Go to the U of M home page

Wednesday, June 22, 2016

Phishing Example 153: Fake PDF attachment "For your Perusal"

Received June 2016

From: [compromised @umn.edu account]
Date: Tue, Jun 21, 2016 at 12:41 PM

This file is sent for your perusal


(Attached is a PDF with a link: )

Clicking on PDF will go to a URL that downloads a javascript form

Form to capture email address and password
  • Mail sent from a compromised UMN account belonging to someone you might know
  • Mail includes an attached PDF that has an active URL link
  • The URL goes to a website that loads a javascript form - the address bar on the form will not show a proper URL (see picture)

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.