{"id":861,"date":"2020-05-22T21:48:18","date_gmt":"2020-05-22T21:48:18","guid":{"rendered":"https:\/\/osintme.com\/?p=861"},"modified":"2020-05-23T09:41:18","modified_gmt":"2020-05-23T09:41:18","slug":"new-spam-phishing-campaign-on-whatsapp-investigating-fake-dominos-pizza-websites","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2020\/05\/22\/new-spam-phishing-campaign-on-whatsapp-investigating-fake-dominos-pizza-websites\/","title":{"rendered":"New spam \/ phishing campaign on Whatsapp &#8211; investigating fake Dominos pizza websites"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"861\" class=\"elementor elementor-861\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5005239 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5005239\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-facc20e\" data-id=\"facc20e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e3857a9 elementor-widget elementor-widget-text-editor\" data-id=\"e3857a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This week&#8217;s focus is an impromptu investigation sparked by another reader submission.<\/p><p>This is the message that one of the readers received today on Whatsapp:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a7b0d14 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a7b0d14\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ac7c52a\" data-id=\"ac7c52a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-eadb77c elementor-widget elementor-widget-image\" data-id=\"eadb77c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"440\" height=\"170\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/dominos-spam-whatsapp.jpg?fit=440%2C170&amp;ssl=1\" class=\"attachment-large size-large wp-image-863\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/dominos-spam-whatsapp.jpg?w=440&amp;ssl=1 440w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/dominos-spam-whatsapp.jpg?resize=300%2C116&amp;ssl=1 300w\" sizes=\"(max-width: 440px) 100vw, 440px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5a531b5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5a531b5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4d53c74\" data-id=\"4d53c74\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f400b9c elementor-widget elementor-widget-text-editor\" data-id=\"f400b9c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The domain looks deceivingly in order &#8211; after all, the real Dominos website in Ireland is www.dominos.ie&#8230;.<\/p><p>Looks legit, right?<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-762024a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"762024a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-88c081f\" data-id=\"88c081f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9a9d8cc elementor-widget elementor-widget-text-editor\" data-id=\"9a9d8cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Well, not exactly. To understand what we&#8217;re looking at here, a quick explanation on web domain addressing structure is in order.\u00a0<\/p><p>Every valid Internet domain name is comprised of the following components:<\/p><ol><li><strong>Top level domain<\/strong> &#8211; whatever follows after the last dot in the URL string. Common top level domains examples are: .com, .org, .gov, .net, .uk, .ie&#8230; And in this case, it&#8217;s <strong><em>.club<\/em><\/strong>.<\/li><li><strong>Second level domain<\/strong> &#8211; whatever is before the top level domain. So, the second level domain of this blog is <strong><em>osintme<\/em><\/strong> and the top level domain is <strong><em>.com<\/em><\/strong>. In our example, the second level domain is <strong><em>ie-pizza<\/em><\/strong> (yes, a hyphen is the only special character is allowed by the domain naming convention).<\/li><li><strong>Subdomain<\/strong> &#8211; whatever is positioned before the second level domain. It can be anything really, for example: aws.amazon.com &#8211; the <strong><em>aws<\/em><\/strong> part is the subdomain here. And in our case, the subdomain is <strong><em>dominos<\/em><\/strong>.<\/li><\/ol><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f629981 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f629981\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fdf3946\" data-id=\"fdf3946\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0638881 elementor-widget elementor-widget-text-editor\" data-id=\"0638881\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Visually it can be very confusing and I would not blame people for believing this could be a real Dominos Pizza website &#8211; because at the first glance, it does look real.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5e9e174 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5e9e174\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a20803f\" data-id=\"a20803f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-381edb8 elementor-widget elementor-widget-text-editor\" data-id=\"381edb8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A quick check using <a href=\"https:\/\/who.is\/\">who.is<\/a> reveals that the domain was registered only yesterday (21st May 2020).<\/p><p>It was registered using <strong>namecheap<\/strong>, a US based hosting company whose services are known to be frequently abused by scammers and cyber criminals.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-82ae66d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"82ae66d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0ed7aba\" data-id=\"0ed7aba\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9e7b042 elementor-widget elementor-widget-image\" data-id=\"9e7b042\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"553\" height=\"492\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/whois-dominos-scam.jpg?fit=553%2C492&amp;ssl=1\" class=\"attachment-large size-large wp-image-864\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/whois-dominos-scam.jpg?w=553&amp;ssl=1 553w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/whois-dominos-scam.jpg?resize=300%2C267&amp;ssl=1 300w\" sizes=\"(max-width: 553px) 100vw, 553px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b8e375d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b8e375d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-843dd2d\" data-id=\"843dd2d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0419d3e elementor-widget elementor-widget-text-editor\" data-id=\"0419d3e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>So before I proceeded any further, I fired off an email to namecheap, just to let them know somebody is hosting a scam website using their service.<\/p><pre>abuse@namecheaphosting.com<\/pre>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d76daca elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d76daca\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7da34b5\" data-id=\"7da34b5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3765c93 elementor-widget elementor-widget-text-editor\" data-id=\"3765c93\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Visual examination of the domain in a safe virtual machine environment only confirms this is a scam:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-463cfa1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"463cfa1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-baeb959\" data-id=\"baeb959\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b8a5928 elementor-widget elementor-widget-image\" data-id=\"b8a5928\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"787\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-scam-website.jpg?fit=1024%2C787&amp;ssl=1\" class=\"attachment-large size-large wp-image-865\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-scam-website.jpg?w=1131&amp;ssl=1 1131w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-scam-website.jpg?resize=300%2C231&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-scam-website.jpg?resize=1024%2C787&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-scam-website.jpg?resize=768%2C590&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6fe4793 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6fe4793\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-15404fa\" data-id=\"15404fa\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b5cfeb9 elementor-widget elementor-widget-image\" data-id=\"b5cfeb9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"395\" height=\"848\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-2.jpg?fit=395%2C848&amp;ssl=1\" class=\"attachment-large size-large wp-image-866\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-2.jpg?w=395&amp;ssl=1 395w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-2.jpg?resize=140%2C300&amp;ssl=1 140w\" sizes=\"(max-width: 395px) 100vw, 395px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-751eda2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"751eda2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c1fd81f\" data-id=\"c1fd81f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-adba2c3 elementor-widget elementor-widget-text-editor\" data-id=\"adba2c3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>I was expecting malicious content so I scanned the website using two very solid malware analysis platforms. The results for both scans are available below:<\/p><p>Any.Run:<\/p><p><a href=\"https:\/\/app.any.run\/tasks\/b5fdaee3-39e5-4be1-9d68-6a3bd55e2611\/\">https:\/\/app.any.run\/tasks\/b5fdaee3-39e5-4be1-9d68-6a3bd55e2611\/<\/a><\/p><p>&#8230; and Virus Total:<\/p><p><a href=\"https:\/\/www.virustotal.com\/gui\/url\/440b4a6a5ec27fe188ac2a4f810f4a72759b0bf31ac9bd014693718a06e283b1\/detection\">https:\/\/www.virustotal.com\/gui\/url\/440b4a6a5ec27fe188ac2a4f810f4a72759b0bf31ac9bd014693718a06e283b1\/detection<\/a><\/p><p>At the time of the writing, there was no malicious software detected on the site by either of those malware analysis services.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-922bf3f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"922bf3f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9e19334\" data-id=\"9e19334\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f01f1bf elementor-widget elementor-widget-text-editor\" data-id=\"f01f1bf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>I interacted with the website in several ways but could not identify any functionality that would lead me to believe the site harvested login credentials, financial or personal information.<\/p><p>It was time to dig deeper into the source code.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e877e9e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e877e9e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-53dcc49\" data-id=\"53dcc49\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-fe57368 elementor-widget elementor-widget-text-editor\" data-id=\"fe57368\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In previous posts I mentioned the use of the F12 key for investigating websites.<\/p><p>Pressing F12 switches on Web Developer mode on a website you are currently viewing in your browser (known as Developer Tools in both Google Chrome and Microsoft Edge).<\/p><p>Some useful information was gleaned after inspecting the target website:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-30d4cb5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"30d4cb5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b70ac91\" data-id=\"b70ac91\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c8639c9 elementor-widget elementor-widget-heading\" data-id=\"c8639c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">1. Geoplugin and redirections to other websites<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-864d73f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"864d73f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5402f43\" data-id=\"5402f43\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bceb68d elementor-widget elementor-widget-text-editor\" data-id=\"bceb68d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The website contains a simple Javascript that utilises <a href=\"https:\/\/www.geoplugin.net\/\">geoplugin.net<\/a> to geolocate a user&#8217;s IP address and redirect to other websites, depending on the user&#8217;s location:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-24e0016 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"24e0016\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-98380e2\" data-id=\"98380e2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b858060 elementor-widget elementor-widget-image\" data-id=\"b858060\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"704\" height=\"323\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/geoplugin-dominos.jpg?fit=704%2C323&amp;ssl=1\" class=\"attachment-large size-large wp-image-869\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/geoplugin-dominos.jpg?w=704&amp;ssl=1 704w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/geoplugin-dominos.jpg?resize=300%2C138&amp;ssl=1 300w\" sizes=\"(max-width: 704px) 100vw, 704px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-173519d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"173519d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-decf1e8\" data-id=\"decf1e8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9803f4a elementor-widget elementor-widget-text-editor\" data-id=\"9803f4a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This is a valuable discovery as suddenly we reveal <strong>4 other websites associated with this scam<\/strong>.<\/p><p>Note how the Italian site is the only non-English option out of them all. Perhaps this could indicate the persons behind this scam are Italians? Or Spanish, due to the elements of the Spanish language here and there in the source code (wide speculation, I know).<\/p><p>The scam websites are all direct clones and all but one impersonate Dominos Pizza website &#8211; apart from the Indian version served to any user with an Indian IP, which offers a false promise of free Adidas merchandise:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fd15237 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fd15237\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7a55a43\" data-id=\"7a55a43\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-42562ad elementor-widget elementor-widget-image\" data-id=\"42562ad\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"670\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/adidas-site-scam.jpg?fit=768%2C670&amp;ssl=1\" class=\"attachment-medium_large size-medium_large wp-image-870\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/adidas-site-scam.jpg?w=1047&amp;ssl=1 1047w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/adidas-site-scam.jpg?resize=300%2C262&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/adidas-site-scam.jpg?resize=1024%2C893&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/adidas-site-scam.jpg?resize=768%2C670&amp;ssl=1 768w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">.<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-dae9f4c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"dae9f4c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e5d4496\" data-id=\"e5d4496\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-32e85c1 elementor-widget elementor-widget-heading\" data-id=\"32e85c1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">2. Browser user agent scan<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-82a12aa elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"82a12aa\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fd2fcc9\" data-id=\"fd2fcc9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5e82e44 elementor-widget elementor-widget-text-editor\" data-id=\"5e82e44\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>When you interact with the fake website, it calls a function to scan your browser user agent.<\/p><p>I have previously talked about user fingerprinting conducted by websites <a href=\"https:\/\/osintme.com\/index.php\/2019\/10\/17\/what-user-information-will-a-website-collect-on-you\/\">here<\/a>.<\/p><p>Essentially, the scam website detects if a user is accessing the site from a mobile device and it prompts the Whatsapp mobile app to share the link.<\/p><p>If you access the site via a desktop browser, this will not work.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-808cbc4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"808cbc4\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8d9350a\" data-id=\"8d9350a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f16731f elementor-widget elementor-widget-image\" data-id=\"f16731f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"833\" height=\"303\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/function-java.jpg?fit=833%2C303&amp;ssl=1\" class=\"attachment-large size-large wp-image-871\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/function-java.jpg?w=833&amp;ssl=1 833w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/function-java.jpg?resize=300%2C109&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/function-java.jpg?resize=768%2C279&amp;ssl=1 768w\" sizes=\"(max-width: 833px) 100vw, 833px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b10e2e7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b10e2e7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e5683a2\" data-id=\"e5683a2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8dc1a9b elementor-widget elementor-widget-heading\" data-id=\"8dc1a9b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">3. Fake user reviews<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4926224 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4926224\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3029dbe\" data-id=\"3029dbe\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9344c1d elementor-widget elementor-widget-text-editor\" data-id=\"9344c1d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>You have probably noticed the presence of &#8220;user reviews&#8221; praising the seemingly legitimate giveaway under the sharing buttons.<\/p><p>They do look fake, but how do they work?<\/p><p>The website is utilising the <a href=\"https:\/\/randomuser.me\/\">randomuser.me<\/a> API to pull in 5 randomly generated users and it pairs them off each with a short made-up review text:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c6a3b2e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c6a3b2e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-77d62f6\" data-id=\"77d62f6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-46b05fe elementor-widget elementor-widget-image\" data-id=\"46b05fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"135\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/random-user-API.jpg?fit=1024%2C135&amp;ssl=1\" class=\"attachment-large size-large wp-image-872\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/random-user-API.jpg?w=1379&amp;ssl=1 1379w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/random-user-API.jpg?resize=300%2C40&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/random-user-API.jpg?resize=1024%2C135&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/random-user-API.jpg?resize=768%2C101&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">The image is very long, zoom in for details<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b9c7672 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b9c7672\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-38641c2\" data-id=\"38641c2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cb794a9 elementor-widget elementor-widget-image\" data-id=\"cb794a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"423\" height=\"816\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-reviews-3.jpg?fit=423%2C816&amp;ssl=1\" class=\"attachment-large size-large wp-image-874\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-reviews-3.jpg?w=423&amp;ssl=1 423w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-dominos-reviews-3.jpg?resize=156%2C300&amp;ssl=1 156w\" sizes=\"(max-width: 423px) 100vw, 423px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b7c6ab4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b7c6ab4\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-473b49d\" data-id=\"473b49d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c61dc86 elementor-widget elementor-widget-heading\" data-id=\"c61dc86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">4. Cookies<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-076e9f0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"076e9f0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ba3d1ef\" data-id=\"ba3d1ef\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dfcd94c elementor-widget elementor-widget-text-editor\" data-id=\"dfcd94c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Cookies can be used for tracking and this website has several of those.<\/p><p>I don&#8217;t believe in this case they are a huge threat, but it&#8217;s always recommended to block cookies.<\/p><p>I personally use the uBlock Origin plugin and it does the job very well.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9db117f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9db117f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e108af4\" data-id=\"e108af4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8f91c5e elementor-widget elementor-widget-image\" data-id=\"8f91c5e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"214\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/cookies-fake-dominos.jpg?fit=1024%2C214&amp;ssl=1\" class=\"attachment-large size-large wp-image-873\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/cookies-fake-dominos.jpg?w=1376&amp;ssl=1 1376w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/cookies-fake-dominos.jpg?resize=300%2C63&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/cookies-fake-dominos.jpg?resize=1024%2C214&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/cookies-fake-dominos.jpg?resize=768%2C161&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Another very long image, zoom in for details<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-331725e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"331725e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bbdfcaf\" data-id=\"bbdfcaf\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0eb2930 elementor-widget elementor-widget-text-editor\" data-id=\"0eb2930\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em><strong>Concluding thoughts:<\/strong><\/em> right now the Dominos scam website appears to only have the spam proliferation functionalities, but this can change as it is very new (only 1 day old during the time of writing).<\/p><p>The scammers can monitor the scale of user interaction with the URL and based on that they can adapt their tactics, ranging from phishing for logins and passwords to deploying malware on users&#8217; phones.<\/p><p>The more people report this scam to the hosting provider, the better the chance we have that namecheap removes and blacklists the scammers.<\/p><p>I would encourage you all to individually email <a href=\"mailto:abuse@namecheaphosting.com\">abuse@namecheaphosting.com<\/a> and report the site to them.<\/p><p><strong>Remain safe and until the next time.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>An impromptu investigation into a spam \/ phishing campaign featuring fake Dominos pizza vouchers on Whatsapp.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"off","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[93],"tags":[96,34,82,81,79,97],"class_list":["post-861","post","type-post","status-publish","format-standard","hentry","category-my-investigations","tag-dominos","tag-investigation","tag-phishing","tag-scam","tag-website","tag-whatsapp"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=861"}],"version-history":[{"count":10,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/861\/revisions"}],"predecessor-version":[{"id":881,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/861\/revisions\/881"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}