{"id":493,"date":"2021-11-02T12:28:08","date_gmt":"2021-11-02T19:28:08","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=493"},"modified":"2021-11-02T12:28:10","modified_gmt":"2021-11-02T19:28:10","slug":"phishing-from-11-1-2021-update","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/493","title":{"rendered":"Phishing from 11\/1\/2021: &#8220;UPDATE&#8221;"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><strong><em>NOTE: If you received this message, please delete it as it is NOT legitimate. Do not click on the link.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"310\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-phish.png\" alt=\"\" class=\"wp-image-494\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-phish.png 1000w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-phish-300x93.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-phish-768x238.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Where Did the Link Lead?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"535\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link-1024x535.png\" alt=\"\" class=\"wp-image-495\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link-1024x535.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link-300x157.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link-768x401.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link-1440x752.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/11\/11-1-21-account-deactivate-link.png 1442w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The link takes you to an online form masquerading as a Microsoft login page that asks you to submit your email and password. Never submit sensitive information in an online form. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Legitimate emails from Technology Services will come from an @pugetsound.edu address.<\/li><li>Technology Services will <span style=\"text-decoration: underline;\">NEVER<\/span><em> <\/em>ask for your login information<span style=\"text-decoration: underline;\"><\/span>.<\/li><li>The URL for the login page is not a Microsoft or Puget Sound page.<\/li><li>Emails with a sense of urgency threatening to cut off services or benefits are extremely common in phishing scams.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Text of Phishing Message<\/h2>\n\n\n\n<p><strong>From<\/strong>: a[.]ormoshev[@]mlsp[.]kg<br><strong>Reply-To: <\/strong>despi[_]greenzone[@]outlook[.]com<br><strong>Subject: <\/strong>UPDATE<br><br>Hello<\/p>\n\n\n\n<p>Your Email account will be Deactivated shortly. <br>To stop Deactivation, CLICK HERE and log in<br><br>Thanks<br><br>IT Service Desk<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please delete it as it is NOT legitimate. Do not click on the link. Where Did the Link Lead? The link takes you to an online form masquerading as a Microsoft login page that asks you to submit your email and password. Never submit sensitive information [&hellip;]<\/p>\n","protected":false},"author":635,"featured_media":494,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/635"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=493"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/493\/revisions"}],"predecessor-version":[{"id":496,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/493\/revisions\/496"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/494"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}