{"id":1196,"date":"2024-02-21T08:45:36","date_gmt":"2024-02-21T16:45:36","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1196"},"modified":"2024-02-21T08:45:38","modified_gmt":"2024-02-21T16:45:38","slug":"phishing-from-2-21-2024-re-it-report","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1196","title":{"rendered":"Phishing from 2\/21\/2024: &#8220;Re: *** IT Report ***&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: jmaster[@]misd[.]net<br><strong>Subject:<\/strong> Re: *** IT Report ***<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"668\" height=\"553\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-23-24-it-report-phish.jpg\" alt=\"\" class=\"wp-image-1197\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-23-24-it-report-phish.jpg 668w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-23-24-it-report-phish-300x248.jpg 300w\" sizes=\"auto, (max-width: 668px) 100vw, 668px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link <em>foreversentiments[.]com\/as<\/em> led to a fake Outlook Web App login page. Always hover over links to see where they lead. Do not enter your credentials on websites you do not recognize or on online forms.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"962\" height=\"477\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-21-24-it-report-phish-link.jpg\" alt=\"\" class=\"wp-image-1198\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-21-24-it-report-phish-link.jpg 962w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-21-24-it-report-phish-link-300x149.jpg 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/02\/2-21-24-it-report-phish-link-768x381.jpg 768w\" sizes=\"auto, (max-width: 962px) 100vw, 962px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the sender&#8217;s email is not @pugetsound.edu and the odd subject line.<\/li><li>An email platform (e.g. Outlook) is not typically where you would access pay slips. The inconsistency in what is changing should be a red flag.<\/li><li>Be aware of what tools the university provides. If phishing messages mention tools no longer provided or supported, that should be a red flag. <\/li><li>Notice the false sense of urgency (e.g. &#8220;MIGRATE immediately&#8221;)<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: jmaster[@]misd[.]net<br><strong>Subject:<\/strong> Re: *** IT Report *** <\/p>\n\n\n\n<p>To All,<\/p>\n\n\n\n<p>Welcome to the new Web-Mail for Staff Single Sign-on. Migrate to the new Outlook Web app for Staff is the new home for online self-service and information.<\/p>\n\n\n\n<p>Click on GATEWAY and login to:<\/p>\n\n\n\n<p>\u2022 Access the new staff directory<br>\u2022 Access your pay slips and P60s<br>\u2022 Update your ID photo<br>\u2022 E-mail and Calendar Flexibility<br>\u2022 Connect mobile number to e-mail for Voicemail<\/p>\n\n\n\n<p>Everyone is advise to MIGRATE immediately.<\/p>\n\n\n\n<p>Please note that if this message is ignored you will experience difficulty in sending and receiving of email messages through our secure Web-mail Portal<\/p>\n\n\n\n<p>Thanks<br>IT Service Desk<br>Copyright \u00a9<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: jmaster[@]misd[.]netSubject: Re: *** IT Report *** Where Did the Link Lead? The link foreversentiments[.]com\/as led to a fake Outlook Web App login page. Always hover over links to see where they lead. Do not enter your credentials on websites you do not recognize or on online forms. Tips for Detection Notice [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1197,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-1196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1196"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1196\/revisions"}],"predecessor-version":[{"id":1199,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1196\/revisions\/1199"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1197"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}