{"id":660,"date":"2022-02-22T09:15:39","date_gmt":"2022-02-22T17:15:39","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=660"},"modified":"2022-02-22T09:15:41","modified_gmt":"2022-02-22T17:15:41","slug":"phishing-from-2-21-2022-your-microsoft-365-business-is-expired","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/660","title":{"rendered":"Phishing from 2\/21\/2022: &#8220;Your Microsoft 365 Business is expired&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please simply delete it as it is not legitimate. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"994\" height=\"677\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-1.png\" alt=\"\" class=\"wp-image-662\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-1.png 994w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-1-300x204.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-1-768x523.png 768w\" sizes=\"auto, (max-width: 994px) 100vw, 994px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a fake Microsoft sign in page hosted on https:\/\/drambor[.]azurewebsites[.]net\/. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"568\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link-1024x568.png\" alt=\"\" class=\"wp-image-663\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link-1024x568.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link-300x166.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link-768x426.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link-1440x798.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-21-22-office-365-invoice-phish-link.png 1499w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> sales[@]ams-ltd[.]com<br><strong>Subject:<\/strong> Your Microsoft 365 Business is expired<\/p>\n\n\n\n<p>Your Microsoft 365 Business is expired .<\/p>\n\n\n\n<p>lnvoice is ready<\/p>\n\n\n\n<p>SlGN IN To The Service Portal.<\/p>\n\n\n\n<p>SlGN lN To Update Your Payment lnformation<\/p>\n\n\n\n<p>Edit release preferences<\/p>\n\n\n\n<p>Choose the release track for your organization. Use these settings to join First Release if you haven&#8217;t already.<\/p>\n\n\n\n<p>You&#8217;re receiving this email because you&#8217;re assigned the Global Administrator .<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please simply delete it as it is not legitimate. Where Did the Link Lead? The link led to a fake Microsoft sign in page hosted on https:\/\/drambor[.]azurewebsites[.]net\/. Text of Phishing Message From: sales[@]ams-ltd[.]comSubject: Your Microsoft 365 Business is expired Your Microsoft 365 Business is expired . [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":662,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=660"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/660\/revisions"}],"predecessor-version":[{"id":664,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/660\/revisions\/664"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/662"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}