Contents

Convincing Phish

Overview

Phishing is real and common threat. Through false pretense, the hacker attempts to coerce the victim into providing secure information.

Definition

## Example

/wp-content/uploads/2020/11/image-14-1024x457-1.png## Tell-Tale signs

  1. It is an External email, noted in subject line.
  2. From an unknown, random email
  3. Commonly has misspellings or branding errors
  4. Links to random websites

In the above example, I (safely) clicked on the link and it resulted in

/wp-content/uploads/2020/11/image-18-1024x750-1.pngNotice the prompt looks exactly like the Microsoft branding. However, the “real” prompt for Microsoft credentials is always hosted on microsoftonline.com web

/wp-content/uploads/2020/11/image-17-1024x742-1.pngBack on the bad example, I entered incorrect credentials several times and it redirected me back to a legitimate site. This can help cover their trail of wrongdoing and confuses the user.

/wp-content/uploads/2020/11/image-19-1024x757-1.png