The sender of this phishing email (Prof. Weinert) was arbitrarily chosen by the attacker. Any other sender could also be listed there (even the President of the University). As you know, all public information is also available to the attacker.
There are several indicators in this email that suggest it is a phishing email.
Absender [1] und Signatur [7] stimmen nicht überein (Weingarten vs. Weinert). Außerdem gibt es diese E-Mail-Adresse überhaupt nicht an der Hochschule 'montessori@ph-weingarten'.
Es wird Druck aufgebaut bzw. soll eine Handlung erzwungen werden (Betreff: „Warnung“)
Es wird auch hier Druck aufgebaut bzw. soll eine Handlung erzwungen werden (im Text der Satz: Sie können sonst keine Mails mehr empfangen oder senden.).
Der Angreifer verwendet eine schlechte deutsche Grammatik.
Die E-Mail ist nicht signiert. Es fehlt ein vom DFN hinterlegtes Nutzerzertifikat, das die Identität des Schreibers bestätigt. Eine signierte Mail erkennt man am roten Siegel und dem Text „Signiert von Musterperson“.
Wenn Sie mit der Maus über den Link gehen, ohne zu klicken, steht als Webseite „https://rodeli.com.mx“ Das ist keine Webseite der Hochschule Anhalt. Außerdem steht dort „Klick hier“ und nicht „Klicken Sie hier“. Das ist sehr inkonsequent, weil die ganze Zeit das „Sie“ verwendet wird.
Die genannte Person hat nichts mit dem IT-HelpDesk oder mit der IT der Hochschule zu tun. Die Adresse vom Helpdesk ist auch nicht Köthen.
Die Telefonnummer ist falsch. Wir haben hier in Köthen 03496 67… und nicht 03496 69. Außerdem gibt es auch nicht die Mailadresse 'admin@hs-anhalt..'. Das sind allerdings zwei Punkte, die nicht wirklich sofort offensichtlich sind.
Das Verwenden des Hochschullogos ist kein Vertrauensbeweis. Das kann jeder kopieren und in eine Mail einbinden.
And even if you have followed the phishing link, it is not yet critical. It only becomes critical when you enter your real data into the input form on the following webpage "rodeli.com.mx" [10]. The used copyright [11] is also not a guarantee of trust. The features are highlighted in red in the image once again.
"rodeli.com.mx" hat nichts mit der Hochschule Anhalt zu tun
Die Eingabemaske ist ein Fake. Unsere sehen anders aus.
Einen Copyright kann jeder einfügen. Das ist kein Vertrauensbeweis.
The input forms for password changes at HSA currently look like this:
© IT-Service-Center
And can be found at the following addresses:
https://selfservice.hs-anhalt.de/
If you have now entered your data into the fake website, the attacker will log into your OWA account (right) in the background and immediately create a rule that, for example, moves all incoming emails to the trash. Now the attacker has access to your email inbox and can send mass emails from there, delete, alter, or simply read your data in the mailbox. There might be some interesting information there whose dissemination is not desired, etc.
Examine every email with a critical eye and only click on links or open attachments if the email seems plausible to you.
Please forward these solely as an attachment. If you do not know how to do this, please contact the responsible administrator in your area beforehand. Otherwise, the phishing email may be distributed within the network, increasing the risk that other employees might fall for it.
© HSA
Do you already have the new Outlook add-in for conveniently reporting phishing emails?
Talk to your administrator.