Brazilian Bank Targeted by Phishing Site and DNS Poisoning
ID: c787cc1d-d84b-5be0-8291-d429263f8ad9
STIX ID: report--c787cc1d-d84b-5be0-8291-d429263f8ad9
Feed Name: Zscaler Security Research Blog
Threat Score
A phishing campaign targeted Santander Brazil by poisoning DNS to resolve santander.com.br to a cloned site at 200.252.58.134 that captured login credentials. The phishing site closely mimicked the real site (legitimate IPs 200.220.178.3 and 200.220.186.3), lacked HTTPS and contained copied HTML comments; the compromised DNS servers were later cleaned but the phishing site remained accessible and unlisted by some URL blocklists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
