{"id":18,"date":"2022-08-15T03:07:07","date_gmt":"2022-08-15T03:07:07","guid":{"rendered":"https:\/\/freshphish.info\/?p=18"},"modified":"2022-09-06T16:49:34","modified_gmt":"2022-09-06T16:49:34","slug":"phishing-email-sent-using-and-hosted-on-paypal-servers","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=18","title":{"rendered":"Phishing Email Sent Using and Hosted on Paypal Servers"},"content":{"rendered":"\n<p>I found this phish in the wild and it&#8217;s pretty concerning. The email originated on PayPal&#8217;s email servers and links to PayPal&#8217;s web servers. The malicious actor was able to send a &#8220;legitimate&#8221; invoice with a request to pay through PayPal&#8217;s servers. If you click the link to pay the invoice, you are taken to the legitimate PayPal login screen and I assume, since I will not enter my PayPal credentials there, you&#8217;ll be in your account and ready to pay the invoice through PayPal. If you choose to call the phone number, you&#8217;ll be connected to a call center in India where they&#8217;ll likely step you through the standard refund scam.<\/p>\n\n\n\n<p>Here is the email:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"paypalphish.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>Here are the headers showing it originated on PayPal&#8217;s servers:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"paypalphishheaders.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>Here is the page you are taken to if you click the link:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"paypalwebinvoice.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>This is the page you are taken to if you click the button to pay the invoice:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"paypalsigninpage.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p>Note the email address PayPal says originated the invoice at the bottom of the page.<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I found this phish in the wild and it&#8217;s pretty concerning. The email originated on PayPal&#8217;s email servers and links<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=18\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Phishing Email Sent Using and Hosted on Paypal Servers<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[5,4],"class_list":["post-18","post","type-post","status-publish","format-standard","hentry","category-phish","tag-paypal","tag-phish"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/18","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/18\/revisions"}],"predecessor-version":[{"id":20,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/18\/revisions\/20"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}