Ascolta l'episodio
In breve
Researchers at the SANS Internet Storm Center analyzed a phishing email whose link pointed to a credential harvesting page built with heavily obfuscated JavaScript. The page was "polymorphic": each visit produced a slightly different...
Come funziona
Researchers at the SANS Internet Storm Center analyzed a phishing email whose link pointed to a credential harvesting page built with heavily obfuscated JavaScript. The page was "polymorphic": each visit produced a slightly different...
Indicatori rossi
- Unsolicited email whose link contains your own address in the query string ( ?good=you@example.com ) — classic targeted phishing. Page hangs for tens of seconds while a CPU core maxes out — a sign of malicious obfuscated JavaScript, not a normal site. The login page and its assets change on every load, defeating simple blocklists
Cosa fare
- 1Never click login links from unsolicited email
- 2navigate to the service directly. Report suspicious messages to your IT/security team and delete them. Keep browsers an
Fonte
FAQ
Polymorphic phishing page that sometimes breaks itself (SANS ISC analysis) e una truffa reale?
Si. Tratta messaggi, chiamate o richieste di pagamento come sospette finche non le verifichi da un canale ufficiale.
Quali sono i primi segnali?
Unsolicited email whose link contains your own address in the query string ( ?good=you@example.com ) — classic targeted phishing. Page hangs for tens of seconds while a CPU core maxes out — a sign of malicious obfuscated JavaScript, not a normal site. The login page and its assets change on every load, defeating simple blocklists
Cosa devo fare subito?
Never click login links from unsolicited email; navigate to the service directly. Report suspicious messages to your IT/security team and delete them. Keep browsers an
LegalAudit puo controllare il mio caso?
Si. Apri la chat gratis e incolla messaggio, link, mittente o dati di pagamento per un triage.