{"id":930,"date":"2022-11-17T08:55:56","date_gmt":"2022-11-17T16:55:56","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=930"},"modified":"2022-11-17T09:13:00","modified_gmt":"2022-11-17T17:13:00","slug":"phishing-from-11-17-2022-email-maintenance","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/930","title":{"rendered":"Phishing from 11\/17\/2022: &#8220;Email maintenance&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please simply delete it and do not click on the link. This email is NOT legitimate. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"501\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-1024x501.png\" alt=\"\" class=\"wp-image-931\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-1024x501.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-300x147.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-768x375.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish.png 1250w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message. This indicates the message matches patterns of previous phishing attempts. <\/li><li>Legitimate emails about your Puget Sound account will generally come from an @pugetsound.edu address. This message came from rasha[@]hammad[.]com. <\/li><li>Notice the sense of urgency in the wording &#8220;avoid login interruption&#8221; and &#8220;required now&#8221;. Be cautious as many phishing emails contain a false sense of urgency. <\/li><li>Always hover over links! In this case, the hyperlink appears to go to a pugetsound.edu site. However, if you hover over it, you will see that it would actually take you to the website https:\/\/prestadores[.]oftalmed[.]pt\/office47\/new\/index.html. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a website https:\/\/prestadores[.]oftalmed[.]pt\/office47\/new\/index[.]html designed to steal your Puget Sound username and password. Never enter your credentials on sites you do not recognize. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"430\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link-1024x430.png\" alt=\"\" class=\"wp-image-934\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link-1024x430.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link-300x126.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link-768x322.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link-1440x605.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/11\/11-17-22-email-maintennace-phish-link.png 1522w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> rasha[@]hammad[.]com<br><strong>Subject: <\/strong>Email maintenance<\/p>\n\n\n\n<p>Your UPS UNIVERSITY EMAIL account settings are out-of-date. To improve all student\/faculty\/staff account user experience, privacy policy update is required to avoid login interruption.<\/p>\n\n\n\n<p>Privacy Policy Action Required Now<\/p>\n\n\n\n<p>Visit [<em>link removed<\/em>]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please simply delete it and do not click on the link. This email is NOT legitimate. Tips for Detection Notice the maroon caution banner prepended to the message. This indicates the message matches patterns of previous phishing attempts. Legitimate emails about your Puget Sound account will [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":931,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-930","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=930"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/930\/revisions"}],"predecessor-version":[{"id":935,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/930\/revisions\/935"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/931"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}