Been observing rampant phishing activity targeting people of Ukraine offering Visa as bait.
Links formatted particularly like this are being forwarded inside emails/chat:
https://evisa.mfa.gov.ua:login@%6D%61%6C%69%63%69%6F%75%73%2E%73%69%74%65
A quick glance will convince any user that the link will lead you to the login portal of https://evisa.mfa.gov.ua
. But it won't. Clicking the link in the browser will lead you to the domain https://malicious.site
.
Why? A root URL format looks like this (as defined in RFC 1808, Section 2.1
):