TARGET SITE

You are signed in. This site just set

Set-Cookie: SESSION=sess-t738884546; HttpOnly; Secure; SameSite=Strict

Host-only cookie on bank.teiubescdalghezamea.app. No other origin can read it and no cross-site request may carry it.

Now go back to the attacker page.