{"id":769,"date":"2021-10-22T17:08:41","date_gmt":"2021-10-23T00:08:41","guid":{"rendered":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/?p=769"},"modified":"2021-10-25T10:53:44","modified_gmt":"2021-10-25T17:53:44","slug":"you-have-received-2-file-via-we-transfer","status":"publish","type":"post","link":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2021\/10\/22\/you-have-received-2-file-via-we-transfer\/","title":{"rendered":"You have received (2) file via We-Transfer"},"content":{"rendered":"<p>This phish comes with a relatively innocent subject suggesting you were sent files by &#8220;wetransfer&#8221; (a free file exchange platform). It contains a &#8220;Get your files&#8221; button and a separate &#8220;download link&#8221; which on screen seems to point to wetransfer.com.<br \/>\nWhat&#8217;s really dangerous about this phish is that both the button and the download link in fact point to a malicious site which has nothing to do neither with wetransfer, nor with UVic.\u00a0 The actual URL (pointed by the red arrow in the screenshot below) can be seen if you hover the mouse cursor over the link. \u00a0 That site contains a copy of the main UVic page and asks you to login with your UVic credentials.\u00a0 It looks so real that you may forgot what was the initial email about and you may forgot to check the address in the address bar.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-774\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-1.png\" alt=\"\" width=\"783\" height=\"864\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-1.png 783w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-1-272x300.png 272w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-1-768x847.png 768w\" sizes=\"auto, (max-width: 783px) 100vw, 783px\" \/><\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>And below is how the fake UVic page looks like. Note the malicious site address in the address bar.\u00a0 As always &#8211; we suggest not to be curious and not to click on such links even for a quick look. Some of them may contain malware and infect your machine almost instantly. Our experts open those in dedicated isolated environments.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-771\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-uvicpage.png\" alt=\"\" width=\"1164\" height=\"689\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-uvicpage.png 1164w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-uvicpage-300x178.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-uvicpage-1024x606.png 1024w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/10\/scam2021-10-22-uvicpage-768x455.png 768w\" sizes=\"auto, (max-width: 1164px) 100vw, 1164px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This phish comes with a relatively innocent subject suggesting you were sent files by &#8220;wetransfer&#8221; (a free file exchange platform). It contains a &#8220;Get your files&#8221; button and a separate &#8220;download link&#8221; which on screen seems to point to wetransfer.com. What&#8217;s really dangerous about this phish is that both the button and the download link &hellip; <a href=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2021\/10\/22\/you-have-received-2-file-via-we-transfer\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">You have received (2) file via We-Transfer<\/span><\/a><\/p>\n","protected":false},"author":738,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-769","post","type-post","status-publish","format-image","hentry","category-uncategorized","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/769","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/users\/738"}],"replies":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/comments?post=769"}],"version-history":[{"count":3,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/769\/revisions"}],"predecessor-version":[{"id":776,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/769\/revisions\/776"}],"wp:attachment":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/media?parent=769"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/categories?post=769"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/tags?post=769"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}