{"id":192,"date":"2024-04-26T14:27:37","date_gmt":"2024-04-26T19:27:37","guid":{"rendered":"https:\/\/freshphish.info\/?p=192"},"modified":"2024-04-26T14:28:06","modified_gmt":"2024-04-26T19:28:06","slug":"phishing-email-sent-using-salesforce","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=192","title":{"rendered":"Phishing Email Sent Using Salesforce"},"content":{"rendered":"\n<p>This phish was likely sent from a compromised customer account on Salesforce. The email definitely originated from Salesforce servers and definitely links to Salesforce servers. The envelope sender of this email was (defanged) bounce-e360-0gxvy0apr7mk639rrpc1a9zq-9be2d031-1712784599529[@]bounce.400.yfeipo.mx.salesforce[.]com . The sender hostname was 9be2d031.400.yfeipo.mx[.]salesforce[.]com and the sending server IP was 155[.]226[.]208[.]49.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"753\" height=\"339\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/email.jpg\" alt=\"\" class=\"wp-image-193\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/email.jpg 753w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/email-300x135.jpg 300w\" sizes=\"auto, (max-width: 753px) 100vw, 753px\" \/><\/figure>\n\n\n\n<p>If the recipient clicked the link, they would be brought to Salesforce servers and automatically redirected to another site: hxxps:\/\/lpace.bradentoncc[.]store\/index0.php. This domain was registered on March 31, 2024, which was 25 days before this email was sent.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This phish was likely sent from a compromised customer account on Salesforce. The email definitely originated from Salesforce servers and<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=192\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Phishing Email Sent Using Salesforce<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[4,15],"class_list":["post-192","post","type-post","status-publish","format-standard","hentry","category-phish","tag-phish","tag-salesforce"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=192"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/192\/revisions"}],"predecessor-version":[{"id":194,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/192\/revisions\/194"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}