EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://alisteronlinebanking.com/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
796b9f29-89e…
Analyzed
2026-02-27 18:00

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1F463353C63C1563550C783B2E594AF69D29CCF9ADB27AD8BF2ACC247178AC45CF52260
CONTENT ssdeep
768:P5CFfvqJ5kbfXHwo4xBg28Lavx1v3PZSGEWbjRBTeRCa:SfCJtTx1v3PPEWbM

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a9abd0bac0ead2d2
VISUAL aHash
ff0b0b2303030100
VISUAL dHash
dbd7d3d3d7d79390
VISUAL wHash
ff0b1b7b1303035a
VISUAL colorHash
07600008040
VISUAL cropResistant
4bdff3d3d3d7d7b3,2040838b73a36393,dfd3d3d3d7d39a90

Code Analysis

Risk Score 82/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester šŸŽ£ OTP Stealer šŸŽ£ Card Stealer šŸŽ£ Banking šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Phishing
• Target: Banking users
• Method: Impersonation
• Exfil: Unknown, likely to steal credentials and financial info. Obfuscation suggests attempt to hide data exfiltration.
• Indicators: Domain mismatch, Javascript obfuscation.
• Risk: HIGH

šŸ”’ Obfuscation Detected

  • fromCharCode
  • hex_escape
  • unicode_escape
  • base64_strings

šŸŽÆ Kit Endpoints

  • https://alisteronlinebanking.com/login
  • https://alisteronlinebanking.com/verify
  • https://alisteronlinebanking.com/send-money

šŸ“” API Calls Detected

  • https://libretranslate.com/translate
  • GET

šŸ“Š Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Domain mismatch
The domain is not affiliated with a known bank.
JavaScript obfuscation
Obfuscation techniques are often used to hide malicious code from detection.
Form submission detected
Form submission and javascript obfuscation strongly indicates that data is being sent to external source

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
CRITICAL - Automated credential harvesting with Unknown

āš ļø Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 49 obfuscation techniques

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Alister Bank
Fake Service
Online Banking

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The site likely attempts to harvest login credentials. The user is prompted to 'Login to Banking' or 'Open Account Today', and these links likely lead to forms. Obfuscated javascript often accompanies these form submissions to exfiltrate user's information.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
alisteronlinebanking.com
Registered
2024-05-24
Registrar
Unknown
Status
active

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.