Friday, November 22, 2019

New Phishing Attack Observed [Random]


While trying to figure out why my Outlook 2007 can't IMAP connect to outlook.com and get emails, I come across a suspicious website.

I googled for "outlook +2007 cannot connect imap" and filter results to only those from the past week. The top result goes to the website www.vinar*.com (not going to provide the full site url since it might be dangerous).

I have uMatrix (an browser extension) on by default, and nothing loads when I clock on that first search results. If I scroll through it (or look at the HTML code), I find a lot of SEO type text to get it to the top of the search results.

While I can't say conclusively, it does occur to me that this can be a form of phishing/virus attack. I.e., find a comment/recent problem, get your page to listed as a top results, and have people go to your site where it runs gods know what that might potentially be dangerous.

For those that have no idea what uMatrix is, from the mozilla.org page: "Point & click to forbid/allow any class of requests made by your browser. Use it to block scripts, iframes, ads, facebook, etc."

(And unfortunately, I still can't figure out my IMAP issue. I am reading that Microsoft is experiment with TLS1.3 and that breaks Outlook connections for outlook running on newer versions of Windows. I am running Outlook 2007 on Windows XP and so that's not quite the problem.)