{"id":1319,"date":"2024-11-22T11:23:35","date_gmt":"2024-11-22T19:23:35","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1319"},"modified":"2024-11-22T11:23:37","modified_gmt":"2024-11-22T19:23:37","slug":"phishing-from-11-18-2024-your-email-suspension-notification-received","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1319","title":{"rendered":"Phishing from 11\/18\/2024: &#8220;Your Email Suspension-notification Received&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: shizusan[@]sky[.]plala[.]or[.]jp<br><strong>Subject<\/strong>: Your Email Suspension-notification Received 33bd7b2a52119311bcc14d54f682a043|12:12:52 AM<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"521\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-1024x521.png\" alt=\"\" class=\"wp-image-1320\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-1024x521.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-300x153.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-768x390.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish.png 1129w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Where did the link lead?<\/p>\n\n\n\n<p>The link led to a fake website hosted on storage[.]bunnycdn[.]com mimicking the main pugetsound.edu website. The fake website is designed to steal your password. Never enter your password on sites you do not recognize. Always investigate links before clicking and\/or check the URL bar in your browser to confirm what website you are visiting.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-1024x516.png\" alt=\"\" class=\"wp-image-1321\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-1024x516.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-300x151.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-768x387.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-1536x774.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link-1440x725.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/11\/11-18-24-email-suspension-phish-link.png 1906w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The email is coming from a suspicious email address, shizusan[@]sky[.]plala[.]or[.]jp. <\/li><li>Notice that &#8220;Puget Sound&#8221; is spelled &#8220;Pugetsound&#8221; in the email and on the phishing site. <\/li><li>Technology Services will not ask you to click a link in an email to re-activate your email account. Beware of urgent emails attempting to impersonate the IT department. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: shizusan[@]sky[.]plala[.]or[.]jp <br><strong>Subject<\/strong>: Your Email Suspension-notification Received 33bd7b2a52119311bcc14d54f682a043|12:12:52 AM <\/p>\n\n\n\n<p>Mailbox Notification!<\/p>\n\n\n\n<p>Dear [<em>username removed<\/em>],<\/p>\n\n\n\n<p>You have some incoming messages that are placed on hold-([<em>username<\/em>]@pugetsound.edu), due to mailbox upgrades.<\/p>\n\n\n\n<p>Kindly RE-ACTIVATE your account below to access incoming messages 11\/19\/2024.<\/p>\n\n\n\n<p>RE-ACTIVATE HERE<\/p>\n\n\n\n<p>Failure to re-activate your mailbox might lead to suspension.<\/p>\n\n\n\n<p>Best Regards<\/p>\n\n\n\n<p>Pugetsound Administrator.<\/p>\n\n\n\n<p>\u00a9 2024 pugetsound.edu Administrator. All Rights Reserved.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: shizusan[@]sky[.]plala[.]or[.]jpSubject: Your Email Suspension-notification Received 33bd7b2a52119311bcc14d54f682a043|12:12:52 AM Where did the link lead? The link led to a fake website hosted on storage[.]bunnycdn[.]com mimicking the main pugetsound.edu website. The fake website is designed to steal your password. Never enter your password on sites you do not recognize. Always investigate links before clicking [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1320,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-1319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1319"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1319\/revisions"}],"predecessor-version":[{"id":1322,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1319\/revisions\/1322"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1320"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}