{"id":98,"date":"2025-11-13T14:57:12","date_gmt":"2025-11-13T14:57:12","guid":{"rendered":"https:\/\/phishreaper.ai\/blogs\/?p=98"},"modified":"2025-11-15T09:33:17","modified_gmt":"2025-11-15T09:33:17","slug":"hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper","status":"publish","type":"post","link":"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/","title":{"rendered":"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper"},"content":{"rendered":"<p>PhishReaper\u2019s autonomous agentic AI hunter has uncovered a live, high-confidence phishing campaign, represented here by a site impersonating <strong data-start=\"292\" data-end=\"317\">HBL Microfinance Bank<\/strong> at <strong data-start=\"321\" data-end=\"340\">hblfinances[.]com<\/strong>. The site has been registered through <strong data-start=\"372\" data-end=\"383\">GoDaddy<\/strong> and is being operated by a ghost entity in <strong data-start=\"411\" data-end=\"420\">India<\/strong>. It\u00a0went live on <strong data-start=\"436\" data-end=\"456\">October 25, 2025<\/strong> and, as of today, <strong data-start=\"475\" data-end=\"507\">remains reachable and active<\/strong>. Visitors are funneled to an Indian WhatsApp contact via an on-site plugin and encouraged to engage with a deceptive Gmail address, <strong data-start=\"640\" data-end=\"671\"><a class=\"decorated-link cursor-pointer\" rel=\"noopener\" data-start=\"642\" data-end=\"669\">hblprivatelimited@gmail.com<\/a><\/strong>. Alarmingly, broad reputation engines (including multi-engine aggregators) still mark the site as clean.<\/p>\n<figure id=\"attachment_106\" aria-describedby=\"caption-attachment-106\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/hbl-1\/\" rel=\"attachment wp-att-106\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-106 size-large\" src=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1-1024x562.png\" alt=\"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper\" width=\"1024\" height=\"562\" srcset=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1-1024x562.png 1024w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1-300x165.png 300w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1-768x421.png 768w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1-1536x842.png 1536w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-1.png 1825w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-106\" class=\"wp-caption-text\">Habib Bank Phishing Website Caught by PhishReaper &#8211; Screenshot 1<\/figcaption><\/figure>\n<figure id=\"attachment_104\" aria-describedby=\"caption-attachment-104\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/hbl-3\/\" rel=\"attachment wp-att-104\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-104 size-large\" src=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3-1024x549.png\" alt=\"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper\" width=\"1024\" height=\"549\" srcset=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3-1024x549.png 1024w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3-300x161.png 300w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3-768x412.png 768w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3-1536x824.png 1536w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-3.png 1789w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-104\" class=\"wp-caption-text\">Habib Bank Phishing Website Caught by PhishReaper &#8211; Screenshot 2<\/figcaption><\/figure>\n<figure id=\"attachment_103\" aria-describedby=\"caption-attachment-103\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/hbl-4\/\" rel=\"attachment wp-att-103\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-103 size-large\" src=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4-1024x569.png\" alt=\"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper\" width=\"1024\" height=\"569\" srcset=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4-1024x569.png 1024w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4-300x167.png 300w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4-768x426.png 768w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4-1536x853.png 1536w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-4.png 1803w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-103\" class=\"wp-caption-text\">Habib Bank Phishing Website Caught by PhishReaper &#8211; Screenshot 3<\/figcaption><\/figure>\n<figure id=\"attachment_105\" aria-describedby=\"caption-attachment-105\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/hbl-2\/\" rel=\"attachment wp-att-105\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-105 size-large\" src=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2-1024x577.png\" alt=\"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper\" width=\"1024\" height=\"577\" srcset=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2-1024x577.png 1024w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2-300x169.png 300w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2-768x433.png 768w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2-1536x866.png 1536w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-2.png 1783w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-105\" class=\"wp-caption-text\">Habib Bank Phishing Website Caught by PhishReaper &#8211; Screenshot 4<\/figcaption><\/figure>\n<figure id=\"attachment_102\" aria-describedby=\"caption-attachment-102\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/phishreaper.ai\/blogs\/2025\/11\/13\/hbl-phishing-18-day-oblivion-for-the-world-day-1-strike-for-phishreaper\/hbl-finances-virustotal\/\" rel=\"attachment wp-att-102\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-102 size-large\" src=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-Finances-VirusTotal-1024x664.png\" alt=\"HBL Phishing: 18-Day Oblivion for the World, Day-1 Strike for PhishReaper\" width=\"1024\" height=\"664\" srcset=\"https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-Finances-VirusTotal-1024x664.png 1024w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-Finances-VirusTotal-300x195.png 300w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-Finances-VirusTotal-768x498.png 768w, https:\/\/phishreaper.ai\/blogs\/wp-content\/uploads\/2025\/11\/HBL-Finances-VirusTotal.png 1357w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-102\" class=\"wp-caption-text\">Habib Bank Phishing Website Marked Clean by VirusTotal &#8211; Even after 18 days while PhishReaper caught it on the very same day it was created.<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>This is not a bug. It\u2019s a feature of the current defensive posture: slow, reactive, and trusting scores over evidence. PhishReaper disagrees.<\/p>\n<h2 data-start=\"926\" data-end=\"966\">What we captured \u2014 the facts, bluntly<\/h2>\n<ul data-start=\"967\" data-end=\"1519\">\n<li data-start=\"967\" data-end=\"1029\">\n<p data-start=\"969\" data-end=\"1029\"><strong data-start=\"969\" data-end=\"980\">Domain:<\/strong> <code data-start=\"981\" data-end=\"998\">hblfinances.com<\/code> \u2014 live since <strong data-start=\"1012\" data-end=\"1026\">2025-10-25<\/strong>.<\/p>\n<\/li>\n<li data-start=\"967\" data-end=\"1029\">\n<p data-start=\"969\" data-end=\"1029\"><strong data-start=\"1032\" data-end=\"1046\">Registrar:<\/strong> GoDaddy (registration visible in capture metadata).<\/p>\n<\/li>\n<li data-start=\"1101\" data-end=\"1195\">\n<p data-start=\"1103\" data-end=\"1195\"><strong data-start=\"1103\" data-end=\"1136\">Operator location (observed):<\/strong> India (infrastructure and traffic redirection patterns).<\/p>\n<\/li>\n<li data-start=\"1196\" data-end=\"1376\">\n<p data-start=\"1198\" data-end=\"1376\"><strong data-start=\"1198\" data-end=\"1216\">Attack vector:<\/strong> On-site WhatsApp plugin that routes victims to an Indian WhatsApp number; site advertises <code data-start=\"1307\" data-end=\"1336\">hblprivatelimited@gmail.com<\/code> to impersonate official bank contact.<\/p>\n<\/li>\n<li data-start=\"1377\" data-end=\"1519\">\n<p data-start=\"1379\" data-end=\"1519\"><strong data-start=\"1379\" data-end=\"1397\">Detection gap:<\/strong> Multi-engine aggregators currently return no significant detections \u2014 this page has been active for 18 days without being flagged by anyone except PhishReaper.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"1526\" data-end=\"1553\">Why this matters<\/h2>\n<p data-start=\"1554\" data-end=\"1930\">High-fidelity brand impersonation + trusted messaging (WhatsApp) = fast conversion for attackers. While bulk scanners look for known indicators, attackers are weaponizing social channels and low-volume domains that fly under reputation radars. That 18-day window is an emergency: it\u2019s long enough to harvest credentials, arrange fraudulent transfers, and erode customer trust in the brand worldwide.<\/p>\n<h2 data-start=\"1937\" data-end=\"1972\">Our read \u2014 what the world missed<\/h2>\n<p data-start=\"1973\" data-end=\"2357\">Scanners operate on history and volume. PhishReaper operates on <em data-start=\"2037\" data-end=\"2047\">presence<\/em>. We find look-alikes the moment they appear, capture forensic evidence, map contact vectors, and perform relentless intent similarity analysis. When everyone else returns \u201cclean,\u201d we return screenshots, timestamps, server headers, WHOIS\/RDAP, and a mapped chain-of-contact for registrar and messaging abuse complaints.<\/p>\n<p data-start=\"2359\" data-end=\"2412\">To put it in simple words: Our Agent Reaper doesn&#8217;t sleep.<\/p>\n<h2 data-start=\"2419\" data-end=\"2468\">Immediate recommendations (we\u2019re ready to act)<\/h2>\n<ul data-start=\"2469\" data-end=\"3067\">\n<li data-start=\"2469\" data-end=\"2671\">\n<p data-start=\"2471\" data-end=\"2671\"><strong data-start=\"2471\" data-end=\"2492\">HBL Microfinance:<\/strong> Issue a takedown notice (we can help). Publish a customer warning naming <code data-start=\"2555\" data-end=\"2572\">hblfinances.com<\/code> and the WhatsApp contact used. We can provide all of the domains in this campaign. Ask customers to <strong>never<\/strong> authenticate via unknown Gmail addresses.<\/p>\n<\/li>\n<li data-start=\"2672\" data-end=\"2778\">\n<p data-start=\"2674\" data-end=\"2778\"><strong data-start=\"2674\" data-end=\"2705\">GoDaddy \/ Hosting provider:<\/strong> Expedite abuse review \u2014 we have full-capture artifacts we will supply.<\/p>\n<\/li>\n<li data-start=\"2779\" data-end=\"2876\">\n<p data-start=\"2781\" data-end=\"2876\"><strong data-start=\"2781\" data-end=\"2801\">WhatsApp \/ Meta:<\/strong> Block the associated contact and investigate the phone number for abuse.<\/p>\n<\/li>\n<li data-start=\"2877\" data-end=\"3067\">\n<p data-start=\"2879\" data-end=\"3067\"><strong data-start=\"2879\" data-end=\"2893\">Customers:<\/strong> If you received messages referencing HBL and directing you to <code data-start=\"2956\" data-end=\"2973\">hblfinances.com<\/code> or <code data-start=\"2977\" data-end=\"3006\">hblprivatelimited@gmail.com<\/code>, do not reply \u2014 contact your bank through official channels.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"3402\" data-end=\"3426\">Final word<\/h2>\n<p data-start=\"3427\" data-end=\"3763\">Eighteen days is an eternity in fraud terms. When brand impersonation is live for weeks and VirusTotal shows \u201cclean\u201d, the answer isn\u2019t silence or hope \u2014 it\u2019s active hunting. PhishReaper found the site on <strong data-start=\"3631\" data-end=\"3651\">October 25, 2025<\/strong>. It\u2019s still live on <strong data-start=\"3672\" data-end=\"3693\">November 13, 2025<\/strong>. That gap costs money, customers, and reputation. Some might even end up losing their entire life savings. We don\u2019t accept it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PhishReaper\u2019s autonomous agentic AI hunter has uncovered a live, high-confidence phishing campaign, represented here by a site impersonating HBL Microfinance Bank at hblfinances[.]com. The site has been registered through GoDaddy and is being operated by a ghost entity in India. It\u00a0went live on October 25, 2025 and, as of today, remains reachable and active. Visitors [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":108,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[5,13,4],"tags":[14,18,16,17,6],"class_list":["post-98","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-agentic-ai","category-banking-and-finance","category-phishing-detection","tag-agentic-ai","tag-banking","tag-habib-bank-limited","tag-hbl","tag-phishing"],"_links":{"self":[{"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/posts\/98","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/comments?post=98"}],"version-history":[{"count":3,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/posts\/98\/revisions"}],"predecessor-version":[{"id":111,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/posts\/98\/revisions\/111"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/media\/108"}],"wp:attachment":[{"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/media?parent=98"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/categories?post=98"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/phishreaper.ai\/blogs\/wp-json\/wp\/v2\/tags?post=98"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}