This incident involves a phishing email pretending to send the victim shared images. The phishing URL in the body of the email http://accounts.gmaillogin.com.serverfortechhelp.com/eng.service-login.adds-essions-een-us-1rnd-mbi.reply.rs/ contains the victim's email address in the query string, so the landing page looks like just a password entry dialog for Google. The user's email address and password are then posted to a second stage phishing page that collects the credentials. The base domain used in this attack, serverfortechhelp.com uses a Comodo SSL certificate, but the phishing hostname on the domain, accounts.gmaillogin.com.serverfortechhelp.com uses a separate LetsEncrypt SSL certificate. Both certificates were on 2017-05-04.
Created: 2026-02-23
Indicatorsは見つかっていない。
このPulseに見つかったCVEはありません。