{"id":6323,"date":"2023-12-04T13:28:33","date_gmt":"2023-12-04T13:28:33","guid":{"rendered":"https:\/\/really.zonky.org\/?p=6323"},"modified":"2023-12-04T13:28:37","modified_gmt":"2023-12-04T13:28:37","slug":"diagnosing-a-phishing-scam","status":"publish","type":"post","link":"https:\/\/really.zonky.org\/?p=6323","title":{"rendered":"Diagnosing A Phishing Scam"},"content":{"rendered":"\n<p>Just for fun (I have admittedly a very weird sense of fun), I thought I&#8217;d have a look at one of the phishing emails that came into me. I&#8217;ll go through this bit by bit, picking out bits that first occurred to me &#8230;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Subject: LastPass : Required action needed regarding your account<\/code><\/pre>\n\n\n\n<p>Eh? Do I even have a LastPass account? I keep my passwords stored somewhere else, but it&#8217;s not impossible &#8211; I&#8217;ve been known to sign up to things just to test them out. Including cloud-based password managers.<\/p>\n\n\n\n<p>But all the same, let&#8217;s give it a point on the suspicion scale. Running total: 1.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>From: LastPass &lt;yoji-okugawa1975@tg8.so-net.ne.jp><\/code><\/pre>\n\n\n\n<p>Well LastPass certainly use a funny looking email domain (the bit to the right of the &#8220;@&#8221;), but Marketing departments sometimes aren&#8217;t aware of how important that email domain really is. On the other hand, &#8220;tg8.so-net.net.jp&#8221; does look particularly uncorporate, so let us give it a suspicion point.<\/p>\n\n\n\n<p>Running total: 2<\/p>\n\n\n\n<p>On the other hand, it is too easy to <em>fake<\/em> domains &#8211; I could very easily send you an email from <em>the-management@l\u00e1stp\u00e1ss.com<\/em>  (and even more subtle equivalents of &#8220;a&#8221; &#8211; &#8220;\u0430&#8221;, &#8220;\u1ea1&#8221;, &#8220;\u0105&#8221;, &#8220;\u00e4&#8221;, &#8220;\u00e0&#8221;, &#8220;\u00e1&#8221;, &#8220;\u0105&#8221;). And just to demonstrate something that looks identical can actually be quite different :-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>In &#91;8]: print(ord('\u0430'))\n1072\n\nIn &#91;9]: print(ord('a'))\n97\n<\/code><\/pre>\n\n\n\n<p>Now this isn&#8217;t to suggest that you should run your email headers through some Python code, but just that because something looks like <em>lastpass.com<\/em> doesn&#8217;t mean it really is. The next thing that jumped out at me was the body of the email &#8211; I may be well trained, but something new and shiny is still distracting :-<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"565\" height=\"1024\" src=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2023-12-04_1242.png?resize=565%2C1024&#038;ssl=1\" alt=\"\" class=\"wp-image-6324\" srcset=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2023-12-04_1242.png?resize=565%2C1024&amp;ssl=1 565w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2023-12-04_1242.png?resize=166%2C300&amp;ssl=1 166w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2023-12-04_1242.png?w=571&amp;ssl=1 571w\" sizes=\"auto, (max-width: 565px) 100vw, 565px\" \/><\/figure>\n\n\n\n<p>Now the first thing that jumps out at me is that red &#8220;Confirm my information&#8221; box. Screams &#8220;click here&#8221; doesn&#8217;t it? Well don&#8217;t click on it! In my email client (something you&#8217;re quite likely not using &#8211; <em>claws-mail<\/em>), if I hold the mouse pointed above a link, it&#8217;ll tell me where that link goes in the status bar of the client. In this case it shows up as <em>https:\/\/tg8.benchurl.com<\/em>\/&#8230;. doesn&#8217;t look very much like <em>lastpass.com<\/em> does it? That&#8217;s sufficiently suspicious that I&#8217;ll award it 3 suspicion points.<\/p>\n\n\n\n<p>Running total: 5<\/p>\n\n\n\n<p>Notice how they don&#8217;t add a &#8220;Dear ${name}&#8221; to the top of the email? Not personally addressing email is ever so convenient to scammers that want to get your details &#8211; because they don&#8217;t necessarily know your name. That&#8217;s a suspicion point all on its own.<\/p>\n\n\n\n<p>Running total: 6<\/p>\n\n\n\n<p>Next note how it tries to rush you &#8230; &#8220;log in before January 16, 2024&#8221;. It&#8217;s subtler than many phishing scams, but it&#8217;s still trying to rush you. Add another suspicion point.<\/p>\n\n\n\n<p>Running total: 7<\/p>\n\n\n\n<p>There&#8217;s further details we could dig into, but that&#8217;s more than enough that the Delete button is the only thing this email should attract. That running total? It was just for fun, it&#8217;s not intended as a guideline for when to count something as a phishing email.<\/p>\n\n\n\n<p>In the case of doubt, contact the company via other means. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just for fun (I have admittedly a very weird sense of fun), I thought I&#8217;d have a look at one of the phishing emails that came into me. I&#8217;ll go through this bit by bit, picking out bits that first occurred to me &#8230; Eh? Do I even have a LastPass account? I keep my <a href='https:\/\/really.zonky.org\/?p=6323' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false,"_share_on_mastodon":"0"},"categories":[4,489],"tags":[121,488,2186],"class_list":["post-6323","post","type-post","status-publish","format-standard","hentry","category-it","category-security","tag-email","tag-phishing","tag-scam","category-4-id","category-489-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"share_on_mastodon":{"url":"https:\/\/mstdn.social\/@grumpygrimnir\/111522382908674238","error":""},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1f2KI-1DZ","_links":{"self":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/6323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6323"}],"version-history":[{"count":2,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/6323\/revisions"}],"predecessor-version":[{"id":6326,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/6323\/revisions\/6326"}],"wp:attachment":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}