{"id":296,"date":"2021-03-01T08:24:04","date_gmt":"2021-03-01T16:24:04","guid":{"rendered":"http:\/\/blogs.pugetsound.edu\/infosec\/?p=296"},"modified":"2021-03-01T08:33:14","modified_gmt":"2021-03-01T16:33:14","slug":"phishing-from-3-1-2021-re-ithelp-survey-invitation","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/296","title":{"rendered":"Phishing from 3\/1\/2021: &#8220;RE: ITHelp Survey invitation&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message, please simply delete the message. Do not click any links and do not enter or reply with any information<\/em>. <\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"322\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-1024x322.jpg\" alt=\"\" class=\"wp-image-298\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-1024x322.jpg 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-300x94.jpg 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-768x241.jpg 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-1536x482.jpg 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1-1440x452.jpg 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-1.jpg 1872w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the &#8220;Caution&#8221; banner that was applied to the top of the message. Technology Services adds the banner on emails that match patterns of previous phishing attempts. <\/li><li>The sending email address is from the cornwallhospital[.]ca domain. This is <strong>not <\/strong>a Puget Sound address. <\/li><li>The link in the email leads to ithelpsurveyinvitationportal[.]godaddysites[.]com which is <strong>not<\/strong> a Puget Sound site. <\/li><li>Technology Services does utilize a ticketing system. Any legitimate survey request or ticket update will come from an @pugetsound.edu address and links in those emails will begin with https:\/\/kbox.pugetsound.edu. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where did the link lead?<\/p>\n\n\n\n<p>The link led to a fraudulent survey portal that asked for your username, email, and password. <strong><em>Note: If you entered your credentials on this page, please immediately change your password and contact the Service Desk at x8585. Your credentials are likely compromised. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"537\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link-1024x537.jpg\" alt=\"\" class=\"wp-image-299\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link-1024x537.jpg 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link-300x157.jpg 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link-768x403.jpg 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link-1440x755.jpg 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/03\/3-1-21-it-help-survey-link.jpg 1465w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p>From: Sonya.Marleau-Bonacci[@]cornwallhospital[.]ca<br>Subject: E: ITHelp Survey invitation<\/p>\n\n\n\n<p>You have been invited to take a Satisfaction survey for a recent IT-Help ticket.<br>here to take your survey<br>To view your survey queue at any time, sign in and navigate to Self-Service &gt; My Assessments &amp; Surveys.<\/p>\n\n\n\n<p>Additional details about this Survey are:<br>Number #: INC1798292<br>Short Description: HELP-DESK ALERT.<br>Description:<br>Resolved Date: Today<br>Ref:MSG5211182<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, please simply delete the message. Do not click any links and do not enter or reply with any information. Tips for Detection Notice the &#8220;Caution&#8221; banner that was applied to the top of the message. Technology Services adds the banner on emails that match patterns of [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":298,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=296"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/296\/revisions"}],"predecessor-version":[{"id":301,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/296\/revisions\/301"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/298"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}