{"id":87,"date":"2022-12-20T18:05:54","date_gmt":"2022-12-20T18:05:54","guid":{"rendered":"https:\/\/freshphish.info\/?p=87"},"modified":"2023-01-27T16:57:18","modified_gmt":"2023-01-27T16:57:18","slug":"yahoo-mail-phish-follow-up","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=87","title":{"rendered":"Yahoo Mail Phish Follow-Up"},"content":{"rendered":"\n<p>I received this phish last week. It&#8217;s a follow-up to the phish I posted previously <a href=\"https:\/\/freshphish.info\/?p=64\" target=\"_blank\" rel=\"noopener\" title=\"here\">here<\/a>.<\/p>\n\n\n\n<p>In it, they told me about it previously and I needed to confirm I&#8217;ve read and acknowledge the new Yahoo Mail terms of service. Unfortunately, I&#8217;ve been sick for the past week and didn&#8217;t get a chance to investigate the email before today and I find that the payload site has already been taken down.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"560\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/yahoomailphish20221215-1024x560.jpg\" alt=\"\" class=\"wp-image-88\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/yahoomailphish20221215-1024x560.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/yahoomailphish20221215-300x164.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/yahoomailphish20221215-768x420.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/yahoomailphish20221215.jpg 1282w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The red call-out square is just me showing where the link leads to. The red square did not appear in the email. I would imagine that non-technical recipients of this email that don&#8217;t have good knowledge of phishing emails could fall for this phish. It passed DMARC authenticity checks because it was sent from a Yahoo email address. However, it was sent from either a spoofed or a compromised Yahoo mailbox.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I received this phish last week. It&#8217;s a follow-up to the phish I posted previously here. In it, they told<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=87\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Yahoo Mail Phish Follow-Up<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[4,22],"class_list":["post-87","post","type-post","status-publish","format-standard","hentry","category-phish","tag-phish","tag-yahoo"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/87","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=87"}],"version-history":[{"count":3,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/87\/revisions"}],"predecessor-version":[{"id":93,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/87\/revisions\/93"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=87"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=87"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=87"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}