{"id":2322,"date":"2010-02-24T16:15:47","date_gmt":"2010-02-24T23:15:47","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=2322"},"modified":"2018-01-30T13:18:05","modified_gmt":"2018-01-30T20:18:05","slug":"twitter-phish-floods-network-with-short-urls","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/02\/24\/twitter-phish-floods-network-with-short-urls\/","title":{"rendered":"Twitter Phish Floods Network with Short URLs"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align: left;\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2001.png\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/02\/24\/twitter-phish-floods-network-with-short-urls\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Facebook\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2011.png\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;title=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Digg\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2021.png\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;title=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Del.icio.us\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2031.png\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;title=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Stumbleupon\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2041.png\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;title=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Reddit\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2051.png\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;Title=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Blinklist\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2061.png\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Twitter\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2071.png\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Technorati\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2081.png\" \/><\/a><a title=\"Add to Furl\" href=\"http:\/\/www.furl.net\/storeIt.jsp?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;t=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Furl\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2091.png\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F02%2F24%2Ftwitter-phish-floods-network-with-short-urls&amp;h=Twitter%20Phish%20Floods%20Network%20with%20Short%20URLs\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Newsvine\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2101.png\" \/><\/a><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2111.png\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/02\/20100224_twitterphish.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-2324\" title=\"20100224_twitterphish_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/02\/20100224_twitterphish_crop.jpg\" width=\"407\" height=\"177\" \/><\/a>All day, I&#8217;ve been getting reports from my <strong>Twitter<\/strong>-using friends and <a href=\"http:\/\/mashable.com\/2010\/02\/24\/this-you-phishing-attack\/\" target=\"_blank\">acquaintances<\/a> that they&#8217;ve been receiving tweets of short URLs. I took a look and it looks like another phishing campaign aimed at users of the social network is underway. The short URLs, prefaced with the message &#8220;<strong>This you???<\/strong>&#8221; lead to a fake Twitter login page.<\/p>\n<p>The fake login page is hosted on a domain that points to a server in China. Other domains that are currently hosted on that same server&#8217;s IP address, including <strong>bzpharma.net<\/strong>, have previously been implicated in <a href=\"http:\/\/www.sophos.com\/blogs\/gc\/g\/2010\/02\/21\/video-twitter-phishing-bzpharma-lol-funny-attack\/\" target=\"_blank\">earlier Twitter spam campaigns<\/a>. The same domain appears to also be attempting to phish credentials to AOL&#8217;s Bebo social network, and has reportedly begun spamming users with fake pharma ads.<\/p>\n<p>It appears a lot of people may get tripped up in the rush to see what the link is all about. After you type anything at all into the phishing version of the Twitter login form, your browser is redirected to <a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/02\/20100224_twitterphish_blogspotpage.jpg\" target=\"_blank\">a hastily created, empty blog page on Blogspot<\/a>. Meanwhile, the tweets keep on coming.<\/p>\n<p>Just a reminder to our Twitter fans: Please look at the address bar before you enter your Twitter credentials. As you can see from the screenshot above, it&#8217;s painfully obvious that this is not the legitimate twitter.com URL.<\/p>\n<div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>All day, I&#8217;ve been getting reports from my Twitter-using friends and acquaintances that they&#8217;ve been receiving tweets of short URLs. I took a look and it looks like another phishing campaign aimed at users of the social network is underway. The short URLs, prefaced with the message &#8220;This you???&#8221; lead to a fake Twitter login [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4133,4499,4849,7337,6791,4635,4487,4521,3919,3539,7331,3699,6603,7335,4721,7329,7333,3529,3471,4201],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2322"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=2322"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2322\/revisions"}],"predecessor-version":[{"id":23919,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2322\/revisions\/23919"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=2322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=2322"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=2322"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=2322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}