Catching a Rookie Mistake in a Facebook Phish

General News

Summary

This short post will show a real-world phish that DNSWatch caught and how analysts were able to garner further information using trivial open-source tools because of a unique mistake by the attacker. Second, the login page is displaying a warning banner in red-colored font that states: “Facebook needs to verify your account information to allow access to this video”. Finally, at the time of this writing, the Facebook login page has been updated and no longer resembles what this phishing attempt is impersonating. Upon inspecting the source code of the website and navigating to the authentication form there exists an obvious anomaly. It is also worth noting that this IP address has ports open for HTTP(S), FTP(S), IMAP(S), SMTP(S), and DNS.

Classifications

industries
Retail
applications
Security

AskAI Classifications

Labels
Cybersecurity Software SaaS Network Security

Linked Companies

WatchGuard
$250M to $500M