{"id":907,"date":"2022-11-09T12:03:20","date_gmt":"2022-11-09T20:03:20","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=907"},"modified":"2022-11-21T11:45:55","modified_gmt":"2022-11-21T19:45:55","slug":"phishing-from-11-09-2022-fake-wf-login-you-received-a-new-letter","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/907","title":{"rendered":"PHISHING FROM 11\/09\/2022: &#8220;You received a new letter&#8221;"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><strong><em>NOTE: If you received this message, please delete it and DO NOT click on any links. This message is not legitimate.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"427\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/Screenshot-12-1024x427.png\" alt=\"\" class=\"wp-image-908\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/Screenshot-12-1024x427.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/Screenshot-12-300x125.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/Screenshot-12-768x320.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/Screenshot-12.png 1366w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts.<\/li><li>The email is not sent from a wells fargo address. Instead it is sent by &#8220;from[.]QI6fDOY6sxPqowm[@]AcreVo[.]com&#8221;<\/li><li>Hovering over the hyperlinked text reveals that the link &#8220;vk[.]cc\/cikV46?FeOvmRGXOY&#8221; which brings you to a very convincing wells fargo login page<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Where Did the Link Lead?<\/h2>\n\n\n\n<p>The link led to a a site designed to collect your credentials. Never enter your username\/password on sites you do not recognize.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"656\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-1024x656.png\" alt=\"\" class=\"wp-image-909\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-1024x656.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-300x192.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-768x492.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-1536x984.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image-1440x922.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/image.png 1557w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Text of Phishing Message<\/h2>\n\n\n\n<p><strong>From<\/strong><span style=\"font-size: revert; color: initial;\">: from[.]QI6fDOY6sxPqowm[@]AcreVo[.]com<\/span><br><strong>Subject:<\/strong> You received a new letter<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Dear Customer: We&#8217;re are letting you know we&#8217;ve detected an unsual activity on your card<br>card on 11\/7\/2022 11:32:31 PM EST which may result to the closure of your account and card to ensure safety and continuous use of your card, please&nbsp;Click here To Process<br><br>Note: Therefore we have placed a security hold on your online access to provide better security for your protection. <br><br>Your security is our 1st priority, Thank you for being a valued client. <br><br>Sincerely, Online Banking Team<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Please do not reply to this automated email. 2386-148-af0e-76PJamRtTb-a2656bd3_xfaXuYAFuQ_7f41-14c<\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please delete it and DO NOT click on any links. This message is not legitimate. Tips for Detection Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts. The email is not sent from [&hellip;]<\/p>\n","protected":false},"author":643,"featured_media":908,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-907","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/643"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=907"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/907\/revisions"}],"predecessor-version":[{"id":942,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/907\/revisions\/942"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/908"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}