[ << ALL_FEED ]

An endless series of transitions

More in Phishing & sandbox

An endless chain of redirects ♾️

Quite often, when sending phishing links via email, attackers do not attach them explicitly to the email but use various redirection techniques. The suspicious domain is hidden from the user and from security tools that perform static link analysis, increasing the chances of catching a victim.

Cybercriminals often use a single level of redirection from a legitimate resource to a malicious one. But we were fortunate enough to analyze a case where the attacker used five consecutive — and, most importantly, diverse — redirection techniques to a malicious resource.

1️⃣ Redirection via TikTok

The link starts with the following construct:


https://www.tiktok.com/link/v2?aid=1988&lang=en&scene=bio_url&target=
Code language: YAML (yaml)


TikTok allows you to place links to external resources in the profile description (the bio_url parameter), and redirection to them is performed via the URL above. By the way, aid=1988 is seen not only in this case study but also in reports from other vendors. The only optional parameter in this request is lang, but apparently it, like the ID, has migrated and formed a stable prefix in phishing cases. This suggests adding it as a template for security tools.

So, instead of funny reels, TikTok forwards us to…

2️⃣ Google AMP

https://www.google.ca/url?q=amp/s/<phishing_url>
Code language: YAML (yaml)


Google AMP is a means of accelerated viewing of web pages that support a number of restrictions specially designed for this acceleration. Notably, the page is loaded not from the domain where it is hosted but from Google’s cache. In fact, the first web page of interest to us fully satisfies these requirements, since it contains only a few lines of JavaScript code.

3️⃣ The first suspicious domain

Contains the following code:


<script type="text/javascript">
    var firstBase64Url = "aHR0cHM6Ly94LmNvbQ==";
    var secondBase64Url = "<Another malicious resource>";
 
    // Load the first URL for a few seconds
    setTimeout(function() {
      window.open(atob(firstBase64Url), '_blank');
    }, 2000); // 2000 milliseconds = 2 seconds
 
    // After the specified time, load the second URL
    setTimeout(function() {
      window.location.href = atob(secondBase64Url) + "?qrc=" + window.location.hash.substr(1);
    }, 2000); // 2000 milliseconds = 2 seconds
  </script>
Code language: JavaScript (javascript)


When executed, once the 2-second timeout expires, a new tab opens with firstBase64Url (which, as is easy to verify, is https://x.com/, another legitimate resource), and in the open tab a redirect occurs to secondBase64Url. Both techniques — opening a new browser tab and enabling a timeout — are needed to complicate analysis by web crawlers.

4️⃣ Transition to secondBase64Url

At this stage, we encounter the use of Cloudflare Turnstile — an embeddable mini-captcha that does not require routing traffic through Cloudflare (example of the interface in screenshot 1). During manual analysis of the code on this page, we can already parse another URL, but in order to actually follow it, we need to learn how to pass this captcha.

5️⃣ Traditional 3XX page response code

Here everything is simple: at the previous stage, the URL from the code, via a standard 302 response, redirects to the final phishing password-collection page, which imitates the Microsoft Outlook login window. Its interface in the browser window is shown in screenshot 2.

💁‍♂️ Tips:

• When analyzing a phishing URL, it is worth paying attention to whether the detected anti-redirect techniques (inserting pauses, captchas, opening new tabs) are covered by the available information security tools: if the security tool in use cannot bypass them during automatic link following, then simply detecting them and blocking the corresponding email message may be useful.

• If you (as a user) clicked on such a link — pay attention to how often the URL in the browser’s address bar changed and how many additional actions were performed by you and on the browser’s side.


#tip #phishing #web
@ptescalator

More from global_author

More from global_author

More in Phishing & sandbox