请问HN:来自646-257-4500的网络钓鱼攻击

3作者: latchkey7 天前原帖
昨天,我接到了646-257-4500的电话。<p>电话那头是一个美国西部男性的声音,非常礼貌。他们实际上给我打了三次电话,前两次我都挂了。<p>他们声称收到了来自谷歌支持门户的请求,要求更改我账户上的电话号码,并希望我验证我的账户。<p>他们给我发了一封电子邮件,看起来非常像是来自谷歌的……甚至在邮件头信息中也如此!我没有发现其中有什么明显的问题。<p>主题:回复:您现在正在与一位经过验证的谷歌代理通话,您的案件编号是:XXXXX。请让您的代理在电话中确认这一点。<p><pre><code> ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20251104 header.b=XXXX; spf=pass (google.com: XXXX.XXXX.XXX@cases-outbound-prod.bounces.google.com 的域名指定 209.85.220.75 为允许的发件人) smtp.mailfrom=XXX.XXX.XXX@cases-outbound-prod.bounces.google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com; dara=pass header.i=@gmail.com Received: from mail-sor-f75.google.com (mail-sor-f75.google.com. [209.85.220.75]) by mx.google.com with SMTPS id XXXX-XXXX.10.2026.06.11.14.42.06 for &lt;XXXX@gmail.com&gt; (Google Transport Security); Thu, 11 Jun 2026 14:42:06 -0700 (PDT) </code></pre> 当他们意识到我不会给他们读那个代码时,他们立刻挂了电话。<p>对这个号码的搜索确认我并不是唯一的受害者。<p>我想问的是,他们怎么能发出那封电子邮件!?<p>为什么谷歌没有通过他们的系统过滤掉这些邮件呢?
查看原文
Yesterday, I got a call from 646-257-4500.<p>American western male voice. Very polite. They actually called me 3 times. The first two, I just hung up.<p>They were claiming they received a request from the google support portal for a change of phone number on my account and wanted me to verify my account.<p>They sent me an email which looks very much like it came from Google… even in the headers! I don&#x27;t see anything intrinsically wrong in it.<p>Subject: Re: You are now on the phone with a verified Google Agent, your Case ID is: XXXXX. Please ask your Agent to confirm this over the phone.<p><pre><code> ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20251104 header.b=XXXX; spf=pass (google.com: domain of XXXX.XXXX.XXX@cases-outbound-prod.bounces.google.com designates 209.85.220.75 as permitted sender) smtp.mailfrom=XXX.XXX.XXX@cases-outbound-prod.bounces.google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com; dara=pass header.i=@gmail.com Received: from mail-sor-f75.google.com (mail-sor-f75.google.com. [209.85.220.75]) by mx.google.com with SMTPS id XXXX-XXXX.10.2026.06.11.14.42.06 for &lt;XXXX@gmail.com&gt; (Google Transport Security); Thu, 11 Jun 2026 14:42:06 -0700 (PDT) </code></pre> They hung up immediately when they realized that I wasn’t going to read them that code.<p>Searches for the number confirm I&#x27;m not the only one.<p>I guess my question is how they could send that email!?<p>Why isn&#x27;t google filtering this out through their system?