Catching a Rookie Mistake in a Facebook Phish
Summary
This short post will show a real-world phish that DNSWatch caught and how analysts were able to garner further information using trivial open-source tools because of a unique mistake by the attacker. Second, the login page is displaying a warning banner in red-colored font that states: “Facebook needs to verify your account information to allow access to this video”. Finally, at the time of this writing, the Facebook login page has been updated and no longer resembles what this phishing attempt is impersonating. Upon inspecting the source code of the website and navigating to the authentication form there exists an obvious anomaly. It is also worth noting that this IP address has ports open for HTTP(S), FTP(S), IMAP(S), SMTP(S), and DNS.
Classifications
industries
Retail
applications
Security
AskAI Classifications
Labels
Cybersecurity Software
SaaS
Network Security
Linked Companies
WatchGuard
$250M to $500M