{"id":1731,"date":"2023-09-25T10:58:28","date_gmt":"2023-09-25T17:58:28","guid":{"rendered":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/?p=1731"},"modified":"2023-09-25T15:34:35","modified_gmt":"2023-09-25T22:34:35","slug":"pdf-attachment-in-a-legit-looking-email","status":"publish","type":"post","link":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2023\/09\/25\/pdf-attachment-in-a-legit-looking-email\/","title":{"rendered":"pdf attachment in a legit looking email."},"content":{"rendered":"<p>Malicious actors deployed a bunch of phish against UVic recipients today. The trick they apply is to use some authentic text sent by a UVic person. In some cases that&#8217;s a mass-mail sent a year ago to hundreds of recipients, in some cases it is just the out-of office message of somebody. In all cases they add a line of theirs on top of the legit text &#8212; &#8220;please check the attachment&#8221;. The sender address is different. The display name <span class=\"ui-provider ec bee bef beg beh bei bej bek bel bem ben beo bep beq ber bes bet beu bev bew bex bey bez bfa bfb bfc bfd bfe bff bfg bfh bfi bfj bfk bfl\" dir=\"ltr\">may copy a name from the original email thread<\/span>. The attachment itself contains a link to the actual malicious content. A screenshots of a few examples are shown below. The pdf attachments are usually having a very short name &#8211; one or two characters. (however that doesn&#8217;t mean that every attachment with a long and meaningful name is legit). Be vigilant, apply common sense and don&#8217;t open attachments from suspicious emails (unknown sender, unsolicited, etc.).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1733\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925A.png\" alt=\"\" width=\"1206\" height=\"685\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925A.png 1206w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925A-300x170.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925A-1024x582.png 1024w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925A-768x436.png 768w\" sizes=\"auto, (max-width: 1206px) 100vw, 1206px\" \/><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1735\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925C.png\" alt=\"\" width=\"1180\" height=\"588\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925C.png 1180w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925C-300x149.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925C-1024x510.png 1024w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925C-768x383.png 768w\" sizes=\"auto, (max-width: 1180px) 100vw, 1180px\" \/><\/p>\n<hr \/>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1736\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925D.png\" alt=\"\" width=\"1013\" height=\"577\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925D.png 1013w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925D-300x171.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925D-768x437.png 768w\" sizes=\"auto, (max-width: 1013px) 100vw, 1013px\" \/><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>The PDF itself looks like this:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1737\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925E.png\" alt=\"\" width=\"1285\" height=\"615\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925E.png 1285w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925E-300x144.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925E-1024x490.png 1024w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2023\/09\/phish20230925E-768x368.png 768w\" sizes=\"auto, (max-width: 1285px) 100vw, 1285px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious actors deployed a bunch of phish against UVic recipients today. The trick they apply is to use some authentic text sent by a UVic person. In some cases that&#8217;s a mass-mail sent a year ago to hundreds of recipients, in some cases it is just the out-of office message of somebody. In all cases &hellip; <a href=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2023\/09\/25\/pdf-attachment-in-a-legit-looking-email\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">pdf attachment in a legit looking email.<\/span><\/a><\/p>\n","protected":false},"author":738,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1731","post","type-post","status-publish","format-image","hentry","category-uncategorized","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/users\/738"}],"replies":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/comments?post=1731"}],"version-history":[{"count":4,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1731\/revisions"}],"predecessor-version":[{"id":1742,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/1731\/revisions\/1742"}],"wp:attachment":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/media?parent=1731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/categories?post=1731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/tags?post=1731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}