I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.
I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).
The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.
"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing...
I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging??
(at least they don't use 1drv.com in emails like Microsoft.. seriously...)
However you slice it, even after we conquer character limits and font rendering and storage space for every electronic device, human beings will still be using "the analog hole" to copy code like that.
Even if you retrieve registration information about a domain, that will not necessarily help a consumer figure out if it is legitimate, or who owns it. There will be a lot of redactions and shell companies and generic information.
The target market for WHOIS and RDAP has always been administrators and registrants and others on their level. Obviously--RDAP is a JSON format, not plain text anymore!
As a consumer, if you're trying OSINT, try not to spread that around, because it is another opportunity for deception, confusion, and cargo culting. What you want is good malware protection, according to your actual risk profile. If your browser protection is worthwhile then it will stop attacks from domains like that.
If you are particularly worried about strange domains, many 3rd-party DNS services can block those. NextDNS had a checkbox for "block newly-registered domains" as well as filtering any sus gTLD or ccTLD type ones.
Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).
I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.
It’s compliance theater. No real security is gained, but it checks all the boxes.
List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.
Its just attempting to work around incompetence, which always just shows up again somewhere else.
I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain.
Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc.
Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.
I wonder how many domains MS is running these days. It seems like each department and project gets its own.
The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exists. Morons.
Way back in time I wrote an HN post where I just spotaneously came up with plausible 2LD names off the dome and every single one was available. I won't bother repeating the exercise because it was evident that everybody who could understand this was unsurprised while the people who'd previously believed all the good names were gone just dismissed these as bad names because after all, if they were good names they'd be taken already, duh.
https://www.google.com/search?client=firefox-b-d&q=china+unl...
Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose
Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs.
BTW, it'd be nice if browsers automatically show the CNs of the "Issued-To:" and the "Issued-By" in the security certificate.
The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.
As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.
It's moronic that these big companies can't get their shit together and provide nice links like this:
which could have an explainer landing page before prompting you to visit the grotesque original link.
They seem to have improved so much in that time.
(╯°□°)╯︵ ┻━┻
Or, as another poster suggested, competent governments and corporations will use their actual domain name for official communication.
There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database.
It should just be a standard part of business registration processes.
Put in the hierarchical angle, and we're kind of back at domain names.
Over a few years I burned that approach into my parents. It was tough, but worth it.
Australia has mandatory identity verification for getting a SIM card.
The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.
KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.
[1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...
Discussion:
> BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply
If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.
Despite trying to tell people not to trust unknown callers.
You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)
My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.
If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.
You should be more respectful, you’ve clearly received a Message direct from President Trump!
I'd rather be scammed by people who can at least theoretically go to jail for their crimes.