¾«Æ·³ÉÈ˸£ÀûÔÚÏß

Abstract Aliens On Flying Saucers Northern Lights Lighthouse Mountains Water Tree Sun Background Gradient Unidentified Flying Object Ufo Stars Vector Design Style Landscape
Phish Files Articles

¾«Æ·³ÉÈ˸£ÀûÔÚÏß University Payment Returned.

Posted in: Spear Phishing

phishing email posing as MSU to gather personal information.

Screenshot of the malicious page utilized in overdue fee phish attack.

Why this looks valid:

  • Email is coming from an internal email address
  • ¾«Æ·³ÉÈ˸£ÀûÔÚÏß University logo is used
  • Email name is ¾«Æ·³ÉÈ˸£ÀûÔÚÏß University
  • Link within email is showing as MSU website

Why this is phishing?

  • Email address is a personal MSU account
  • Sense of Urgency: Stating you’ll lose access to you account
  • Link is actually malicious and not associated with MSU. Using the hover over technique it points somewhere else.
  • Spelling: Attacker uses “C*V*V #” on the malicious website instead of CSV
  • Personally Identifiable Information (PII): Attacker is requesting SSN

Additional Notes: