{"id":268,"date":"2019-05-02T20:18:18","date_gmt":"2019-05-02T19:18:18","guid":{"rendered":"http:\/\/www.jgt.me.uk\/?p=268"},"modified":"2019-05-02T20:18:19","modified_gmt":"2019-05-02T19:18:19","slug":"more-on-spotting-the-spear-phishers","status":"publish","type":"post","link":"https:\/\/www.jgt.me.uk\/?p=268","title":{"rendered":"More on spotting the spear-phishers"},"content":{"rendered":"\n<p style=\"text-align:left\" class=\"has-drop-cap\">As many of you are probably aware, there&#8217;s lots of people out to try to defraud you on the &#8216;net. Its not personal, just a way for them to increase the money they get. I received a spam mail today allegedly from 1&amp;1 IONOS:<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing1.jpg\" alt=\"\" class=\"wp-image-270\" width=\"310\" height=\"461\" srcset=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing1.jpg 336w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing1-202x300.jpg 202w\" sizes=\"auto, (max-width: 310px) 100vw, 310px\" \/><figcaption>A spear-phishing attack&#8230;<\/figcaption><\/figure>\n\n\n\n<p>Because Gmail blocked it as spam, I paid it no real attention but I figured I&#8217;d take a look as its even got the avatar.co.uk domain there.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"651\" height=\"87\" src=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing2.jpg\" alt=\"\" class=\"wp-image-271\" srcset=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing2.jpg 651w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing2-300x40.jpg 300w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing2-640x87.jpg 640w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><figcaption>oh look, this is definately NOT from 1&amp;1!<\/figcaption><\/figure>\n\n\n\n<p>So, hovering over the links it pointed to a domain. I checked the domain against whois and surprise! Nothing there.<\/p>\n\n\n\n<p>In the body of the e-mail I see:<\/p>\n\n\n\n<table class=\"wp-block-table is-style-stripes\"><tbody><tr><td>If the problem does not resolved within 5 days, the domain has to be set on &#8216;hold&#8217;, which means it will not be usable regularly.  <br><strong>Note<\/strong>: If your data is correct, you will not have to  do anything. If your contact data needs to be updated, you can change it in  the <a rel=\"noreferrer noopener\" href=\"http:\/\/\" target=\"_blank\">1&amp;1 Domain Center<\/a>. Please follow the instructions in this <a rel=\"noreferrer noopener\" href=\"\" target=\"_blank\">1&amp;1 Help Center  article<\/a>.<\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>This is the classic, &#8220;you&#8217;ve gotta do something within the time limit, or bad things happen!&#8221;. Although in this case, it appears that they&#8217;re not too sure what you should do (Both doing nothing AND placing domain on hold within 5 days). Also the grammar of the first paragraph is terrible; the things sent out from a company as big as 1&amp;1 is very unlikely to have these sort of mistakes.<\/p>\n\n\n\n<p>Next for the fun of it, I went to the domain in the &#8220;Check Contract Details&#8221; (after removing any tracking junk):<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"414\" src=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing3-1024x414.jpg\" alt=\"\" class=\"wp-image-272\" srcset=\"https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing3-1024x414.jpg 1024w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing3-300x121.jpg 300w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing3-768x310.jpg 768w, https:\/\/www.jgt.me.uk\/wp-content\/uploads\/2019\/05\/phishing3.jpg 1104w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>No sir please believe me! I&#8217;m a valid domain!<\/figcaption><\/figure>\n\n\n\n<p>So, if by this point, you continue, you probably deserve any malware that&#8217;s on that site. <\/p>\n\n\n\n<p>Also note that they&#8217;ve tried to be clever by using https, but couldn&#8217;t get the certificate to verify correctly. This is why you need to use the latest version of a browser &#8211; its got mechanisms in place to detect this.<\/p>\n\n\n\n<p>For me, this was interesting as I&#8217;m guessing they were trying to get me to log onto their copy of the 1&amp;1 account page with my details so they could steal my account. From WHOIS they could tell that 1&amp;1 hosted the site and they sent it to an e-mail contact address from the webpage (which is NOT the one used for my 1&amp;1 login).<\/p>\n\n\n\n<p>Its certainly a better attempt than the ones that show an image email and say &#8220;you&#8217;ve been hacked pay me bitcoin, please&#8221;. <\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For me, this was interesting as I&#8217;m guessing they were trying to get me to log onto their copy of the 1&#038;1 account page with my details so they could steal my account. From WHOIS they could tell that 1&#038;1 hosted the site and they sent it to an e-mail contact address from the webpage <a class=\"more-link\" href=\"https:\/\/www.jgt.me.uk\/?p=268\">Continue reading <span class=\"screen-reader-text\">  More on spotting the spear-phishers<\/span><span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5,1],"tags":[37],"class_list":["post-268","post","type-post","status-publish","format-standard","hentry","category-nothing-in-particular","category-uncategorized","tag-phishing"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=268"}],"version-history":[{"count":4,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/268\/revisions"}],"predecessor-version":[{"id":275,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/268\/revisions\/275"}],"wp:attachment":[{"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jgt.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}