# Hunting Phishing URLs Made Easy: A Comprehensive Series [0x2]

## **Introduction**

In the [previous part](https://huskyscripts.hashnode.dev/hunting-phishing-urls-made-easy-a-comprehensive-series-0x1) of this blog series, we learned about the structure of phishing websites, which can aid us in identifying similar phishing websites. In this part, we will focus on identifying similar phishing websites from a single phishing website. We will utilize a community-based platform, URLScan.io, to hunt down identical phishing URLs. 

## **The Phishing URL**

To begin the hunting game, we require an active phishing URL as our starting point. There are numerous ways to obtain a live phishing URL, but I usually search the latest Twitter feed using the #[phishing](https://twitter.com/search?q=%23phishing&src=typed_query) or #[scam](https://twitter.com/search?q=%23scam&src=typed_query&f=top) hashtags. Victims or recipients of phishing/suspicious URLs share screenshots when they receive such links, and one of the benefits of this is that we get to see the distribution medium of the phishing link. While browsing through the Twitter feed, I promptly identified a URL via @[CriminalIP](https://twitter.com/CriminalIP_US)’s Twitter account, and it turned out to be an Apple Phishing Page, as indicated in the [post](https://twitter.com/CriminalIP_US/status/1749114640079155215).

*CriminalIP’s Twitter post*

%[https://twitter.com/CriminalIP_US/status/1749114640079155215] 

The suspicious link mentioned in the post is [http://apple-clone-by-rebie\[.\]netlify\[.\]app](https://www.criminalip.io/domain/report?scan_id=10937976), fortunately, it was active while writing this blog.

## **Analysis of the URL**

Once we have the URL to analyze it and get the necessary information, we can scan it on URLscan.io or do it ourselves(manually with the browser). Here, we will do it in both ways.

### **Scan with URLScan.io**

URLScan.io is one of the best tools for scanning any URL. It helps us to extract all the associates and entities. Like from WHOIS records and screenshots of the webpage, including IP address and passive DNS data of the URL.

**Steps to Scan a URL in URLScan.io:**

* Go to the urlscan.io and paste the URL that needs to be scanned in the URL to scan box. Click on the `Public Scan` button to scan it.  
    
    ![](https://lh7-us.googleusercontent.com/NZW7PRS5We_kR7TMP0sZSiCKdZgcXz1-eoOAs0zrQYK2J8AGwbwAEJa__M-brnmm3oReqw-gdt7A9bar8OaECcSycEMv8u3rPLcJh7_rsVprxQTKhpJDVxuzlX6QKTd6k3O__hYiGln0amzUGkyDnTbAIHHHgxh6SWxWeTn0l3n28ahcSsC8wSaqfSwE9w align="center")
    
* Once the scan is complete, a page displaying the summary of all HTTP requests, external links, redirect behaviors, and a screenshot of the webpage will load. The Phishing URL result can be shown here: [`https://urlscan.io/result/f0972c72-2948-4f08-9d1b-4f91bb1a6d1b`](https://urlscan.io/result/f0972c72-2948-4f08-9d1b-4f91bb1a6d1b)  
    
    ![](https://lh7-us.googleusercontent.com/lh3POzo2yUZMAQ4YCFUcUsR0EZpM_uXvuHs0t8ie97QfhONiDPE35Nt1_v7FqwmcbHP0avJUYFEKMXJh7KW9LB-nqI0HVyjqpnI6RqR0BSD-3OxmWLbIzbJqQQ8mB8TfvlUblu5GF7IVo1tj_McgG-lhaphZ5tKbtRORq9EVqi6397RPA0hwyxwZhjz9BQ align="center")
    

Scanning URLs and checking results are hassle-free, so if you are starting with phishing URL hunting, this platform will greatly help you. Also, I am planning to write a dedicated blog on Hunting with URLScan.io.

### **Analyzing Manually**

We can also find more information about the phishing website if we open the URL using a local browser.

> <cite>PS: It is always advisable to open phishing sites in a temp browser or maintain proper OPSEC.</cite>

Most of the time, I always open the Network tab from the browser’s Developer Tools\[`Ctrl+Shit+i`\] before I open any phishing URL in the local browser to get network traffic visibility.

![](https://huskyscripts.blog/wp-content/uploads/2024/01/image-3.png align="center")

Now we can have more information about the phishing URL, like what the files loaded and their names or if any particular files are getting loaded from the other external links.

## **Hunting Similar URLs**

After getting more information about the websites and the assets, we can search for unique file names that are getting loaded. With the file, we can reverse-search other URLs in URLScan.io. The syntax for searching URLs is based on its file: `filename:”<filename.extnsion>”`.

On the website mentioned above, we have a few files that seem unique:

![](https://huskyscripts.blog/wp-content/uploads/2024/01/image-2.png align="center")

Let’s try to find similar websites that were likely using the same files:

* With `filename:"apple-card-logo.png"`, we have found similar patterns in URLs that impersonate Apple 
    

![](https://huskyscripts.blog/wp-content/uploads/2024/01/image-1.png align="center")

* And with the other file name, `filename:"search-icon-sm.png"`We have found more similar URLs  
    
    ![](https://lh7-us.googleusercontent.com/6h_Ku-F8NhvNllc0aFn3ybFUf6leSgt0rYmqtxmqd-zkwD2BLG7zZxM00GGqlyCfHMA4tYdQSe_A84JOaEBMHUFaEONvDATEDiaiMLM1n6axQmZtEyUiKt6rWpBn-2PJdScr63M7Sq7Wv4ywf80wz9mdjIAg7NXJLK1CI--0NJst6f-MNJsGndWROMiKSA align="center")
    

### **List of Similar Phishing URLs**

<table><tbody><tr><td colspan="1" rowspan="1"><p>hxxp[://]sebene27[.]github[.]io/apple[.]com-clone-bootstrap/<br>hxxps[://]illustrious-peony-447413[.]netlify[.]app/<br>hxxp[://]apple-clone-by-rebie[.]netlify[.]app/<br>hxxps[://]apple-with-bootstrap[.]netlify[.]app/<br>hxxp[://]golos[.]com[.]ua/<br>hxxp[://]www[.]wise-cad[.]com/<br>hxxp[://]samigutema[.]com/<br>hxxps[://]www[.]samigutema[.]com/<br>hxxp[://]objective-blackwell-5e79b8[.]netlify[.]app/<br>hxxps[://]apple-bootstrap[.]pages[.]dev/<br>hxxp[://]apple-with-bootstrap[.]netlify[.]app/<br>hxxps[://]www[.]apple-replica-bootstrap[.]naty12[.]com/<br>hxxp[://]sebene27[.]github[.]io/apple[.]com-clone-bootstrap<br>hxxp[://]illustrious-peony-447413[.]netlify[.]app/<br>hxxp[://]kaufman-cad[.]org/<br>hxxp[://]www[.]apple[.]nikeb13[.]com/<br>hxxps[://]objective-blackwell-5e79b8[.]netlify[.]app/<br>hxxps[://]www[.]appleclone[.]eyosiyastibebu[.]com/<br>hxxp[://]apple-replica-bootstrap[.]naty12[.]com/<br>hxxps[://]fervent-borg-a88941[.]netlify[.]app/<br>hxxps[://]showmeexchange[.]com/<br>hxxp[://]apple-bootstrap[.]pages[.]dev/<br>hxxps[://]apple-replica-bootstrap[.]naty12[.]com/<br>hxxps[://]samigutema[.]com/<br>hxxp[://]fervent-borg-a88941[.]netlify[.]app/<br>hxxp[://]appleboot[.]netlify[.]app/<br>hxxp[://]apple[.]nikeb13[.]com/<br>hxxps[://]www[.]applebootstrap[.]naty12[.]com/<br>hxxp[://]apple-clone12[.]netlify[.]app/<br>hxxp[://]downunderleisure[.]co[.]uk/<br>hxxps[://]www[.]hctax[.]info/<br>hxxps[://]coverageappple[.]000webhostapp[.]com/<br>hxxp[://]justonweb[.]be/<br>hxxps[://]www[.]apple[.]moebios[.]com[.]br/<br>hxxp[://]hctax[.]info/<br>hxxps[://]sebene27[.]github[.]io/apple[.]com-clone-bootstrap<br>hxxps[://]gentle-churros-0eaa63[.]netlify[.]app/<br>hxxps[://]justonweb[.]be/</p></td></tr></tbody></table>

## **Conclusion**

In this blog, I have discussed one of the approaches to how we can hunt for similar phishing URLs based on filenames used by phishing sites. In the next blog, I will write about more approaches to hunting for phishing websites.
