{"id":744,"date":"2022-05-31T08:14:41","date_gmt":"2022-05-31T15:14:41","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=744"},"modified":"2022-05-31T12:40:02","modified_gmt":"2022-05-31T19:40:02","slug":"phishing-from-5-31-2022-maintenance","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/744","title":{"rendered":"Phishing from 5\/31\/2022: &#8220;Maintenance&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message or a similar one, please delete it and do not click on any links. The message is NOT legitimate.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"988\" height=\"470\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish.png\" alt=\"\" class=\"wp-image-745\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish.png 988w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-300x143.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-768x365.png 768w\" sizes=\"auto, (max-width: 988px) 100vw, 988px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message. Messages with this banner match previous phishing attempts. <\/li><li>Technology Services will not ask you to click on a link to update your email. <\/li><li>Notice the reference to &#8220;Pugetsound University&#8221; instead of &#8220;University of Puget Sound&#8221;.<\/li><li>Always hover over hyperlinked text. In this case, it was tricky as it appeared to go to a pugetsound.edu website. However, hovering over the link reveals the link would go to https:\/\/www[.]cognitoforms[.]com\/elizabethphanllc\/maintenanceupdate or https:\/\/7a815daf[.]sibforms[.]com\/. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p><strong><em>Note: If you entered your credentials on this form, please call the Service Desk as soon as possible at 253-879-8585 (option 2) as your password is compromised.<\/em><\/strong><\/p>\n\n\n\n<p>The link led to a fake form intended to steal your credentials: https:\/\/www[.]cognitoforms[.]com\/elizabethphanllc\/maintenanceupdate. Never enter credentials on web forms or on sites you do not recognize. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"535\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-1024x535.png\" alt=\"\" class=\"wp-image-748\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-1024x535.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-300x157.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-768x401.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-1536x803.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link-1440x752.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/05\/5-31-22-maintenance-phish-link.png 1912w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>akhanna5[@]lion[.]lmu[.]edu OR hamj[@]gvsu[.]edu<br><strong>Subject: <\/strong>Maintenance<\/p>\n\n\n\n<p>PUGETSOUND UNIVERSITY\/Office365 service is currently undergoing scheduled maintenance on our mail servers due to high levels of queued emails.<\/p>\n\n\n\n<p>All users are mandated to complete this update.<br>https:\/\/www[.]pugetsound[.]edu\/technology-support\/help-support [<em>LINK REMOVED<\/em>]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message or a similar one, please delete it and do not click on any links. The message is NOT legitimate. Tips for Detection Notice the maroon caution banner prepended to the message. Messages with this banner match previous phishing attempts. Technology Services will not ask you to [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":745,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-744","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=744"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/744\/revisions"}],"predecessor-version":[{"id":751,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/744\/revisions\/751"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/745"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}