{"id":55,"date":"2022-11-21T21:58:38","date_gmt":"2022-11-21T21:58:38","guid":{"rendered":"https:\/\/freshphish.info\/?p=55"},"modified":"2024-02-11T20:07:06","modified_gmt":"2024-02-12T01:07:06","slug":"phish-uses-redirects-on-legitimate-web-sites","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=55","title":{"rendered":"Phish Uses Redirects on Legitimate Web Sites"},"content":{"rendered":"\n<p>Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create the redirector, making them public, then creating the phishing emails linking to them. I could be wrong on how this is done but this is what I believe.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"858\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish-1024x858.jpg\" alt=\"\" class=\"wp-image-57\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish-1024x858.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish-300x252.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish-768x644.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish.jpg 1194w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Booking.com hosted phish redirect. Note the domain [in brackets] the email security<br>system adds to the rewritten link showing where it actually leads to.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"859\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/judicialwatchhostedredirectphish-1-1024x859.jpg\" alt=\"\" class=\"wp-image-60\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/judicialwatchhostedredirectphish-1-1024x859.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/judicialwatchhostedredirectphish-1-300x252.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/judicialwatchhostedredirectphish-1-768x645.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/judicialwatchhostedredirectphish-1.jpg 1194w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Judicialwatch.org hosted redirect phish. Note the domain shown [in brackets] the email security<br>system adds showing where the link leads to. Note the subdomain of myjw.pr.judicialwatch.org.<br>I would think &#8220;myjw&#8221; stands for &#8220;My JudicialWatch&#8221;.<\/figcaption><\/figure>\n\n\n\n<p>I have informed Judicial Watch of this phishing redirect on their web site. I do not see an option at Booking.com to contact them.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=55\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Phish Uses Redirects on Legitimate Web Sites<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[21,20,4],"class_list":["post-55","post","type-post","status-publish","format-standard","hentry","category-phish","tag-booking-com","tag-judicialwatch-org","tag-phish"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Matt\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/freshphish.info\/?p=55\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Fresh Phish - All the freshest phish\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish\" \/>\n\t\t<meta property=\"og:description\" content=\"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/freshphish.info\/?p=55\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-11-21T21:58:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-02-12T01:07:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#blogposting\",\"name\":\"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish\",\"headline\":\"Phish Uses Redirects on Legitimate Web Sites\",\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/freshphish.info\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/bookinghostedredirectphish.jpg\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55\\\/#articleImage\",\"width\":1194,\"height\":1001},\"datePublished\":\"2022-11-21T21:58:38-05:00\",\"dateModified\":\"2024-02-11T20:07:06-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#webpage\"},\"articleSection\":\"Phish, booking.com, judicialwatch.org, phish\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/freshphish.info\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"position\":2,\"name\":\"Phish\",\"item\":\"https:\\\/\\\/freshphish.info\\\/?cat=12\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#listItem\",\"name\":\"Phish Uses Redirects on Legitimate Web Sites\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#listItem\",\"position\":3,\"name\":\"Phish Uses Redirects on Legitimate Web Sites\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?author=1\",\"name\":\"Matt\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#webpage\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?p=55\",\"name\":\"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish\",\"description\":\"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=55#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"datePublished\":\"2022-11-21T21:58:38-05:00\",\"dateModified\":\"2024-02-11T20:07:06-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish","description":"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create","canonical_url":"https:\/\/freshphish.info\/?p=55","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/freshphish.info\/?p=55#blogposting","name":"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish","headline":"Phish Uses Redirects on Legitimate Web Sites","author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"publisher":{"@id":"https:\/\/freshphish.info\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/11\/bookinghostedredirectphish.jpg","@id":"https:\/\/freshphish.info\/?p=55\/#articleImage","width":1194,"height":1001},"datePublished":"2022-11-21T21:58:38-05:00","dateModified":"2024-02-11T20:07:06-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/freshphish.info\/?p=55#webpage"},"isPartOf":{"@id":"https:\/\/freshphish.info\/?p=55#webpage"},"articleSection":"Phish, booking.com, judicialwatch.org, phish"},{"@type":"BreadcrumbList","@id":"https:\/\/freshphish.info\/?p=55#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","position":1,"name":"Home","item":"https:\/\/freshphish.info","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","position":2,"name":"Phish","item":"https:\/\/freshphish.info\/?cat=12","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=55#listItem","name":"Phish Uses Redirects on Legitimate Web Sites"},"previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=55#listItem","position":3,"name":"Phish Uses Redirects on Legitimate Web Sites","previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}}]},{"@type":"Organization","@id":"https:\/\/freshphish.info\/#organization","name":"Fresh Phish","description":"All the freshest phish","url":"https:\/\/freshphish.info\/"},{"@type":"Person","@id":"https:\/\/freshphish.info\/?author=1#author","url":"https:\/\/freshphish.info\/?author=1","name":"Matt","image":{"@type":"ImageObject","@id":"https:\/\/freshphish.info\/?p=55#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt"}},{"@type":"WebPage","@id":"https:\/\/freshphish.info\/?p=55#webpage","url":"https:\/\/freshphish.info\/?p=55","name":"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish","description":"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/freshphish.info\/#website"},"breadcrumb":{"@id":"https:\/\/freshphish.info\/?p=55#breadcrumblist"},"author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"creator":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"datePublished":"2022-11-21T21:58:38-05:00","dateModified":"2024-02-11T20:07:06-05:00"},{"@type":"WebSite","@id":"https:\/\/freshphish.info\/#website","url":"https:\/\/freshphish.info\/","name":"Fresh Phish","description":"All the freshest phish","inLanguage":"en-US","publisher":{"@id":"https:\/\/freshphish.info\/#organization"}}]},"og:locale":"en_US","og:site_name":"Fresh Phish - All the freshest phish","og:type":"article","og:title":"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish","og:description":"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create","og:url":"https:\/\/freshphish.info\/?p=55","article:published_time":"2022-11-21T21:58:38+00:00","article:modified_time":"2024-02-12T01:07:06+00:00","twitter:card":"summary_large_image","twitter:title":"Phish Uses Redirects on Legitimate Web Sites - Fresh Phish","twitter:description":"Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create"},"aioseo_meta_data":{"post_id":"55","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2022-11-21 21:58:39","updated":"2025-06-04 04:43:01","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\/?cat=12\" title=\"Phish\">Phish<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tPhish Uses Redirects on Legitimate Web Sites\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/freshphish.info"},{"label":"Phish","link":"https:\/\/freshphish.info\/?cat=12"},{"label":"Phish Uses Redirects on Legitimate Web Sites","link":"https:\/\/freshphish.info\/?p=55"}],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/55","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=55"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/55\/revisions"}],"predecessor-version":[{"id":62,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/55\/revisions\/62"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=55"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=55"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=55"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}