Local gmail phishing

NullHypothesis

Well-Known Member
Joined
Nov 20, 2015
Messages
363
Just a heads up.

A friend recently told me about a suspicious Email she received, so I asked her to forward it to me.

It was sent to an Email address that processes sales queries, quotes, invoices etc.

Email read:
From: mmabotsile myeni [mailto:mmmabotsile@gmail.com]
Subject: Order

Hello

Attached is the receipt of the purchase order and kindly process urgently for collection.
Kind Regards,

mmabotsile myeni
Senior Hydrogeologist - First Quantum

Attached was an HTML file: Order.7.html

Which when opened is a Gmail login form with the text "Sign in to view PDF file" above it.

The form is being processed by the domain: purchaseht.com (Registered On 2016-10-21)

The whois details on that domain seems bogus:

Name: christain martin
Organization: howardmartin
Address: no 23 west street no 13 west street
City: sandton
State / Province: Johannesburg
Postal Code: 1696
Country: ZA
Phone: +27.814717559
Email: [kkdlamini91@gmail.com]

Now these people would not be able to catch out anyone with awareness in these matters and it goes without saying that a person should not have to log into anywhere to see a receipt under the circumstances. It's just sometimes people get caught up in the fog of work and the alarm bells don't go off.
 
Top