{"id":209,"date":"2024-11-13T17:10:37","date_gmt":"2024-11-13T22:10:37","guid":{"rendered":"https:\/\/freshphish.info\/?p=209"},"modified":"2025-03-13T09:58:07","modified_gmt":"2025-03-13T14:58:07","slug":"meta-phish-sent-through-salesforce","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=209","title":{"rendered":"Meta Phish Sent Through Salesforce"},"content":{"rendered":"\n<p>Here&#8217;s a phish recently seen in the wild. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"622\" height=\"573\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphish1.jpg\" alt=\"\" class=\"wp-image-210\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphish1.jpg 622w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphish1-300x276.jpg 300w\" sizes=\"auto, (max-width: 622px) 100vw, 622px\" \/><\/figure>\n\n\n\n<p>The email claims it is from Meta, owner of Facebook, warning about restrictions placed on the recipient&#8217;s Meta account due to recent activity seen on the account, which is seen as an &#8220;exploit&#8221; that could impact internal functions within the &#8220;Meta Business Suite&#8221;, used to manage a business&#8217; Facebook, Instagram and WhatsApp for Business accounts. It claims that if an appeal is not filed within one day, the restrictions they have placed on the account could become permanent.<\/p>\n\n\n\n<p>Looking at the headers of the email, it shows that the email was definitively sent from Salesforce servers.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"412\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishheaders-1024x412.jpg\" alt=\"\" class=\"wp-image-211\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishheaders-1024x412.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishheaders-300x121.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishheaders-768x309.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishheaders.jpg 1135w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The link in the email goes to a page on &#8220;salesforce-sites[.]com&#8221;, which redirects to a page on &#8220;metasystemschat[.]com&#8221;. The link existing on salesforce-sites[.]com tells me someone&#8217;s Salesforce account has been compromised and used to stage the phish and send the email.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"954\" height=\"505\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishlandingpage.jpg\" alt=\"\" class=\"wp-image-212\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishlandingpage.jpg 954w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishlandingpage-300x159.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/11\/salesforcemetaphishlandingpage-768x407.jpg 768w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><\/figure>\n\n\n\n<p>The metasystemschat[.]com is a recently registered fraudulent lookalike domain, hosting what appears to be a Meta Business Support page. It asks for information about the account in question to open a chat. I entered completely bogus information and was not told I had entered invalid information.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here&#8217;s a phish recently seen in the wild. The email claims it is from Meta, owner of Facebook, warning about<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=209\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Meta Phish Sent Through Salesforce<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[14,55,4,15],"class_list":["post-209","post","type-post","status-publish","format-standard","hentry","category-phish","tag-facebook","tag-meta","tag-phish","tag-salesforce"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=209"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/209\/revisions"}],"predecessor-version":[{"id":214,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/209\/revisions\/214"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}