Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Fresh Phish All the freshest phish ## Sitemaps - [XML Sitemap](https://freshphish.info/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [TOAD Sent Through Microsoft](https://freshphish.info/?p=265) - Just an FYI about a new type of phish we’ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on - [Fraudulent Accounts Created for EA Games](https://freshphish.info/?p=258) - We've seen hundreds of accounts being created at EA.com by fraudulent actors. These account creations end up having emails delivered to the email addresses associated with these accounts. There is no way to easily delete these accounts. I've requested the accounts associated with my company be deleted. EA support said they can't do this. Because - [DNS as an Attack Vector](https://freshphish.info/?p=255) - In an article posted by Domain Tools, they discuss the transfer of malicious files through DNS. It works much the same way as html smuggling or registry smuggling where a file is encoded in hexadecimal or Base64 text. This text is then placed in a DNS TXT record. All the malicious actor needs to do - [Hack Utilizes Organic Component](https://freshphish.info/?p=227) - If a hacker can't hack the system, he'll hack the organic component, otherwise known as the user. In this case, the email the link was found in wasn't actually malicious, so I won't post it here. It was a legitimate email linking to a site that happened to have been compromised and used to spread - [Convincing Social Security Phish](https://freshphish.info/?p=242) - I received this email a few days ago to the email address associated with my social security online account. I didn't dig deep into the sender or where the link would lead me to but knew I should check my social security account and see how it's looking. I finally had time to look today, - [Malicious Actors Sending Phish Using Microsoft Secure Messaging Platform](https://freshphish.info/?p=232) - I found one article talking about this type of attack that was written two years ago. I can't believe more people aren't talking about this. I'm seeing emails being sent from a compromised M365 account using Microsoft Purview. Sending this way ends up with only a notification of a secure message being sent to the - [Meta Phish Sent Through Salesforce](https://freshphish.info/?p=209) - Here's a phish recently seen in the wild. The email claims it is from Meta, owner of Facebook, warning about restrictions placed on the recipient's Meta account due to recent activity seen on the account, which is seen as an "exploit" that could impact internal functions within the "Meta Business Suite", used to manage a - [Malicious SVG Attachment](https://freshphish.info/?p=219) - I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an - [Purported Proofpoint Flaw: Is it a Microsoft Flaw?](https://freshphish.info/?p=196) - The purported Proofpoint flaw, as seen reported on some cybersecurity news sites, is in my opinion a great overstatement and at least partially incorrect pointing of fingers. First, what is being reported? Here's a link to one of the stories: https://thehackernews.com/2024/07/proofpoint-email-routing-flaw-exploited.html The headlines say that Proofpoint has been breached, allowing malicious actors to send phishing - [Phishing Email Sent Using Salesforce](https://freshphish.info/?p=192) - This phish was likely sent from a compromised customer account on Salesforce. The email definitely originated from Salesforce servers and definitely links to Salesforce servers. The envelope sender of this email was (defanged) bounce-e360-0gxvy0apr7mk639rrpc1a9zq-9be2d031-1712784599529[@]bounce.400.yfeipo.mx.salesforce[.]com . The sender hostname was 9be2d031.400.yfeipo.mx[.]salesforce[.]com and the sending server IP was 155[.]226[.]208[.]49. If the recipient clicked the link, they would - [Fake AV TOAD Ads](https://freshphish.info/?p=186) - This one isn't an email I know it is something that has been around awhile. I've seen a lot more of these in the past week or so. First, a web browser is presented an ad in the middle of a news article that looks like a continue button to read the rest of the - [Phish Uses Redirects on Legitimate Web Sites](https://freshphish.info/?p=55) - Here are two examples from the same phishing campaign. One links to the legitimate Booking.com web site and one links to the legitimate JudicialWatch.org web site. I believe these subdomains normally contain some sort of user profiles, which means the hacker would create or gain control of existing user profiles on these web sites, create - [MrWeeBee Phish Kit](https://freshphish.info/?p=68) - The malicious threat actor and phish kit creator and seller "MRWEEBEE" has been around since July 2021. This phish kit is designed to be used to create phish posing as US banks and credit unions. I can't say that all phish created using this kit do this, but I can say I've seen a large - [Getting Malware Past Email Filter](https://freshphish.info/?p=73) - In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which - [Convincing IRS ID.me Phish Making the Rounds](https://freshphish.info/?p=177) - It's tax season so you know malicious actors are going to try to come after your tax refunds. This one looks pretty legitimate, as long as you ignore the sender's email address and the domain the link takes you to. I just recently filed my Federal income taxes for this year and had to establish - [Public Email Providers To Require Security](https://freshphish.info/?p=172) - Does your organization send more than 5000 emails per day to Gmail, Yahoo or Apple recipients? If so, and you haven't setup DMARC records for your domains, you have some work to do! Even if you don't send that many emails to recipients on this services, you still have some work to do. You can - [Phish Using QR Codes](https://freshphish.info/?p=160) - I knew it was inevitable. It has finally happened. I've spotted two phish using QR codes in the wild. Why is this worse than phish using normal links? Because for people trying to protect an enterprise environment, a link that is essentially only usable on a mobile device not connected to the enterprise network means - [Delivering Executable Using Registry File](https://freshphish.info/?p=146) - I just came across this phish that had a method of delivering an executable file that I've never seen before. The email itself is not that interesting or convincing. Incomplete sentences, typical misspellings, typos and grammatical errors. I suppose it's vague enough that it might convince someone to click out of curiosity. Here are the - [Phish Landing Page Hosted on Citibank Server Redirects to Phish on Microsoft Server](https://freshphish.info/?p=128) - I recently came across a phishing emails with a link leading to a subdomain of citi.com, owned by Citibank. Further investigation shows that this particular subdomain is used by Citibank for marketing emails. You can see the link, rewritten by an email security system, links to l.info16.citi.com, shown in brackets at the end of the - [WordPress Blog Posts Host Phish](https://freshphish.info/?p=135) - No, not this one. But I did find a phish being sent from what appears to be a compromised account linking to a phishing page hosted on a WordPress blog that was either hijacked or else created using the name of the compromised business. The phishing page the email linked to was just one blog - [Email Attachment With RTLO Character in Filename](https://freshphish.info/?p=119) - I had heard about malicious actors potentially using the Right-To-Left-Override (Unicode U+202e) character a while back. This is the first time I've seen it for myself. The RTLO character tells the operating system to display the text following it in reverse order. So if a filename is called "thisisafile.doc.exe" with the RTLO character immediately before - [Phishing Link Leads to Google Translate](https://freshphish.info/?p=114) - This phish contains a link that leads to Google Translate. - [Bitcoin Phish](https://freshphish.info/?p=99) - Here's a type of phish I haven't seen before. It intends to make the victim believe they opened some sort of a Bitcoin mining account a year ago that has since accumulated several thousand dollars, and uses that as bait to get information from the victim. Here's the email: The link as shown is rewritten - [Refund Scam Sent Through PayPal](https://freshphish.info/?p=94) - This email was sent through PayPal. While it doesn't have any malicious links or attachments and doesn't appear to be trying to trick the victim into paying the scammer through Paypal, it contains the phone number where the victim will be connected to a refund scam posing as PayPal. - [Yahoo Mail Phish Follow-Up](https://freshphish.info/?p=87) - I received this phish last week. It's a follow-up to the phish I posted previously here. In it, they told me about it previously and I needed to confirm I've read and acknowledge the new Yahoo Mail terms of service. Unfortunately, I've been sick for the past week and didn't get a chance to investigate - [Crypto Wallet Phish](https://freshphish.info/?p=81) - I found this phish a few days ago. I'm quite sure something similar has been around for a long time but it's the first one of this type I've seen. It claims to be from the Exodus Cryptowallet company, saying they updated their terms of service and because of the "Know Your Customer" regulations, the - [Yahoo Email Phish](https://freshphish.info/?p=64) - I found this Yahoo! phish that arrived today, claiming that you need to agree to updated conditions to use Yahoo email in the future. The email was sent from a Yahoo email address, likely compromised or potentially setup for the purpose of sending this phish, so it passes DMARC authentication checks and appears somewhat legitimate - [Credential Phish on Microsoft Hosted Site](https://freshphish.info/?p=49) - Here is a phishing email seen that links to nvc.microsoft.com and when clicked redirects to a page hosted on customervoice.microsoft.com. These are not spoofing the Microsoft domain. They are actually hosted on servers reached through Microsoft domains. - [Facebook Phish Uses Salesforce and Facebook](https://freshphish.info/?p=32) - Here is a phish that popped up last week. It was sent from Salesforce servers and links to a Facebook page. The payload page on Facebook was taken down before I was able to view it so I do not know what the payload was. Note the urgency the phisher tries to create in order - [Link in Phishing Email Leads to TechRepublic Redirector](https://freshphish.info/?p=40) - I found a phishing email containing a link to techrepublic.com, which ends up redirecting to a .ar (Argentina TLD) URL, which ends up redirecting to a .ru (Russia TLD) phishing page. I've contacted TechRepublic and sent the link to them. Hopefully they'll be able to plug this hole quickly. --Matt - [Phishing Email Sent Using and Hosted on Paypal Servers](https://freshphish.info/?p=18) - I found this phish in the wild and it's pretty concerning. The email originated on PayPal's email servers and links to PayPal's web servers. The malicious actor was able to send a "legitimate" invoice with a request to pay through PayPal's servers. If you click the link to pay the invoice, you are taken to - [Phish Uses Two Different Techniques](https://freshphish.info/?p=23) - Here's a new phish I just found. The malicious actor attaches a .ics file, which is a calendar attachment, like is added to every meeting invitation sent. It appears some spam filter vendors do not inspect links included in .ics file attachments. On top of that, the link uses a hexadecimal version of an IP - [DMARC - Let's Get Started](https://freshphish.info/?p=29) - What is DMARC? It stands for Domain-based Message Authentication, Reporting and Conformance. It is an open protocol for authenticating emails. It can help prevent phishing emails from being delivered to the targeted victims' inboxes. There are two important aspects of DMARC. The first is something email administrators can do immediately. Go into your email filter - [Welcome to Fresh Phish](https://freshphish.info/?p=1) - Where you can see some of the latest real world phishing emails. Learn from them so you don't get hooked. ## Pages - [DMARC Speaker for Security Conference](https://freshphish.info/?page_id=37) - Would you like to have a speaker talking about the importance of DMARC, how it works and how to implement it? Let me know! I am a DMARC expert and would enjoy teaching others how it works and how they can implement it. I've given the talk at only one conference so far but it - [DMARC Assistance](https://freshphish.info/?page_id=271) - Are you struggling to implement a DMARC reject policy? Are scammers spoofing your domain? Are your real emails being rejected by DMARC? Let me know! I have decided to provide DMARC assistance to companies that are having problems. Contact me to discuss rates. --Matt - [Privacy Policy](https://freshphish.info/?page_id=170) - Who we are Our website address is: https://freshphish.info. Comments When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided ## Categories - [Uncategorized](https://freshphish.info/?cat=1) - [Phish](https://freshphish.info/?cat=12) - Examples of phishing emails found in the wild. - [DMARC](https://freshphish.info/?cat=13) - Regarding DMARC. Explanations, instructions, recommendations. - [Malvertising](https://freshphish.info/?cat=53) ## Tags - [phish](https://freshphish.info/?tag=phish) - [paypal](https://freshphish.info/?tag=paypal) - [.ics file](https://freshphish.info/?tag=ics-file) - [hexadecimal version of IP address](https://freshphish.info/?tag=hexadecimal-version-of-ip-address) - [DMARC](https://freshphish.info/?tag=dmarc) - [email security](https://freshphish.info/?tag=email-security) - [SPF](https://freshphish.info/?tag=spf) - [DKIM](https://freshphish.info/?tag=dkim) - [Facebook](https://freshphish.info/?tag=facebook) - [Salesforce](https://freshphish.info/?tag=salesforce) - [TechRepublic](https://freshphish.info/?tag=techrepublic) - [Argentina](https://freshphish.info/?tag=argentina) - [Russia](https://freshphish.info/?tag=russia) - [Microsoft](https://freshphish.info/?tag=microsoft) - [judicialwatch.org](https://freshphish.info/?tag=judicialwatch-org) - [booking.com](https://freshphish.info/?tag=booking-com) - [Yahoo](https://freshphish.info/?tag=yahoo) - [Weebly](https://freshphish.info/?tag=weebly) - [MRWEEBEE](https://freshphish.info/?tag=mrweebee) - [smish](https://freshphish.info/?tag=smish) - [phish kits](https://freshphish.info/?tag=phish-kits) - [malware](https://freshphish.info/?tag=malware) - [iso file](https://freshphish.info/?tag=iso-file) - [html file](https://freshphish.info/?tag=html-file) - [cryptocurrency](https://freshphish.info/?tag=cryptocurrency) - [cryptowallet](https://freshphish.info/?tag=cryptowallet) - [crypto currency](https://freshphish.info/?tag=crypto-currency) - [crypto wallet](https://freshphish.info/?tag=crypto-wallet) - [Exodus](https://freshphish.info/?tag=exodus) - [refund scam](https://freshphish.info/?tag=refund-scam) - [Bitcoin](https://freshphish.info/?tag=bitcoin) - [Google Translate](https://freshphish.info/?tag=google-translate) - [RTLO](https://freshphish.info/?tag=rtlo) - [RTLO character](https://freshphish.info/?tag=rtlo-character) - [filenames](https://freshphish.info/?tag=filenames) - [html attachment](https://freshphish.info/?tag=html-attachment) - [Citibank](https://freshphish.info/?tag=citibank) - [malware delivery](https://freshphish.info/?tag=malware-delivery) - [windows registry](https://freshphish.info/?tag=windows-registry) - [qr codes](https://freshphish.info/?tag=qr-codes) - [TOAD](https://freshphish.info/?tag=toad) - [Fake AV](https://freshphish.info/?tag=fake-av) - [malvertising](https://freshphish.info/?tag=malvertising) - [Proofpoint](https://freshphish.info/?tag=proofpoint) - [Meta](https://freshphish.info/?tag=meta) - [svg](https://freshphish.info/?tag=svg) - [malicious](https://freshphish.info/?tag=malicious) - [attachment](https://freshphish.info/?tag=attachment) - [scalable vector graphic](https://freshphish.info/?tag=scalable-vector-graphic) - [Adobe](https://freshphish.info/?tag=adobe) - [base64](https://freshphish.info/?tag=base64) - [compromised site](https://freshphish.info/?tag=compromised-site) - [pebkac](https://freshphish.info/?tag=pebkac) - [organic component](https://freshphish.info/?tag=organic-component) - [copy-paste](https://freshphish.info/?tag=copy-paste) - [Microsoft Purview](https://freshphish.info/?tag=microsoft-purview) - [social security](https://freshphish.info/?tag=social-security) - [attack vector](https://freshphish.info/?tag=attack-vector) - [DNS](https://freshphish.info/?tag=dns) - [html smuggling](https://freshphish.info/?tag=html-smuggling) - [registry smuggling](https://freshphish.info/?tag=registry-smuggling) - [clickfix](https://freshphish.info/?tag=clickfix) - [EA GAmes](https://freshphish.info/?tag=ea-games) - [bulk email](https://freshphish.info/?tag=bulk-email)