I'm not aware of any CP detection being triggered only based on the SSID. (What does it do if there actually isn't a CP?) ...
An attacker gets a LOT more mileage out of a Open SSID evil twin with NO captive portal if the desire is to capture cookies... Any attacker that gets tripped up by clients doing a Sandboxed browser isn't a very good attacker :)
David