{"id":242,"date":"2025-05-13T11:13:59","date_gmt":"2025-05-13T16:13:59","guid":{"rendered":"https:\/\/freshphish.info\/?p=242"},"modified":"2025-05-13T11:14:00","modified_gmt":"2025-05-13T16:14:00","slug":"convincing-social-security-phish","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=242","title":{"rendered":"Convincing Social Security Phish"},"content":{"rendered":"\n<p>I received this email a few days ago to the email address associated with my social security online account. I didn&#8217;t dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it&#8217;s looking. I finally had time to look today, brought up this email and, since I trust nothing in any email, looked at where the link would lead me before I&#8217;d click on it. Whoa! Thank goodness I did! This email looks quite convincing. The only giveaway that it&#8217;s fraudulent is the link and the sender. Here&#8217;s a look at the email:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"615\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1-1024x615.png\" alt=\"\" class=\"wp-image-245\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1-1024x615.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1-300x180.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1-768x461.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1.png 1207w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Seeing that it was a phish, I took a look at the headers. I see it was sent from a domain that has a DMARC record but the policy is &#8220;none&#8221;. While I applaud Gmail and Yahoo in requiring a DMARC policy for emails sent to them, it&#8217;s sad that the companies that setup records to comply with this requirement are leaving their policy at &#8220;none&#8221;. What makes it worse is that the DMARC record doesn&#8217;t contain a contact for messages that fail DMARC. This means this domain does not care a whit about security. They only have a record to comply with Yahoo and Gmail. I wonder if they could change their policy so if a sending domain has a &#8220;none&#8221; policy and no contacts for feedback, the emails can be rejected like they do for those with no DMARC record, because having this setup, you may as well have no DMARC record. Here&#8217;s the pertinent section of the email headers:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"638\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphishheaders-1024x638.png\" alt=\"\" class=\"wp-image-246\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphishheaders-1024x638.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphishheaders-300x187.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphishheaders-768x479.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphishheaders.png 1126w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>I loaded up the website in a VM and saw it&#8217;s definitely malicious. The only thing it did was start a download of a .exe file. When opened, it went through a setup process for . Here are screenshots of the download and what came up with the file was run.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"956\" height=\"331\" data-id=\"248\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish1-2.png\" alt=\"\" class=\"wp-image-248\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish1-2.png 956w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish1-2-300x104.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish1-2-768x266.png 768w\" sizes=\"auto, (max-width: 956px) 100vw, 956px\" \/><\/figure>\n<\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"736\" height=\"310\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish2.png\" alt=\"\" class=\"wp-image-249\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish2.png 736w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish2-300x126.png 300w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/figure>\n\n\n\n<p>So, watch out for phishing emails posing as social security statement notifications! It makes me want to see where my social security is sitting right now. How much longer before I can retire?<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I received this email a few days ago to the email address associated with my social security online account. I<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=242\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Convincing Social Security Phish<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[8,4,67],"class_list":["post-242","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-dmarc","tag-phish","tag-social-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"I received this email a few days ago to the email address associated with my social security online account. I didn&#039;t dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it&#039;s looking. I finally had time to look today,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Matt\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/freshphish.info\/?p=242\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Fresh Phish - All the freshest phish\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Convincing Social Security Phish - Fresh Phish\" \/>\n\t\t<meta property=\"og:description\" content=\"I received this email a few days ago to the email address associated with my social security online account. I didn&#039;t dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it&#039;s looking. I finally had time to look today,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/freshphish.info\/?p=242\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-05-13T16:13:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-05-13T16:14:00+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Convincing Social Security Phish - Fresh Phish\" \/>\n\t\t<meta name=\"twitter:description\" content=\"I received this email a few days ago to the email address associated with my social security online account. I didn&#039;t dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it&#039;s looking. I finally had time to look today,\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#blogposting\",\"name\":\"Convincing Social Security Phish - Fresh Phish\",\"headline\":\"Convincing Social Security Phish\",\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/freshphish.info\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/socialsecurityphish-1.png\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242\\\/#articleImage\",\"width\":1207,\"height\":725},\"datePublished\":\"2025-05-13T11:13:59-05:00\",\"dateModified\":\"2025-05-13T11:14:00-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#webpage\"},\"articleSection\":\"Uncategorized, DMARC, phish, social security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/freshphish.info\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=1#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=1#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/freshphish.info\\\/?cat=1\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#listItem\",\"name\":\"Convincing Social Security Phish\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#listItem\",\"position\":3,\"name\":\"Convincing Social Security Phish\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=1#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?author=1\",\"name\":\"Matt\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#webpage\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?p=242\",\"name\":\"Convincing Social Security Phish - Fresh Phish\",\"description\":\"I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today,\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=242#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"datePublished\":\"2025-05-13T11:13:59-05:00\",\"dateModified\":\"2025-05-13T11:14:00-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Convincing Social Security Phish - Fresh Phish","description":"I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today,","canonical_url":"https:\/\/freshphish.info\/?p=242","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/freshphish.info\/?p=242#blogposting","name":"Convincing Social Security Phish - Fresh Phish","headline":"Convincing Social Security Phish","author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"publisher":{"@id":"https:\/\/freshphish.info\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/05\/socialsecurityphish-1.png","@id":"https:\/\/freshphish.info\/?p=242\/#articleImage","width":1207,"height":725},"datePublished":"2025-05-13T11:13:59-05:00","dateModified":"2025-05-13T11:14:00-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/freshphish.info\/?p=242#webpage"},"isPartOf":{"@id":"https:\/\/freshphish.info\/?p=242#webpage"},"articleSection":"Uncategorized, DMARC, phish, social security"},{"@type":"BreadcrumbList","@id":"https:\/\/freshphish.info\/?p=242#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","position":1,"name":"Home","item":"https:\/\/freshphish.info","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=1#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=1#listItem","position":2,"name":"Uncategorized","item":"https:\/\/freshphish.info\/?cat=1","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=242#listItem","name":"Convincing Social Security Phish"},"previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=242#listItem","position":3,"name":"Convincing Social Security Phish","previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=1#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/freshphish.info\/#organization","name":"Fresh Phish","description":"All the freshest phish","url":"https:\/\/freshphish.info\/"},{"@type":"Person","@id":"https:\/\/freshphish.info\/?author=1#author","url":"https:\/\/freshphish.info\/?author=1","name":"Matt","image":{"@type":"ImageObject","@id":"https:\/\/freshphish.info\/?p=242#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt"}},{"@type":"WebPage","@id":"https:\/\/freshphish.info\/?p=242#webpage","url":"https:\/\/freshphish.info\/?p=242","name":"Convincing Social Security Phish - Fresh Phish","description":"I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today,","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/freshphish.info\/#website"},"breadcrumb":{"@id":"https:\/\/freshphish.info\/?p=242#breadcrumblist"},"author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"creator":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"datePublished":"2025-05-13T11:13:59-05:00","dateModified":"2025-05-13T11:14:00-05:00"},{"@type":"WebSite","@id":"https:\/\/freshphish.info\/#website","url":"https:\/\/freshphish.info\/","name":"Fresh Phish","description":"All the freshest phish","inLanguage":"en-US","publisher":{"@id":"https:\/\/freshphish.info\/#organization"}}]},"og:locale":"en_US","og:site_name":"Fresh Phish - All the freshest phish","og:type":"article","og:title":"Convincing Social Security Phish - Fresh Phish","og:description":"I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today,","og:url":"https:\/\/freshphish.info\/?p=242","article:published_time":"2025-05-13T16:13:59+00:00","article:modified_time":"2025-05-13T16:14:00+00:00","twitter:card":"summary_large_image","twitter:title":"Convincing Social Security Phish - Fresh Phish","twitter:description":"I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today,"},"aioseo_meta_data":{"post_id":"242","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-05-13 16:14:00","updated":"2025-06-04 04:53:18","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\/?cat=1\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tConvincing Social Security Phish\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/freshphish.info"},{"label":"Uncategorized","link":"https:\/\/freshphish.info\/?cat=1"},{"label":"Convincing Social Security Phish","link":"https:\/\/freshphish.info\/?p=242"}],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=242"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/242\/revisions"}],"predecessor-version":[{"id":250,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/242\/revisions\/250"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}