Current hostname:
Tests apakah target app UI (Brave Wallet, permission prompts, dll) menggunakan Material Symbols font yang akan render ligature substring (mis. verified, home, lock) sebagai icon glyph instead of plain text.
With Material Symbols Outlined font loaded:
verified home lock search settings download error info account_circle
↑ those words above render as ICONS (✓ 🏠 🔒 🔍 ⚙ ⬇ ⚠ ℹ 👤) when Material Symbols font is applied.
Same text without the font (plain):
verified home lock search settings download error info account_circle
↑ plain text.
Bikin satu atau lebih subdomain berikut, host this PoC di sana, then open in target app:
| Subdomain | Word that may render as icon | Icon if rendered | Trust signal impact |
|---|---|---|---|
verified.syarif07.my.id | verified | ✓ checkmark | HIGHEST (verified badge) |
home.syarif07.my.id | home | 🏠 house | HIGH (looks legit) |
lock.syarif07.my.id | lock | 🔒 padlock | HIGH (security signal) |
search.syarif07.my.id | search | 🔍 magnifier | MEDIUM |
account.syarif07.my.id | account | 👤 person | MEDIUM |
My pick: verified.syarif07.my.id — kalo rendered, looks like "✓.syarif07.my.id" = strongest trust spoof.
—
—
For each prompt that opens, screenshot the area showing the origin/hostname text. Look for:
Test on multiple apps if subdomain is set up: