{"id":6677,"date":"2024-01-05T08:30:09","date_gmt":"2024-01-05T13:30:09","guid":{"rendered":"https:\/\/nexela.wpenginepowered.com\/?p=6677"},"modified":"2024-01-02T02:18:50","modified_gmt":"2024-01-02T07:18:50","slug":"suspicious-links-it-s-all-in-the-period","status":"publish","type":"post","link":"https:\/\/nexela.com\/?p=6677","title":{"rendered":"Suspicious Links? It\u2019s All In The Period"},"content":{"rendered":"<p>We\u2019re always telling people to avoid clicking on suspicious links, but the bad guys are making it harder to tell the difference between a legitimate URL and a suspicious one. We\u2019re going to try to simplify it for you, and have you focus on the placement of a single punctuation mark in a link to tell if it might be safe or dangerous.<\/p>\n<p><!--more--><\/p>\n<h2>Introducing The World\u2019s Most Trusted, Fictional Online Retailer<\/h2>\n<p>Let\u2019s make up a fictional company that becomes a massive global retailer and multimedia company, as well as a household name. We\u2019ll call our fake enterprise <em>Flimflamazon<\/em>.<\/p>\n<p>Our totally made-up Flimflamazon has a million billion products and services, and users log in to buy and sell products, manage their payments, run advertising campaigns, customize their own personal Flimflamazon user profiles, watch Flimflamazon movies that were shot exclusively by Flimflamazon Studios, manage their Flimflamazon Web Hosting accounts, and Flimflamazon is proud to announce that patients can now log in to their Flimflamazon to receive telehealthcare from our licensed Flimflamazon doctors and nurses.<\/p>\n<p>Our slogan is <strong>Flimflamazon; Everything is Here.<\/strong><\/p>\n<p>Because Flimflamazon has become the world\u2019s most trusted online retailer, and one of the largest marketplaces and distributors of content, people generally trust it. Just like our ads say, before Flimflamazon, buying products online and consuming media was challenging.<\/p>\n<p>As fun as this is, I think that\u2019s enough world-building for this example. You get the idea. Flimflamazon is, much like companies such as Facebook, Amazon, and Google, huge, multi-faceted, and generally known and trusted by the public.<\/p>\n<p><strong>Like Facebook, Google, PayPal, and Amazon, Flimflamazon\u2019s massive success leads to Flimflamazon users being constantly scammed by cybercriminals to try to trick them out of their money and sensitive information.<\/strong><\/p>\n<h2>When Users Feel Safe, Cybercriminals Have an Edge<\/h2>\n<p>So Flimflamazon users get a lot of email from Flimflamazon. They get emails about products they should buy, account notifications, and receipts. They get emails about their transactions and the products they are trying to sell. They get offers and alerts and everything in between.<\/p>\n<p>All a cybercriminal has to do is make an email look like a typical Flimflamazon email. They can steal the branding and do some technical spoofing to make the email look like it\u2019s coming from one of the dozens of legitimate Flimflamazon email addresses.<\/p>\n<p>They can then include links that look like they go to Flimflamazon, but actually lead the user to a similar looking URL that the cybercriminals purchased and control.&nbsp;<\/p>\n<p>It only costs a few dollars and a little time to create a web page that looks legitimate. A cybercriminal could purchase Flinflamazon.com (notice the subtle spelling difference?) or Flimflamazoncustomerservice.com or a whole slew of other simple tricks to look like they are a legitimate company. It\u2019s up to <strong>all of us<\/strong> to be aware of what to look for so we don\u2019t get scammed.<\/p>\n<p>The links that take you to scam pages exist to steal your information and money, and while the destination might look legitimate, once you go to the scam page of a phishing attack, it might already be too late to look for other potential warning signs.<\/p>\n<h2>How to See the URL Destination of a Link In an Email, Chat, or Other Correspondence:<\/h2>\n<p>While this is going to change a little from one application to another, typically you can see the destination of a link by hovering your mouse over it. Most email clients and web browsers will tell you exactly where the link is going to at the bottom of the page.<\/p>\n<p>For instance, if you are reading this blog in Google Chrome, and you hover your mouse over <a href=\"https:\/\/www.youtube.com\/watch?v=dQw4w9WgXcQ\">this link<\/a>, you will see that it is going to take you over to a YouTube video by looking at the very bottom left of your browser window. Most browsers and email clients like Outlook do the same thing.<\/p>\n<h2>The Periods in a URL Will Likely Be the Dead Giveaway if a Link is Safe<\/h2>\n<p>While you still need to be on the lookout for misspellings and unofficial URLs, one easy way to identify a sketchy link is by looking for a period after the domain name of the website.<\/p>\n<p>Flimflamazon.com is the <strong>domain name<\/strong>. When you are looking at a URL, there can be other stuff <strong>BEFORE<\/strong> a domain name. This is called a <strong>sub domain<\/strong>.<\/p>\n<p>If I own Flimflamazon.com, and I want to make a subdomain, like \u201chelp.flimflamazon.com,\u201d or \u201csupport.flimflamazon.com,\u201d or \u201caccount.flimflamazon.com,\u201d I can do that. Nobody else is able to create a subdomain without actually owning the rights to flimflamazon.com.<\/p>\n<p>There can also be stuff in the URL after the domain name, after a forward slash (\/) or question mark (?). This represents <strong>sub pages<\/strong> or variables on that site, but these elements typically cannot have periods in them. There is an exception, but we\u2019ll cover that in the moment.<\/p>\n<p>Flimflamazon.com could have millions of subpages, so anything after a forward slash is fair game.<\/p>\n<p><strong>If there is a period AFTER the domain name of the website you want to go to, then it might be a trap.<\/strong><\/p>\n<ul>\n<li aria-level=\"1\"><strong>https:\/\/www.flimflamazon.com\/gp\/help\/customer\/account-issues <\/strong>&#8211; This is safe because there isn\u2019t a period after the .com.&nbsp;<\/li>\n<li aria-level=\"1\"><strong>https:\/\/support.flimflamazon.com\/<\/strong> &#8211; This is safe because the extra period is before the company\u2019s domain name (in this case, flimflamazon.com)<\/li>\n<li aria-level=\"1\"><strong>https:\/\/support.account.flimflamazon.com\/customer-support\/password-reset<\/strong> &#8211; Again, this is safe because there are no periods after flimlamazon.com, regardless of how many subdomains (extra periods) are before it in the URL.<\/li>\n<li aria-level=\"1\"><strong>https:\/\/support.flimflamazon.ru <\/strong>&#8211; Time to slow down. While Flimflamazon might legitimately have a .ru domain, not every business has every variation of the domain extension (like .org, .net, .co, .co.uk, etc.). As soon as you get something you don\u2019t expect, start to scrutinize even more. If a company owns their .com domain, they might not also own the .net, for example.<\/li>\n<li aria-level=\"1\"><strong>https:\/\/flimflamazon.com.passwordservices.com\/help\/account-issues<\/strong> &#8211; This one is dangerous. This URL is technically taking you to a site called passwordservices.com. We just made that up for the example. Anyone could purchase that domain (or something similar) and spoof the URL to say Flimflamazon before the first period. It\u2019s tricky because it\u2019s easy to miss.<\/li>\n<\/ul>\n<p><strong>Let\u2019s take a look at another example, using PayPal:<\/strong><\/p>\n<ul>\n<li aria-level=\"1\"><strong>paypal.com<\/strong> &#8211; Safe<\/li>\n<li aria-level=\"1\"><strong>paypal.com\/activatecard<\/strong> &#8211; Safe<\/li>\n<li aria-level=\"1\"><strong>business.paypal.com<\/strong> &#8211; Safe<\/li>\n<li aria-level=\"1\"><strong>business.paypal.com\/retail<\/strong> &#8211; Safe<\/li>\n<li aria-level=\"1\"><strong>paypal.com.activatecard.net<\/strong> &#8211; Suspicious!<\/li>\n<li aria-level=\"1\"><strong>paypal.com.activatecard.net\/secure<\/strong> &#8211; Suspicious!<\/li>\n<li aria-level=\"1\"><strong>paypal.com\/activatecard\/tinyurl.com\/retail<\/strong> &#8211; Suspicious!<\/li>\n<\/ul>\n<p>Keep in mind, these URLs above may or may not be real, we\u2019re just making them up for the sake of an example!<\/p>\n<h3>We Mentioned an Exception<\/h3>\n<p>Some websites might have a period towards the end of the URL, ending with a file type. This might be something like .html, .htm, .asp, .php, and others.&nbsp;<\/p>\n<p>Other files, like PDF files, documents, and images, will have their own extensions too, such as .pdf, .doc, .jpg, .gif, and .png.&nbsp;&nbsp;<\/p>\n<p>While these files can generally be safe, it is possible that malware can be stored within a document or file. Going directly to one of these files can be especially dangerous if they happen to be malicious.&nbsp;<\/p>\n<p>Most businesses won\u2019t give you direct links to files like this without making sure you understand what you are doing. If Flimflamazon wanted you to download a PDF ebook, you would have a legitimate download button on a legitimate Flimflamazon.com page that links to the PDF, not a link or attachment in an email.<\/p>\n<h2>The TL;DR Version<\/h2>\n<p>Be careful what you click on! Legitimate-looking emails can have dangerous links.&nbsp;<\/p>\n<p>Hover over a link to carefully read where it is going to send you before you click on it. If there is a <strong>period after the domain<\/strong>, or there are misspellings or other oddities, be skeptical!<\/p>\n<p>If you ever get an email from a reputable source telling you to log into your account to fix an urgent problem, don\u2019t do so with the links in the email; log in the way you normally would.<\/p>\n<p>We hope this helps! Share this blog post with your colleagues and friends to help make the web a safer place!<\/p>\n<style><\/style>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019re always telling people to avoid clicking on suspicious links, but the bad guys are making it harder to tell the difference between a legitimate URL and a suspicious one. We\u2019re going to try to simplify it for you, and have you focus on the placement of a single punctuation mark in a link to tell if it might be safe or dangerous.<\/p>\n","protected":false},"author":4,"featured_media":6681,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50,61],"tags":[79,88,67],"class_list":["post-6677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-security","tag-email","tag-phishing","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela<\/title>\n<meta name=\"description\" content=\"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nexela.com\/?p=6677\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela\" \/>\n<meta property=\"og:description\" content=\"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nexela.com\/?p=6677\" \/>\n<meta property=\"og:site_name\" content=\"| Philadelphia, PA | Nexela\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/PhiladelphiaITsupport\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-05T13:30:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-02T07:18:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nexela.com\/wp-content\/uploads\/link_655497209_400-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Eric Disengof\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@NexelaInc\" \/>\n<meta name=\"twitter:site\" content=\"@NexelaInc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Eric Disengof\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/nexela.com\/?p=6677\",\"url\":\"https:\/\/nexela.com\/?p=6677\",\"name\":\"Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela\",\"isPartOf\":{\"@id\":\"https:\/\/nexela.com\/#website\"},\"datePublished\":\"2024-01-05T13:30:09+00:00\",\"dateModified\":\"2024-01-02T07:18:50+00:00\",\"author\":{\"@id\":\"https:\/\/nexela.com\/#\/schema\/person\/5435031473121f8542dd2002ae241a9d\"},\"description\":\"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/nexela.com\/?p=6677\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/nexela.com\/#website\",\"url\":\"https:\/\/nexela.com\/\",\"name\":\"| Philadelphia, PA | Nexela\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/nexela.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/nexela.com\/#\/schema\/person\/5435031473121f8542dd2002ae241a9d\",\"name\":\"Eric Disengof\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/nexela.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/85f06e5e0c52138765f1a62466ec5a0779caee9daf1f1a3e2eca775fef7006e2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/85f06e5e0c52138765f1a62466ec5a0779caee9daf1f1a3e2eca775fef7006e2?s=96&d=mm&r=g\",\"caption\":\"Eric Disengof\"},\"url\":\"https:\/\/nexela.com\/?author=4\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela","description":"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nexela.com\/?p=6677","og_locale":"en_US","og_type":"article","og_title":"Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela","og_description":"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.","og_url":"https:\/\/nexela.com\/?p=6677","og_site_name":"| Philadelphia, PA | Nexela","article_publisher":"https:\/\/www.facebook.com\/PhiladelphiaITsupport","article_published_time":"2024-01-05T13:30:09+00:00","article_modified_time":"2024-01-02T07:18:50+00:00","og_image":[{"width":400,"height":400,"url":"https:\/\/nexela.com\/wp-content\/uploads\/link_655497209_400-1.jpg","type":"image\/jpeg"}],"author":"Eric Disengof","twitter_card":"summary_large_image","twitter_creator":"@NexelaInc","twitter_site":"@NexelaInc","twitter_misc":{"Written by":"Eric Disengof","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nexela.com\/?p=6677","url":"https:\/\/nexela.com\/?p=6677","name":"Suspicious Links? It\u2019s All In The Period | Philadelphia, PA | Nexela","isPartOf":{"@id":"https:\/\/nexela.com\/#website"},"datePublished":"2024-01-05T13:30:09+00:00","dateModified":"2024-01-02T07:18:50+00:00","author":{"@id":"https:\/\/nexela.com\/#\/schema\/person\/5435031473121f8542dd2002ae241a9d"},"description":"Think before you click! Here\u2019s a comprehensive guide to hopefully make it easier for you to spot suspicious and dangerous links in your email.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nexela.com\/?p=6677"]}]},{"@type":"WebSite","@id":"https:\/\/nexela.com\/#website","url":"https:\/\/nexela.com\/","name":"| Philadelphia, PA | Nexela","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nexela.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/nexela.com\/#\/schema\/person\/5435031473121f8542dd2002ae241a9d","name":"Eric Disengof","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/nexela.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/85f06e5e0c52138765f1a62466ec5a0779caee9daf1f1a3e2eca775fef7006e2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/85f06e5e0c52138765f1a62466ec5a0779caee9daf1f1a3e2eca775fef7006e2?s=96&d=mm&r=g","caption":"Eric Disengof"},"url":"https:\/\/nexela.com\/?author=4"}]}},"_links":{"self":[{"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/posts\/6677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/nexela.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6677"}],"version-history":[{"count":0,"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/posts\/6677\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nexela.com\/index.php?rest_route=\/wp\/v2\/media\/6681"}],"wp:attachment":[{"href":"https:\/\/nexela.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nexela.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nexela.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}