Kurzfassung
Researchers at the SANS Internet Storm Center analyzed a phishing email whose link pointed to a credential harvesting page built with heavily obfuscated JavaScript. The page was "polymorphic": each visit produced a slightly different...
Wie es funktioniert
Researchers at the SANS Internet Storm Center analyzed a phishing email whose link pointed to a credential harvesting page built with heavily obfuscated JavaScript. The page was "polymorphic": each visit produced a slightly different...
Warnzeichen
- Unsolicited email whose link contains your own address in the query string ( ?good=you@example.com ) — classic targeted phishing. Page hangs for tens of seconds while a CPU core maxes out — a sign of malicious obfuscated JavaScript, not a normal site. The login page and its assets change on every load, defeating simple blocklists
Was tun
- 1Never click login links from unsolicited email
- 2navigate to the service directly. Report suspicious messages to your IT/security team and delete them. Keep browsers an
Quelle
FAQ
Ist Polymorphic phishing page that sometimes breaks itself (SANS ISC analysis) ein reales Betrugsmuster?
Ja. Behandeln Sie Nachricht, Anruf oder Zahlungsaufforderung als verdaechtig, bis ein offizieller Kanal sie bestaetigt.
Was sind die ersten Warnzeichen?
Unsolicited email whose link contains your own address in the query string ( ?good=you@example.com ) — classic targeted phishing. Page hangs for tens of seconds while a CPU core maxes out — a sign of malicious obfuscated JavaScript, not a normal site. The login page and its assets change on every load, defeating simple blocklists
Was sollte ich zuerst tun?
Never click login links from unsolicited email; navigate to the service directly. Report suspicious messages to your IT/security team and delete them. Keep browsers an
Kann LegalAudit meinen Fall pruefen?
Ja. Starten Sie den kostenlosen Chat und fuegen Sie Nachricht, Link, Absender oder Zahlungsdaten ein.