{"id":1190,"date":"2024-02-13T08:30:12","date_gmt":"2024-02-13T16:30:12","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1190"},"modified":"2024-02-13T08:32:37","modified_gmt":"2024-02-13T16:32:37","slug":"phishing-from-2-13-24-re-it-microsoft-outlook-update","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1190","title":{"rendered":"Phishing from 2\/13\/24: &#8220;Re: IT Microsoft Outlook Update&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> llindsay[@]misd[.]net<br><strong>Subject: <\/strong>Re: IT Microsoft Outlook Update<br><strong>Subject<\/strong>: Re: Mailbox Migration<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"666\" height=\"452\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish.jpg\" alt=\"\" class=\"wp-image-1191\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish.jpg 666w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-300x204.jpg 300w\" sizes=\"auto, (max-width: 666px) 100vw, 666px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The university uses Google Mail which does not require using Outlook. This should raise suspicion. <\/li><li>Notice the sender&#8217;s email is from the misd[.]net domain. Emails from Technology Services will generally come from a pugetsound.edu email. <\/li><li>Hovering over the link reveals that it goes to bestrollingstoneconcert[.]com\/sr\/ which is not a pugetsound.edu site.<\/li><li>Notice the false sense of urgency in the email with wording such as &#8220;take effect now&#8221; and &#8220;lose your account&#8221;.<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a fake Outlook Web App login page. Never enter your credentials on sites you do not recognize. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"522\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-link-1024x522.jpg\" alt=\"\" class=\"wp-image-1192\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-link-1024x522.jpg 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-link-300x153.jpg 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-link-768x391.jpg 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-13-24-outlook-phish-link.jpg 1299w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> llindsay[@]misd[.]net<br><strong>Subject: <\/strong>Re: IT Microsoft Outlook Update <br><strong>Subject<\/strong>: Re: Mailbox Migration <\/p>\n\n\n\n<p>To All,<\/p>\n\n\n\n<p>We are migrating all email accounts into the latest Microsoft Outlook 2024 and as such all active Account holders are to verify and Log in for the upgrade and migration to take effect now. This is done to improve the security and efficiency.<\/p>\n\n\n\n<p>Click Microsoft Outlook Portal for migration.<\/p>\n\n\n\n<p>Note: You might lose your account if you fail to Migrate to the latest Outlook web App webmail.<\/p>\n\n\n\n<p>Best Regards,<br>Lindsay Lynda<br>ITS Help-desk<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: llindsay[@]misd[.]netSubject: Re: IT Microsoft Outlook UpdateSubject: Re: Mailbox Migration Tips for Detection The university uses Google Mail which does not require using Outlook. This should raise suspicion. Notice the sender&#8217;s email is from the misd[.]net domain. Emails from Technology Services will generally come from a pugetsound.edu email. Hovering over the link [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1191,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-1190","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1190"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1190\/revisions"}],"predecessor-version":[{"id":1194,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1190\/revisions\/1194"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1191"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}