
10/13/2020 · Elaine Dzuba
What this post added
This post details advanced phishing tactics observed during Amazon Prime Day, including the use of newly registered domains (NRDs), abuse of legitimate services like Sniply for hosting malicious content, and dynamic URL generation to evade detection. It highlights specific patterns in sender email addresses and malicious links, and describes the multi-step victim journey in a phishing attack that aims to steal credit card details and personally identifying information (PII). The analysis also uncovers unique artifacts within the attacker's code, such as specific div class naming conventions and profanity-laced code, which can aid in future attribution.