EN ES PT
Back to Stats

Visual Capture

Screenshot of aktifkann-payllatersx.resmi-soc4.xyz

Detection Info

http://aktifkann-payllatersx.resmi-soc4.xyz/
Detected Brand
DANA
Country
International
Confidence
95%
HTTP Status
200
Report ID
aa59de30-b35…
Analyzed
2026-03-16 00:43

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T11002EA93E00454062E19CA406791FF88913E8A47CB6D687FB5F4656B7EED9F0D2327E0
CONTENT ssdeep
192:8tft5t5SiSphFIc4Vyn6n6MRDQRl5dPVII:8tft5t5SiSpgdyniRsRLdtr

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a74d64735932da13
VISUAL aHash
0002ffffefe7e7ff
VISUAL dHash
0286265848cccece
VISUAL wHash
000003efe7e767e7
VISUAL colorHash
060020001c0
VISUAL cropResistant
8606295a4dcecece,4049c2128206a6a6

Code Analysis

Risk Score 56/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Phishing
• Target: DANA users
• Method: Impersonation and credential harvesting
• Exfil: Potentially collects login credentials and other sensitive information.
• Indicators: Domain mismatch, obfuscation, forms.
• Risk: HIGH

🔒 Obfuscation Detected

  • fromCharCode
  • unescape

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not match the official DANA domain.
Obfuscation Detected
Code obfuscation is used to hide malicious intent.
Forms Detected
The presence of forms suggests data harvesting.
Impersonation
The site visually mimics the DANA interface.

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
DANA users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 4 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
DANA
Official Website
dana.id
Fake Service
DANA Paylater

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker likely aims to steal user credentials by creating a fake login page that mimics DANA's official website. Users are tricked into entering their login details, which are then captured by the attacker.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
aktifkann-payllatersx.resmi-soc4.xyz
Registered
None
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.