they tried to hack me so i confronted them

they tried to hack me so i confronted them

Source: YouTube · John Hammond · published Mar 13, 2025 · 24:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how to analyze and deconstruct a Twitter/X phishing scam by following the technical trail from the initial email to the attacker's infrastructure 0:00-0:18.

Key Takeaways:
• The phishing email impersonates X/Twitter but comes from "possibles dx.com" with a "review details" button that redirects to a credential harvesting site 0:18-0:36
• The scam site displays real Twitter/X profile information by making unauthorized API calls, making it appear more convincing 3:24-3:35
• All stolen credentials (passwords, 2FA codes) are immediately sent to a Telegram bot controlled by the attackers 7:40-7:46
• Using a tool called "Matt cap," the presenter successfully infiltrates the attacker's Telegram bot to view previously stolen victim data 16:02-16:08
• The investigation reveals Turkish language traces in the code and potential attacker information through the compromised Telegram channel 20:07-20:16

The video highlights both the sophistication of modern phishing attacks and how cybersecurity professionals can analyze and potentially disrupt malicious infrastructure 23:41-23:52.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

so this is a fishing email that I just received the subject line of the email says the content on my Twitter or X page does not comply with the X Community guidelines you'll note though this email is not coming from x.com or the official legitimate X website it's coming from info@ possibles dx.com via srid srid being one of the email relay providers where they could send fishing emails like this out in bulk there's not much more to this email really just a big button to review details and that is the call to action but lure to make sure that you fall for the scam if we hover over that big review details button you can see on the very bottom left of the screen the URL that it will send me to since this email was sent by srid that actually includes some tracking details like parameters or UR…