
4/24/2015 · Marc Rogers
What this post added
This post details the analysis of a phishing campaign that exploited a WordPress 0-day vulnerability. It describes the typical phishing attack lifecycle, from email distribution to compromised landing pages, and explains how Cloudflare detected and neutralized the attack by analyzing malicious links and collaborating with hosting providers. The post also discusses various advanced phishing techniques used for URL obfuscation, such as image maps, misspelled domains, homoglyphs, reflection, redirection, JavaScript, and Punycode, providing technical examples of each.