{"id":647,"date":"2022-02-11T10:18:05","date_gmt":"2022-02-11T18:18:05","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=647"},"modified":"2022-02-11T10:18:07","modified_gmt":"2022-02-11T18:18:07","slug":"phishing-from-2-11-2022-help-desk","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/647","title":{"rendered":"Phishing from 2\/11\/2022: &#8220;Help Desk&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please simply delete it as it is NOT legitimate. Do not click the link or enter your credentials. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"998\" height=\"313\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-phish.png\" alt=\"\" class=\"wp-image-648\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-phish.png 998w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-phish-300x94.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-phish-768x241.png 768w\" sizes=\"auto, (max-width: 998px) 100vw, 998px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Please use extra caution on emails that contain the maroon &#8220;Caution&#8221; banner prepended to the message. These messages originate from outside the university and match patterns of other phishing attempts.<\/li><li>Legitimate messages from Technology Services will come from an @pugetsound.edu email address. Notices regarding email capacity are sent prior to a mailbox being 98% full. <\/li><li>If you are unsure whether your mailbox is full, you can log in to webmail.pugetsound.edu to check your current mailbox usage. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a fake Outlook sign in page. Remember &#8211; do not enter your credentials on online forms or on sites you do not recognize. Always check the URL. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"444\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-1024x444.png\" alt=\"\" class=\"wp-image-649\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-1024x444.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-300x130.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-768x333.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-1536x666.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link-1440x624.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-11-22-mailbox-full-link.png 1915w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>samwel.bushukatale[@]muhas[.]ac[.]tz<br><strong>Subject:<\/strong> Help Desk<\/p>\n\n\n\n<p>Your mailbox storage has reached 98% on the email server. Visit OutlookStorage Access Page [<em>link removed<\/em>] and login to adjust and maintain your Mailbox storage.<\/p>\n\n\n\n<p>At 100% limit, these email features:<\/p>\n\n\n\n<p>\u00b7 Sending messages<\/p>\n\n\n\n<p>\u00b7 Receiving messages<\/p>\n\n\n\n<p>\u00b7 Forwarding messages<\/p>\n\n\n\n<p>Will not be available for your utilization.<\/p>\n\n\n\n<p>IT Help Desk<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please simply delete it as it is NOT legitimate. Do not click the link or enter your credentials. Tips for Detection Please use extra caution on emails that contain the maroon &#8220;Caution&#8221; banner prepended to the message. These messages originate from outside the university and match [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":648,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=647"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/647\/revisions"}],"predecessor-version":[{"id":650,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/647\/revisions\/650"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/648"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}