{"id":1688,"date":"2023-08-28T14:20:57","date_gmt":"2023-08-28T21:20:57","guid":{"rendered":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/?p=1688"},"modified":"2023-08-28T14:22:58","modified_gmt":"2023-08-28T21:22:58","slug":"your-ultramar-invoice-is-now-available-to-view","status":"publish","type":"post","link":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2023\/08\/28\/your-ultramar-invoice-is-now-available-to-view\/","title":{"rendered":"Your Ultramar invoice is now available to view"},"content":{"rendered":"<p>Fake invoices are a common theme for PDF phishing. Be wary if you receive an invoice email that you weren&#8217;t expecting, especially if it comes from a company that you don&#8217;t have any dealings with. This fake invoice email is relatively well-written, but there are a couple of signs that the attachment isn&#8217;t legitimate:<\/p>\n<ul>\n<li>The email contains no personalized greeting; this can be a sign of a mass email sent to many recipients, when legitimate invoices are something that are supposed to be individualized.<\/li>\n<li>The email is unusually vague and doesn&#8217;t give any information about the supposed invoice; it just tells you to look at the attachment. Usually a legitimate invoice or receipt email will mention some basic information about the transaction, such as the total amount or perhaps the billing\/order date.<\/li>\n<\/ul>\n<p>The red flags above are a sign that you shouldn&#8217;t open the attachment. InfoSec examined the contents using a secure tool and found that it contains a blurred out picture of an invoice, overlaid with a box that says, &#8220;View Protected Document&#8221;. If a PDF tells you to click to view protected content, that is a sure sign the PDF is malicious. If you did open the PDF, reach out to your department&#8217;s IT support contact immediately for assistance, especially if you clicked on &#8220;View Protected Document&#8221;.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1689\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/08\/2023-08-28-ultramar-invoicepng.png\" alt=\"Fake invoice email directing you to click on a malicious PDF attachment for details\" width=\"779\" height=\"514\" aria-describedby=\"phish_transcript\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/08\/2023-08-28-ultramar-invoicepng.png 779w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/08\/2023-08-28-ultramar-invoicepng-300x198.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/08\/2023-08-28-ultramar-invoicepng-768x507.png 768w\" sizes=\"auto, (max-width: 779px) 100vw, 779px\" \/><\/p>\n<blockquote id=\"phish_transcript\"><p>From: Ultramar &lt;support@cobills.com&gt;<br \/>\nSubject: Your Ultramar invoice is now available to view\/Votre facture Ultramar est maintenant disponible \u00e0 la consultation<\/p>\n<p>Attachment: Invoice3421.pdf<\/p>\n<p>Thank you for choosing Ultramar as your product and service provider. We appreciate your business! We would like to remind you that e-Bill is our environmentally friendly billing option.<br \/>\n<strong>Please do not reply to this email.<\/strong><br \/>\nIf you have any questions, please see the attached statement for Ultramar contact information.<\/p>\n<p>Merci d&#8217;avoir choisi Ultramar comme fournisseur de produits et services. Nous appr\u00e9cions votre entreprise ! Nous vous rappelons que l&#8217;e-Bill est notre option de facturation \u00e9cologique.<br \/>\n<strong>Veuillez ne pas r\u00e9pondre \u00e0 cet e-mail.<\/strong><br \/>\nSi vous avez des question, veuillez consulter la d\u00e9claration ci-jointe pour les coordonn\u00e9es d&#8217;Ultramar.<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Fake invoices are a common theme for PDF phishing. Be wary if you receive an invoice email that you weren&#8217;t expecting, especially if it comes from a company that you don&#8217;t have any dealings with. This fake invoice email is relatively well-written, but there are a couple of signs that the attachment isn&#8217;t legitimate: The &hellip; <a href=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2023\/08\/28\/your-ultramar-invoice-is-now-available-to-view\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Your Ultramar invoice is now available to view<\/span><\/a><\/p>\n","protected":false},"author":8719,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1688","post","type-post","status-publish","format-image","hentry","category-uncategorized","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/users\/8719"}],"replies":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/comments?post=1688"}],"version-history":[{"count":2,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1688\/revisions"}],"predecessor-version":[{"id":1691,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1688\/revisions\/1691"}],"wp:attachment":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/media?parent=1688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/categories?post=1688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/tags?post=1688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}