This is the contents from a phishing attemt I had recieved recently.
- Recieve an attachment.html usually from a free email service.
- The email contains html file with encoded JS that would call http://angelotti.it/cms/moj1.js
- Once you open the html file an outlook login portal will be visualized to authenticate.
IoCs: