{"id":263,"date":"2021-01-29T13:12:34","date_gmt":"2021-01-29T21:12:34","guid":{"rendered":"http:\/\/blogs.pugetsound.edu\/infosec\/?p=263"},"modified":"2021-01-29T13:12:35","modified_gmt":"2021-01-29T21:12:35","slug":"phishing-from-1-29-2021-progressive-billing-2-for-pugetsound","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/263","title":{"rendered":"Phishing from 1\/29\/2021: &#8220;Progressive Billing #2 for Pugetsound&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><em>Note: If you received this message, simply delete the message as it is not legitimate. Do not open the attachment or supply credentials. <\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"645\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phisih.png\" alt=\"\" class=\"wp-image-264\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phisih.png 867w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phisih-300x223.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phisih-768x571.png 768w\" sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Always check the sender&#8217;s email address! Though the display name says &#8220;Pugetsound&#8221;, the message was sent from an @califacoustics.com email address. <\/li><li>Notice that in both the display name and subject line, Puget Sound is written as &#8220;Pugetsound&#8221; which is atypical when referring to the university. <\/li><li>The inclusion of a Puget Sound logo in an email does not necessarily mean the email is legitimate. Our logo can easily be found on our public website and misused by attackers. <\/li><li>Technology Services does not currently offer any fax to email service. If you receive any emails about a new faxed document, it is most likely not legitimate. <\/li><li>This email contained an attachment with a <strong>.htm <\/strong>file extension. Generally, use caution with attachments that are <strong>.htm<\/strong> or <strong>.html<\/strong> since attackers commonly use them to open fraudulent webpages in your browser to try to steal your credentials. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">What was in the attachment? <\/p>\n\n\n\n<p>The attachment did not contain any malware. However, it would have opened a webpage with a fake Microsoft Office 365 login page with your email address pre-filled. If you tried to sign in, your password would have been sent straight to the attacker who would then have access to your account. <strong><em>Note: if you entered credentials at this step, please immediately contact the Service Desk at x8585 as your account may be compromised. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"518\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phish-htm-1024x518.png\" alt=\"\" class=\"wp-image-265\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phish-htm-1024x518.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phish-htm-300x152.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phish-htm-768x388.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/01\/1-29-21-fax-phish-htm.png 1331w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p>From: katie[@]califacoustics[.]com<br>Subject: Progressive Billing #2 for Pugetsound<\/p>\n\n\n\n<p>New Fax Received For [<em>username<\/em>]<\/p>\n\n\n\n<p>You have a new fax document from (677) 677 &#8211; 5744.<\/p>\n\n\n\n<p>Pages 2 Full scanned PDF.<br>Received 29, Jan 2021<br>Recipient [<em>username<\/em>]@pugetsound.edu<\/p>\n\n\n\n<p>To view FAX messages, open the attachment and login with your office email to authenticate viewer and enable instant access to all your fax messages on the go.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, simply delete the message as it is not legitimate. Do not open the attachment or supply credentials. Tips for Detection Always check the sender&#8217;s email address! Though the display name says &#8220;Pugetsound&#8221;, the message was sent from an @califacoustics.com email address. Notice that in both the [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":264,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=263"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/263\/revisions"}],"predecessor-version":[{"id":266,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/263\/revisions\/266"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/264"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}