{"id":270,"date":"2021-02-08T09:58:01","date_gmt":"2021-02-08T17:58:01","guid":{"rendered":"http:\/\/blogs.pugetsound.edu\/infosec\/?p=270"},"modified":"2021-02-08T10:04:30","modified_gmt":"2021-02-08T18:04:30","slug":"phishing-from-2-8-2021-aw-its-help-desk","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/270","title":{"rendered":"Phishing from 2\/8\/2021: &#8220;AW: ITS Help-Desk&#8221;"},"content":{"rendered":"\n<p style=\"font-size:25px\">Original Phishing Message<\/p>\n\n\n\n<p><em>Note: If you received this message, please simply delete it. The email is<strong> not <\/strong>legitimate. If you clicked the link and entered your credentials on the site, please immediately contact the Service Desk at x8585 as your account may be compromised. <\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"487\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-phish-1024x487.png\" alt=\"\" class=\"wp-image-272\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-phish-1024x487.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-phish-300x143.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-phish-768x365.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-phish.png 1360w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p style=\"font-size:25px\">Tips For Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the &#8220;Caution&#8221; banner prepended to the email. The banner is added by Technology Serivces on email messages that match patterns of previous phishing attempts. Be especially wary of replying, clicking links, or opening attachments when you see this.<\/li><li>Always check the sender&#8217;s email address. This email orginated from stefanie.sjuts[@]jade-hs[.]de which is clearly not a Puget Sound address. <\/li><li>Technology Services will not ask you to click a link to &#8220;update&#8221; your email account. <\/li><\/ul>\n\n\n\n<p style=\"font-size:25px\">Where did the link lead?<\/p>\n\n\n\n<p>The link in the email led to a fake Outlook Web Access sign in page. Remember to always hover over links in emails to see where they lead. In this case, the link led to microsoft0[.]moonfruit[.]com. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"391\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-1024x391.png\" alt=\"\" class=\"wp-image-271\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-1024x391.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-300x115.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-768x293.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-1536x587.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link-1440x550.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-8-21-owa-upgrade-link.png 1654w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p style=\"font-size:25px\">Text of Phishing Message<\/p>\n\n\n\n<p>From: stefanie.sjuts[@]jade-hs[.]de<br>Subject: AW: ITS Help-Desk<\/p>\n\n\n\n<p>To All Employees\\Staff,<\/p>\n\n\n\n<p>Take note of this important update that our new web mail has been improved with a new messaging system from Owa\/outlook which also include faster usage on email, shared calendar,web-documents and the new 2021 anti-spam version.<\/p>\n\n\n\n<p>Kindly use the link below to complete your 2021 Outlook Webmail User authentication form.<br>CLICK on ( Outlook Web Access ) to update immediately.<br>Best Regards,<br>ITS Help-Desk<br>Office of Information Technology Services (ITS)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, please simply delete it. The email is not legitimate. If you clicked the link and entered your credentials on the site, please immediately contact the Service Desk at x8585 as your account may be compromised. Tips For Detection Notice the &#8220;Caution&#8221; banner prepended to the email. [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":272,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-270","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=270"}],"version-history":[{"count":4,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/270\/revisions"}],"predecessor-version":[{"id":278,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/270\/revisions\/278"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/272"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}