Phishing Emails now using SendGrid for URL ReWrites

Recently had a user receive an email that got past multi Spam protection. The issue was the sender had actually been hacked and they were using his email service to spam all his contacts with the below: 


I have been trying to send you this file, but it failed with attaching them to my email. I managed to upload them here. The document is password protected for confidentiality. You may be required to sign in to view.

View Here <https://u8062662.ct.sendgrid.net/wf/click?upn=wZQTK0j1og7ZpMJhH8Ud1KVnbiPHM9y73Xakn2Kz-2FW3NjeIbG2SHvoQBr-2FU18gy0sWZ8XmNWnZXVIwYoPeDbMdKFtXGpU-2FkCKJt7n9ht0-2Bc-3D_5kx02phTxyE6nAkdmbPR-2BLnKNuh-2FMh-2Fnzaqek3PlNNGNn5K7iZReVzccFSICLkn2TWbvJrH-2Bw-2BE7xgHn2ty-2B1BSOsEXhaW-2Fe1ryw1S4JCO1SZ5Cc96DNVFrgvKTCexkvDBOvJEZat1Xu3mo-2F-2Bg54FPgHa7ASkej2pIVyR-2BRlCbquUGTUk4YBF0lmrI20ZPDbWrW-2Fob7Pfi5neeYJCNhBDw-2FFhGqmFj4h8u6mNpuZg9g-3D>

 

Sendgrid is used for mass emails and people use sendgrid to track clicks. This domain is also never going to be blocked or marked as an issue

The link actually redirects to here : https://beautifulbeanfootage.com/box/Login.php?sslchannel=true which is a Phish page pretending to be box.com

 

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...