Bernard Aybouts - Blog - Miltonmarketing.com

Approx. read time: 4.4 min.

Post: What’s behind this 1,000-character phishing URL?

Phishing sites are common, but this week the internet found a strange strain that’s a little rarer: a phishing site with a URL almost a thousand characters long. Experts have a good theory about why a scammer would go to all that trouble.

We learned of a strange phishing campaign which uses an unusually long URL. The mail purports to come from your email provider, telling you that your account has been blacklisted due to multiple login failures. The phisher tries to hook your mail login credentials by getting you to log in again, but of course, the link it provides isn’t really a link to your login provider’s page.

Phishing links generally arrive behind an innocuous piece of text like ‘log in’, ‘reauthorise’ or ‘validate’. Hyperlinks separate the text from the actual links that they follow, though, and unless a victim hovers over the text or right-clicks it, or checks the address bar of their browser after clicking on the link, they won’t know what sites they’re really visiting.

Phishers are aware of this and diligent ones will try to lure you with a URL that looks plausible. They’ll use tricks like top-level domains (TLDs) designed to look like the last couple of words in a legitimate domain, or homographs that use foreign character sets to create English-looking letters. Hyphens and subdomains are also a good way of creating URLs that look like a legitimate site at first glance.

This phisher didn’t bother with any of that. The link they provided was a domain that looked nothing like the recipient’s email domain. Moreover, it also used a ridiculously long combination of subdirectory and page name (those are the folders and actual pages after the top level domain name). The total URL was almost a thousand characters long.

Eduardo Schultze at the Threat intelligence team lead at Axur, which uses AI to help companies with online brand protection and digital fraud detection. Eduardo Schultze, also a representative on the Anti-Phishing Working Group, an industry group that combats phishing scammers. He said:

The interesting thing is that the phishing [site] doesn’t allow you to type your email but it instead grabs it from the “email” parameter in the URL from the person who received the phishing.

This isn’t a one-off. An analysis of the weird URL by web site analysis service URLscan shows over 1100 phishing pages with a similar structure and files, suggesting that they could be coming from the same phishing kit. It also shows over 180 phishing domains hosted at the same Hong Kong-based IP address, but serving different domains.

So, what’s going on? Schultze points out that because this phishing URL uses subdirectories, it’s possible for it to take the phishing victim into a variety of folders:

The more you click, the deeper you go into the actual phishing landing page.

This feeds into the theory that the phisher is hiding the location of the phishing files on the hacked server. Stefanie Ellis, portfolio marketing manager at brand protection company Clarivate Analytics and also a representative for the APWG, has seen a small proportion of phishing sites using 500 characters or more. She said:

There’s nothing in the configuration of the URL that prevents us from detecting the site so we have to think it’s related to hiding on the server, or generally making the investigation more time-consuming or frustrating for the host.

It isn’t clear whether the variety of folders were randomly scripted or manually created, but no matter: a determined anti-phishing investigator will quickly work out that it’s a scam domain. Said Ellis:

It’s creative, but at the end of the day a longer URL is not going to prevent detection, blocking, or mitigation of the phishing site.

However, while this ridiculously long URL might alert desktop users to something phishy, infosecurity expert Spencer Alessi points out, mobile users might be oblivious:

View image on twitter.

They  seem to like long URL business because of how the URL displays on mobile. iOS typically, for example, shows the front of the url as opposed to the root domain.

ALWAYS CHECK ROOT DOMAINS AND HEADERS OF EMAILS.

So I would have this as an example:

https://www…google-imagine-this-is-a-very-long-url-imagine-it-was-1000-characters-long…google.com

The iPhone or an iOS device might trunctuate and display only the front or the back of the URL above like this:

…google.com

This can be misleading because its taken out of context and the URL does not belong to Google its a deception and has been used in the phishing community for decades.


Related Videos:

Bernard Aybouts - Blog - Miltonmarketing.com

Related Links:

Reasons why website visitors stop reading before the end of your page

The background-color CSS property

Automatically Link to Twitter Usernames in Content

Chrome warns you if your username or passwords have been hacked

Learn RE – Regular Expressions in Python

How to secure your Nest account and cameras and keep hackers at bay

How to Fix ERR_TOO_MANY_REDIRECTS on Your WordPress Site

Googles John Mueller on Best Site Structure

How To Start a Blog – Beginner’s Guide for 2018

Kodi Add-on Development Tools

The Longevity Blueprint: AI-Powered Health Optimization

Current step:1AI-Human Medical Analyzer: Smarter, Personalized Health
2AI-Human Medical Analyzer: Smarter, Personalized Health

> SYS.HEALTH: AI-Human Medical Analyzer_

// Revolutionize Your Diagnostics

Experience the perfect blend of cutting-edge AI precision and expert human care. Our revolutionary analyzer turns your raw health data into personalized, actionable insights tailored just for you.

> INITIALIZING_BIOMETRIC_SCAN...

[+] DATA_INPUT

Securely upload complex health parameters, including lab bloodwork and comprehensive medical history.

[+] PROCESSING

Advanced algorithmic parsing combined with human-level oversight ensures hyper-accurate data interpretation.

[+] OUTPUT_MATRIX

Receive smarter, faster, and truly personalized care strategies to take immediate charge of your health journey.

A name/nickname is required to continue.

> TRANSLATION_MATRIX_ACTIVE...
[ LANG_EN ]
Knowledge Heals, Prevention Protects
[ LANG_HI ]
ज्ञान ठीक करता है, रोकथाम सुरक्षा करती है
[ LANG_ZH ]
知识治愈,预防保护
[ LANG_JA ]
知識は癒し、予防は守る
[ LANG_HE ]
הידע מרפא, המניעה מגנה
[ LANG_AR ]
المعرفة تُشفي، والوقاية تحمي
[ LANG_FR ]
La connaissance guérit, la prévention protège

> SYS.AUTH: Data Processing Consent_

[ AWAITING_AUTHORIZATION ] By providing consent, you allow us to process your uploaded data through our proprietary AI-Human analysis system.

  • [+] SECURE_REVIEW: This ensures your information is carefully reviewed using advanced AI technology and certified professional oversight to deliver personalized health insights.
  • [+] PRIVACY_LOCK: Your privacy is our strict priority. Your data will only be used for this specific diagnostic purpose.

> SYS.UPLOAD: Share Medical Records [OPTIONAL]_

[ USER_CONTROL_ACTIVE ] Uploading your medical records during registration is entirely optional. You can choose to bypass this step and provide data later if it suits your timeline.

You dictate the data flow: share as much or as little as you’re comfortable with, and let us guide you toward better health.

[+] FORMAT_SUPPORT

We accept all file formats, including photos, PDFs, text documents, and raw official medical data.

[+] DATA_YIELD

Increased inputs correlate with higher precision. The more info you share, the better we tailor your personalized insights.

> NEXT_STEPS: Post-Registration Protocol_

Once your registration is complete, a human specialist from our team will personally reach out to you within 3-10 business days. We will discuss your health journey and map out exactly how we can support you.

About the Author: Bernard Aybout (Virii8)

Avatar Of Bernard Aybout (Virii8)
I am a dedicated technology enthusiast with over 45 years of life experience, passionate about computers, AI, emerging technologies, and their real-world impact. As the founder of my personal blog, MiltonMarketing.com, I explore how AI, health tech, engineering, finance, and other advanced fields leverage innovation—not as a replacement for human expertise, but as a tool to enhance it. My focus is on bridging the gap between cutting-edge technology and practical applications, ensuring ethical, responsible, and transformative use across industries. MiltonMarketing.com is more than just a tech blog—it's a growing platform for expert insights. We welcome qualified writers and industry professionals from IT, AI, healthcare, engineering, HVAC, automotive, finance, and beyond to contribute their knowledge. If you have expertise to share in how AI and technology shape industries while complementing human skills, join us in driving meaningful conversations about the future of innovation. 🚀