNS Timeout)
Received: from ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (137.184.34.4) by
BN8NAM11FT066.mail.protection.outlook.com (10.13.177.138) with Microsoft SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.6813.19 via Frontend Transport; Tue, 19 Sep 2023 18:36:44 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:3B61F64750F88C5569DF38A496B2374685F23D8BC662A6A19B6823B2F6745D54;UpperCasedChecksum:62071BC7A7CF5B0844A7B406B0E9EFCDAA2CB94988E687CF8C56555AD4B52D30;SizeAsReceived:544;Count:9
Received: by ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (Postfix, from userid 0)
id 39DEA3F725; Tue, 19 Sep 2023 18:35:49 +0000 (UTC)
Content-type: text/html; charset=UTF-8
Content-Transfer-Encoding: base64
Subject: CLIENTE PRIME - BRADESCO LIVELO: Seu cartão tem 92.990 pontos LIVELO expirando hoje!
From: BANCO DO BRADESCO LIVELO<banco.bradesco@atendimento.com.br>
To: phishing@pot
Message-Id: <20230919183549.39DEA3F725@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06>
Date: Tue, 19 Sep 2023 18:35:49 +0000 (UTC)
X-IncomingHeaderCount: 9
Return-Path: root@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06
X-MS-Exchange-Organization-ExpirationStartTime: 19 Sep 2023 18:36:44.2236
(UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic:
BN8NAM11FT066:EE_|SA3PR19MB7370:EE_|MN0PR19MB6312:EE_
X-MS-Exchange-Organization-AuthSource:
BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-UserLastLogonTime: 9/19/2023 6:25:15 PM
X-MS-Office365-Filtering-Correlation-Id: b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 137.184.34.4
X-SID-PRA: BANCO.BRADESCO@ATENDIMENTO.COM.BR
X-SID-Result: NONE
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-SCL: 5
X-Microsoft-Antispam: BCL:9;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Sep 2023 18:36:44.1298
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-AuthSource:
BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg:
00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA3PR19MB7370
X-MS-Exchange-Transport-EndToEndLatency: 00:00:02.6179349
X-MS-Exchange-Processed-By-BccFoldering: 15.20.6792.025
X-Microsoft-Antispam-Mailbox-Delivery:
wl:1;pcwl:1;ucf:0;jmr:0;ex:0;psp:0;auth:0;dest:I;OFR:TrustedSenderList;ENG:(5062000305)(920221119095)(90000117)(920221120095)(91040095)(9050020)(9075021)(9100341)(944500132)(2008001134)(4810010)(4910033)(9610028)(9560006)(10180021)(9439006)(9310011)(9220031)(120001);
X-Message-Info:
qZelhIiYnPlgo3oeAkqKQrb/Je8fpvpPmRGjYwLej8PYXc5p/l16IG5I8gDUPoij+JWSvja0BAMLtkgrOcbx5zEN7V98T2UZUZs4k8BX/DcDfI7QJ0t2aouiqx4ENvkR1M3sDKP/XN09+50x9Rxi6onUtDV4eqq36VUi2qAa0zCzkJwjdl3Y9DzNE1OkaWjrHAizeUyMZ/UtK/Pz9zhA2A==
MIME-Version: 1.0
atendimento[.]com[.]br- 1/91 (Phishing)137.184.34.4- 1/91 (Malicious) + 2 Suspicious Flags
domain: atendimento.com.br
owner: Maximilian Gregory Peisker Lacerda
ownerid: ***.658.560-**
country: BR
owner-c: MGPLA3
tech-c: MGPLA3
nserver: ns822.hostgator.com.br
nsstat: 20260512 QREFUSED
nslastaa: 20230917
nserver: ns823.hostgator.com.br
nsstat: 20260512 QREFUSED
nslastaa: 20230917
saci: yes
created: 20180920 #18801717
changed: 20250822
expires: 20270920
status: published
nic-hdl-br: MGPLA3
person: Maximilian Gregory Peisker Lacerda
e-mail: kaerjek@yahoo.com.br
country: BR
created: 20151209
changed: 20250115
End of Report - MFR-S001 Investigation By - Subhadeep Chakraborty | Date: 22-03-2026