Page 1 of 1

Interesting graph of response to phishing attempt on Sonic users

Posted: Sun Jul 02, 2017 12:59 pm
by patty1
I got three spam messages today that were phishing for my Sonic login information. This time, the scammers used a Bitly redirect to their site, so I was able to use Bitly's preview function to see the real address, which turned out to be in Cameroon. Turns out that Bitly preview pages also includes a graph showing how many clicks the URL has gotten in recent hours. This particular phishing expedition has gotten 85 clicks. What I don't know (anyone here familiar with Bitly?) is whether that includes people who changed the URL to go to the preview page (i.e., people who knew how to avoid going directly to the scam site), or whether it's all people who clicked on the original URL :( .

Here's the URL to the preview page, in case you're interested. The "+" at the end takes you to the preview page. Without it, you'd be redirected to the scam site, not the Bitly preview page.

https://bitly.com/2tEErMT+

Re: Interesting graph of response to phishing attempt on Sonic users

Posted: Mon Jul 03, 2017 8:56 pm
by rtrinh
I just loaded up my sandbox, enabled VPN for extra measure and saw that clicking the original link will increase the count. I made 4 clicks.

Re: Interesting graph of response to phishing attempt on Sonic users

Posted: Mon Jul 03, 2017 9:07 pm
by patty1
Well, let's hope that most of the clicks are people viewing the preview page, then!

Re: Interesting graph of response to phishing attempt on Sonic users

Posted: Mon Jul 03, 2017 10:45 pm
by rtrinh
The click tracker doesn't count page previews when I was checking it out. The page it lead to also was 403 forbidden at the time at least.