This weekend I got a piece of e-mail that I thought was going to be an attempt at phishing, and I opened it expecting to quickly hit the "Report Phishing" doo-dad in Gmail.
But it didn’t contain a phishing appeal in the text of the e-mail itself. (You know, all those Nigeria/wherever variants on The Spanish Prisoner). Instead, it contained a link to a blog on Blogspot.
Ostensibly, the e-mail was from the pastor of a church in another country who had set up a blog and was inviting me to read it, but the e-mail still threw off phishing vibes to me even though there was no appeal for money in the e-mail itself.
So I clicked on the link and took a look at the blog.
I found what appeared to be the blog of a pastor in another country. Yet the way the thing was written and the way it re-used photographs kept my spider sense tingling and, sure enough, sandwiched in to various blog posts were appeals for financial support, and something in my brain said: "Two-step phishing routine; phishers may start sending out innocent-seeming e-mails as bait to get people to sites where traditional phishing is carried out."
Now, I don’t know for sure that this wasn’t legit. It may be that this really as the blog of a pastor in another country, who is innocently asking for donations.
Which is why I’m not naming the site. I don’t want to falsely accuse someone who is legitimate.
But just coincidentally, later that day, I happened to run into
THIS STORY ABOUT BLOGSPOT BEING INFECTED WITH PHISHING AND MALWARE-SPREADING BLOGS.
Be careful out there, folks.

