logo

Virtual Machine Aware Phishing Sites

ID: 0a16aed0-a1c7-52f0-af49-e948ec1e517f

STIX ID: report--0a16aed0-a1c7-52f0-af49-e948ec1e517f

Feed Name: On the Hunt

Threat Score
50/100

Date Published: 2021-08-03

Date Updated: 2026-04-19

Author: Paul Newton

...
...

The report examines a DHL-themed phishing page that uses WebGL's WEBGL_debug_renderer_info and screen properties (color depth and resolution) to detect virtual machines or headless/bot environments and withhold the malicious content when such environments are detected. The analyst links the payload to a ‘m3dular’ phish kit, provides example phishing URLs and mail IOCs (including a sender IP), and highlights the anti-analysis techniques used by the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.