How do these scammers make an official url show their page?

marveloz

BANNED
Joined
Dec 19, 2014
Messages
49
Reaction score
8
There was this clickbaitty spam message getting spammed across Whatsapp saying that adidas is celebrating its anniversary day and is giving away 100000 shoes to the fastest claimers on their site. There's the official adidas's url in the message and it didn't change in the browser after you clicked on it but it showed a different, scammy and suspicious page with some stock remaining gauge, a simple webform asking for your full name, dob, etc, a social media widget asking you to like/follow every single one of their partner's socmed page, survey panels and what not. This is new to me because I usually find something like this with a convincing url but it would change in the browser once we clicked on it but this, this stays still. How do they do this? o_O
 
Please check CPA section for your question, some sort of redirect.
 
Can I have OP move this thread of mine to the right section please?
 
interesting, do you have the original message? if yes, you can copy and paste it in editor that can reveal the trick, they may used a unicode(UTF-8) look-alike replacement characters
For example, the letter "a" will be replaced with "а" Looks the same, doesn't it?? It's NOT!
the first one is Regular 7-bit character, present in GSM charset the other one is a Character that is not present in GSM charset, forces to use Unicode encoding

so adidas.com is the official website
and the аdidаs.com is the attacker website...
try to copy it and paste in your browser it will leads to a domain xn--dids-43dd.com
 
interesting, do you have the original message? if yes, you can copy and paste it in editor that can reveal the trick, they may used a unicode(UTF-8) look-alike replacement characters
For example, the letter "a" will be replaced with "а" Looks the same, doesn't it?? It's NOT!
the first one is Regular 7-bit character, present in GSM charset the other one is a Character that is not present in GSM charset, forces to use Unicode encoding

so adidas.com is the official website
and the аdidаs.com is the attacker website...
try to copy it and paste in your browser it will leads to a domain xn--dids-43dd.com

I agree with certainty with this guy.
Recently just a few months ago a ton of articles wrote about this kind of attack.
Unicode is nothing new but a surge of usage in phishing did this.
So I think whoever is behind this spam scheme just jumped on the wagon.
 
Thank you all for having clarified this, this sh*t is totally sophisticated in my opinion.
It's just that it's such a shame that this way, their clients' reputation will get ruined instead.

Edit: I no longer have the original message but last time I checked, it no longer retained the victim's address after getting clicked on
 
Back
Top