
they tried to hack me so i confronted them
Source: YouTube · John Hammond · published Mar 13, 2025 · 24:07
This video demonstrates how to analyze and deconstruct a Twitter/X phishing scam by following the technical trail from the initial email to the attacker's infrastructure 0:00-0:18.
Key Takeaways:
• The phishing email impersonates X/Twitter but comes from "possibles dx.com" with a "review details" button that redirects to a credential harvesting site 0:18-0:36
• The scam site displays real Twitter/X profile information by making unauthorized API calls, making it appear more convincing 3:24-3:35
• All stolen credentials (passwords, 2FA codes) are immediately sent to a Telegram bot controlled by the attackers 7:40-7:46
• Using a tool called "Matt cap," the presenter successfully infiltrates the attacker's Telegram bot to view previously stolen victim data 16:02-16:08
• The investigation reveals Turkish language traces in the code and potential attacker information through the compromised Telegram channel 20:07-20:16
The video highlights both the sophistication of modern phishing attacks and how cybersecurity professionals can analyze and potentially disrupt malicious infrastructure 23:41-23:52.
Sources:
- 0:00-0:18 Introduction to the Twitter/X phishing email
- 0:18-0:36 Revealing the suspicious sender domain and button URL
- 3:24-3:35 Accessing and analyzing the phishing site
- 7:40-7:46 Discovery of Telegram bot receiving credentials
- 16:02-16:08(https://www.youtube.com/watch?v=C
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
so this is a fishing email that I just received the subject line of the email says the content on my Twitter or X page does not comply with the X Community guidelines you'll note though this email is not coming from x.com or the official legitimate X website it's coming from info@ possibles dx.com via srid srid being one of the email relay providers where they could send fishing emails like this out in bulk there's not much more to this email really just a big button to review details and that is the call to action but lure to make sure that you fall for the scam if we hover over that big review details button you can see on the very bottom left of the screen the URL that it will send me to since this email was sent by srid that actually includes some tracking details like parameters or UR…