Monday, February 24, 2020

Splash Wine Phishing Email - 15 Bottles of Overstocked Wines for only $85 with Free Shipping!

For the record, this is an Splash Wine phishing email attempt that is recently going around.  What to do?  Report them, goto bottom of page.

Interesting aspects of this phishing email; 

  1. https://aws.amazon.com/ using Amazon AWS
  2. https://storage.googleapis.com/ using Google Cloud Platform


From : Splash Wine <freetrial@dls.affpartners.com> aliased from  kgresk5hg@65e0q---65e0q----ap-southeast-2.compute.amazonaws.com


Subject
 : 15 Bottles of Overstocked Wines for only $85 with Free Shipping!




PHISHING LINKs;
The gatcha here is if you can't see image below, baiting you to click the link here

1. https://storage.googleapis.com/wadrari/splashwineLINKO.html
2. https://storage.googleapis.com/wadrari/splashwineUNSBLinkO.html - unsubscribe



How to tell this is a Phishing email ?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the  company's website then forget it.

  3. The best way is to look at message source, see below.

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from apple.com.


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing URLs at Google now 

If you have recievied this email take further action now by click these links

  1. https://www.google.com/safebrowsing/report_phish/


Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx

National Family Insurance Phishing Email - No Medical Exam up to $1,000,000 and Guaranteed Life Insurance Plans

For the record, this is an National Family Insurance phishing email attempt that is recently going around.  What to do?  Report them, goto bottom of page.

Interesting aspects of this phishing email; 

  1. https://aws.amazon.com/ using Amazon AWS
  2. https://storage.googleapis.com/ using Google Cloud Platform


From : National Family Insurance <tJruJhvt@kwbduiw1piwoyelp.com> aliased from  return@ec2-3-16-203-110.us-east-2.compute.amazonaws.com


Subject : No Medical Exam up to $1,000,000 and Guaranteed Life Insurance Plans


PHISHING LINKs;


The gatcha here is if you can't see image below, baiting you to click the link here

1. https://storage.googleapis.com/herouach/FamilyInsuraLINKO.html
2. https://storage.googleapis.com/wadrari/optoutjdida.html - unsubscribe



How to tell this is a Phishing email ?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the  company's website then forget it.

  3. The best way is to look at message source, see below.

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from apple.com.


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing URLs at Google now 

If you have recievied this email take further action now by click these links

  1. https://www.google.com/safebrowsing/report_phish/


Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx

Sunday, February 23, 2020

Walgreens Phishing Email - Congratulations You Have (1) New Walgreens Reward Ready To Claim!

For the record, this is an Walgreens phishing email attempt that is recently going around.  What to do?  Report them, goto bottom of page.

Interesting aspects of this phishing email; 

  1. https://aws.amazon.com/ using Amazon AWS
  2. https://storage.googleapis.com/ using Google Cloud Platform


From : Congratulations <freetrial@vnn.affpartners.com> aliased from  
fqz7slif7@1xerm---1xerm----ap-southeast-2.compute.amazonaws.com


Subject
 : 
Congratulations - You Have (1) New Walgreens Reward Ready To Claim!


Phishing Links

The gatcha here is if you can't see image below, baiting you to click the link here

1. https://storage.googleapis.com/wadrari/WalgreensLINKO.html
2. https://storage.googleapis.com/wadrari/optoutjdida.html - unsubscribe



How to tell this is a Phishing email ?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the  company's website then forget it.

  3. The best way is to look at message source, see below.

How to examine Email Message Source ?

Now lets look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from apple.com.


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing URLs at Google now 

If you have recievied this email take further action now by click these links

  1. https://www.google.com/safebrowsing/report_phish/


Report phishing at Microsoft and government agencies

  1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx