5 ms·
I reverse engineered a sketchy link I got in an SMS. I opened up Tor, then went to a URL 'de-shortener' service. Furthermore, I saw an interstitial page with a
by favourable 4y ago
I reverse engineered a sketchy link I got in an SMS. I opened up Tor, then went to a URL
'de-shortener' service. Furthermore, I saw an interstitial page with a JavaScript payload in it, and it was all obfuscated and obviously coded to hide what it was doing.
I could have gone further and unpacked the code, beautifying it to see what 0 day it was leveraging, but I didn't proceed further. Obviously, this was designed to take over my device. Luckily, my default browser is Firefox with JavaScript turned off, so it wouldn't have been able to execute if I did click on the link.
- latexr 4y ago> then went to a URL 'de-shortener' service To get the last URL in a redirect chain with `curl`: curl --silent --location --output /dev/null --write-out '%{url_effective}' 'URL HERE'
- jabroni_salad 4y agoDoes this make your device 'follow' that URL? As someone who is responsible for abuse reports, one of the things I like about services such as hybrid-analysis, joe's sandbox, urlscan.io etc is that I can get some info about a link without having to worry about my local computer or maintain a sandbox. Also, a lot of sketch URLs belong to 'booters' and exist only to collect the IP address of whatever connects to them so someone can ddos it later.
- favourable 4y agoSo in my case I don't want my IP exposed, so I used the Tor Browser Bundle and used something similar to URLEX which expands short links typically found in SMS links. More often than not, the links are benign and trying to phish you, but now and then you find a malicious payload. [0] https://urlex.org/ https://urlex.org/
- meetups323 4y agoIMO much more likely they're mining, phishing, or advertising than sending out 0-days to random phone numbers. Unless you're a far more influential bloke than you're letting on.