<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacker | Matt Crawford</title>
	<atom:link href="https://mattcrawford.me/tag/hacker/feed/" rel="self" type="application/rss+xml" />
	<link>https://mattcrawford.me</link>
	<description>Handyman &#124; Geek &#124; YouTuber</description>
	<lastBuildDate>Tue, 14 Jun 2022 23:20:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
<site xmlns="com-wordpress:feed-additions:1">176948450</site>	<item>
		<title>Interesting Phishing Attempt</title>
		<link>https://mattcrawford.me/interesting-phishing-attempt/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=interesting-phishing-attempt</link>
					<comments>https://mattcrawford.me/interesting-phishing-attempt/#comments</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Wed, 28 Oct 2020 18:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[e-mail]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[html]]></category>
		<category><![CDATA[lame]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing e-mail]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://mattcrawford.me/?p=5500</guid>

					<description><![CDATA[<p>One of my co-workers received an e-mail with an attachment titled &#8220;INVOICE_26.HTML&#8221; and asked if there was anyway to scan it before clicking on it. Since it&#8217;s an .html file virus scanners would claim it was not infected since the file isn&#8217;t infected with a virus or trojan. This is just a phishing attempt which [&#8230;]</p>
The post <a href="https://mattcrawford.me/interesting-phishing-attempt/">Interesting Phishing Attempt</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">One of my co-workers received an e-mail with an attachment titled &#8220;<strong>INVOICE_26.HTML</strong>&#8221; and asked if there was anyway to scan it before clicking on it.  </p>



<p class="wp-block-paragraph">Since it&#8217;s an .html file virus scanners would claim it was not infected since the file isn&#8217;t infected with a virus or trojan. This is just a phishing attempt which starts when a user opens the fake internet page.</p>



<p class="wp-block-paragraph">So I viewed the source code of the file in notepad ++ and this is what I found.</p>



<pre class="wp-block-code"><code>&lt;!DOCTYPE html>
&lt;html>
&lt;head>
&lt;meta name="viewport" content="width=device-width, initial-scale=1">
&lt;style>
.container {
  position: relative;
  width: 100%;
  max-width: 400px;
}

.container img {
  width: 100%;
  height: auto;
}

.container .btn {
  position: absolute;
  top: 50%;
  left: 50%;
  transform: translate(-50%, -50%);
  -ms-transform: translate(-50%, -50%);
  background-color: #228B22;
  color: white;
  font-size: 16px;
  padding: 12px 24px;
  border: none;
  cursor: pointer;
  border-radius: 5px;
  text-align: center;
}

.container .btn:hover {
  background-color: black;
}
&lt;/style>
&lt;/head>
&lt;body>

&lt;h2>&lt;font face="arial">&lt;u>D&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ocu&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ment is sec&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ured&lt;/u>&lt;/font>&lt;/h2>&lt;br>
&lt;p>&lt;b>&lt;font face="sans serif">Cl&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ic&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>k be&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>low to v&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>iew com&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>ple&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>te fi&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>le&lt;/font>&lt;/b>&lt;/p>

&lt;div class="container">
  &lt;img src="https://i.ibb.co/qghx6vy/b.jpg" alt="invoice" style="width:100%;height:100%">
  &lt;button class="btn" onclick="window.location.href='https://ingenioxicotencatl.com/adk/wamp.php?warp=020202'" >Vie&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>w Fi&lt;span style="font-size: 0px">jgfhgfhgfchgfxhfesyrdzxdgszgczgcxzgfdzhfdxhgfxjgfxjgfcjhcgfjgckjhufkugk&lt;/span>le&lt;/button>
&lt;/div>

&lt;/body>
&lt;/html></code></pre>



<p class="wp-block-paragraph">If you actually look through the code you will quickly learn that all that gibberish and random letters will not show up on the page due to it being between the tags shown below.</p>



<pre class="wp-block-code"><code>&lt;span style="font-size: 0px"> &lt;/span></code></pre>



<p class="wp-block-paragraph">Instead anybody viewing the page would simply see the following words.</p>



<pre class="wp-block-preformatted">Document is secured

Click below to view complete file

View File</pre>



<p class="wp-block-paragraph">The words &#8220;View File&#8221; are actually a button which goes to the url shown in the code above. </p>



<p class="wp-block-paragraph">Aka this is just a lame phishing attempt that somebody is trying to confuse the average person with however I&#8217;m no average person and simply do not fall for tricks like this.</p>



<p class="wp-block-paragraph">Check out the links below for more information regarding phishing.</p>



<ul class="wp-block-list"><li><a href="https://ideas.ted.com/why-we-fall-for-phishing-emails-and-how-we-can-protect-ourselves/" target="_blank" rel="noreferrer noopener">Why we fall for phishing e-mails</a> </li><li><a href="https://blog.malwarebytes.com/101/2018/09/6-sure-signs-someone-is-phishing-you-besides-email/" target="_blank" rel="noreferrer noopener">6 sure signs somebody is phishing you</a></li><li><a href="https://www.globallearningsystems.com/what-to-do-after-a-phishing-attack/" target="_blank" rel="noreferrer noopener">What to do after a phishing attack</a>.</li><li><a href="https://www.technologyvisionaries.com/latest-phishing-scams/" target="_blank" rel="noreferrer noopener">What are the latest phishing scams in 2020</a></li></ul>



<p class="wp-block-paragraph">Leave me a comment below if you enjoyed this article!</p>The post <a href="https://mattcrawford.me/interesting-phishing-attempt/">Interesting Phishing Attempt</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/interesting-phishing-attempt/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5500</post-id>	</item>
	</channel>
</rss>
