{"id":12164,"date":"2021-03-02T15:12:30","date_gmt":"2021-03-02T20:12:30","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12164"},"modified":"2021-03-11T13:53:08","modified_gmt":"2021-03-11T18:53:08","slug":"coronavirus-scams-phishing-websites-emails-target-unsuspecting-users","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/coronavirus-scams-phishing-websites-emails-target-unsuspecting-users\/","title":{"rendered":"Coronavirus Scams: Phishing Websites &#038; Emails Target Unsuspecting Users"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-as-covid-19-fears-grow-hundreds-of-coronavirus-themed-domains-are-being-used-to-spread-malware-and-steal-information\">As COVID-19 fears grow, hundreds of Coronavirus-themed domains are being used to spread malware and steal information<\/h2>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-info has-icon\" data-type=\"info\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewbox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"10\"><\/circle><line x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"><\/line><line x1=\"12\" y1=\"8\" x2=\"12\" y2=\"8\"><\/line><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Information<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\"><strong><em>Note: This article, which was originally published in 2020, has been updated to include related news &amp; media resources<\/em><\/strong>.<\/p><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Amongst growing fears of this global pandemic, Coronavirus scams and malicious websites are on the rise. The latest news from the <a href=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/hc3_coronavirus_alert.pdf\">Health Sector Cybersecurity Coordination Center (HC3)<\/a>, a new malicious website is circulating on the internet that targets unsuspecting users. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">True to their selfish nature, cybercriminals are taking\nadvantage of public panic about the global Coronavirus pandemic for their own\nselfish goals. Now, of course, this concept is nothing new. Cybercriminals are\nalways looking for the next best thing to take advantage of. But that doesn\u2019t\nmean that it isn\u2019t a serious issue that you can simply ignore.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, what is this new phishing website and why should you be\nconcerned about it? And what are some of the other Coronavirus scam tactics\nthat cybercriminals are using to take advantage of the global pandemic?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cybercriminals-create-coronavirus-tracker-map-to-spread-info-stealing-malware\">Cybercriminals Create Coronavirus Tracker Map to Spread Info-Stealing\nMalware<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When something\u2019s wrong, people frequently turn to the\ninternet to get the latest information. Cybercriminals know this and are\ncreating fraudulent websites that impersonate real, reputable authorities. Their\nlatest tactic? Live tracker websites. <\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<p class=\"wp-block-paragraph\">In truly low-life fashion, some schmuck decided to create a phishing website, corona-virus-map[dot]com (and, no, please don\u2019t type that into your browser), that appears to be a legitimate COVID-19 live tracking map for the virus. In this case, HC3 reports that the cybercriminals were impersonating John\u2019s Hopkins University, a world-renowned health institution, to infect website visitors with the <a href=\"https:\/\/attack.mitre.org\/software\/S0344\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">AZORult trojan<\/a>. This program exfiltrates a wealth of sensitive data that can be sold on the dark web or used to commit cybercrimes, including cryptocurrency theft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a screenshot from the official HC3 notification about\nthe phishing scam site: <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"835\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-phishing-site-1024x835.png\" alt=\"Graphic: Screenshot of a Coronavirus phishing site\" class=\"wp-image-12166 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-phishing-site-1024x835.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-phishing-site-300x245.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-phishing-site-768x627.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-phishing-site.png 1053w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In general, Coronavirus themed cyber attacks and phishing websites are becoming a lot more common as news about the virus continuously blasts from virtually every media outlet. Check Point, a cybersecurity firm, <a href=\"https:\/\/blog.checkpoint.com\/2020\/03\/05\/update-coronavirus-themed-domains-50-more-likely-to-be-malicious-than-other-domains\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">recently reported on their blog<\/a> that CNN alone hosts more than 1,200 articles. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the same blog post:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cSince January 2020, based on Check Point Threat Intelligence, there have been over 4,000 coronavirus-related domains registered globally. Out of these websites, 3% were found to be malicious and an additional 5% are suspicious. Coronavirus- related domains are 50% more likely to be malicious than other domains registered at the same period, and also higher than recent seasonal themes such as&nbsp;Valentine\u2019s day.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to users finding the website organically through\nweb searches, the website was circulated via a variety of other tactics,\nincluding: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>malicious links and attachments in emails<\/li><li>social engineering, and <\/li><li>online advertising. <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This newly discovered threat follows on the heels of other\ncyber scams, including other Coronavirus-themed malware and phishing emails. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-coronavirus-themed-phishing-emails-are-on-the-rise\">Coronavirus-Themed Phishing Emails Are on the Rise<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Another way that cybercriminals are taking advantage of a bad situation is by launching Coronavirus-themed <a href=\"https:\/\/www.vox.com\/recode\/2020\/3\/5\/21164745\/coronavirus-phishing-email-scams\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">email phishing campaigns<\/a>. In a February notification, the HC3 reported that carefully crafted phishing emails are sent to entice users to open attachments or to click on links that contain malware that\u2019s frequently used to target healthcare organizations and their IT systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the HC3:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cVictims who interact with malicious links or attachments may expose their systems, networks, and valuable information. These exposures allow an attacker to use infected systems as a platform to launch additional attacks.\u201d<\/em> <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">In these campaigns, cybercriminals impersonate a variety of organizations, including the U.S. Centers for Disease Control and Prevention (CDC), the World Health Organization (WHO), and a <a href=\"https:\/\/blog.checkpoint.com\/2020\/02\/13\/january-2020s-most-wanted-malware-coronavirus-themed-spam-spreads-malicious-emotet-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Japanese disability welfare service provider<\/a>. But Coronavirus scams don\u2019t stop where the digital world ends \u2014 criminals are <a href=\"https:\/\/www.cnn.com\/2020\/03\/10\/us\/nj-coronavirus-cdc-scam-trnd\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">impersonating federal authorities in face-to-face scams<\/a> as well. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Check Point, one particularly widespread phishing campaign targeted <strong>more than 10% of all organizations in Italy<\/strong>! The email contained an Ostap Trojan-Downloader disguised as a Microsoft Word document. This downloader is commonly used as to install <a href=\"https:\/\/www.cisecurity.org\/white-papers\/security-primer-trickbot\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">TrickBot<\/a>, a banking trojan that\u2019s steals sensitive information via man-in-the-middle (MitM) attacks, or spreads other types of malware across networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a screenshot from Check Point\u2019s blog post:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"163\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-scam-email-example-1024x163.png\" alt=\"\" class=\"wp-image-12167 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-scam-email-example-1024x163.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-scam-email-example-300x48.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-scam-email-example-768x123.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-scam-email-example.png 1134w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The email translates to read the following in English: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cDue to the number of cases of coronavirus infection that have been documented in your area, the World Health Organization has prepared a document that includes all the necessary precautions against coronavirus infection.<\/em>  <em>We strongly recommend that you read the document attached to this message.<\/em> <\/p><p><em>We strongly recommend that you read the document attached to this message.<\/em> <\/p><p> <em>With best regards,<\/em> <\/p><p> <em>Dr. Penelope Marchetti (World Health Organization \u2013 Italy)\u201d<\/em> <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Although the email didn\u2019t come from an official WHO email\naddress or domain, people who are ignorant of cybersecurity threats \u2014 or who\nare caught in a moment of unawareness \u2014 could find themselves the victims of a\ndata breach. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-background-on-the-coronavirus-and-why-it-makes-an-effective-scam-method\">Background on the Coronavirus and Why It Makes an Effective Scam Method<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, we\u2019re not global health experts, but here is some basic information about <a href=\"https:\/\/www.theguardian.com\/world\/2020\/mar\/12\/what-is-a-pandemic-coronavirus-covid-19\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">COVID-19<\/a>:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Coronavirus Disease 2019 (also known as COVID-19) is something that\u2019s captured the world\u2019s attention \u2014 and for good reason. <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.worldometers.info\/coronavirus\/\" target=\"_blank\" rel=\"noreferrer noopener\">Wordometers.info<\/a> reports that the virus has infected individuals in 125 countries and territories globally in additional to cruise ships. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.washingtonpost.com\/world\/2020\/01\/22\/mapping-spread-new-coronavirus\/?arc404=true\" target=\"_blank\" rel=\"noreferrer noopener\">Washington Post reports<\/a> that there have been more than 100,000 cases of the disease reported since late 2019 when the outbreak started, and \u201cseveral thousand people have died\u201d (although the true number of Coronavirus cases is thought to be <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.latimes.com\/science\/story\/2020-03-10\/us-coronavirus-cases-far-above-official-tally-scientists\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cfall above official tally.\u201d<\/a>) <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the Washington Post reports:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cCoronaviruses range from the common cold virus to more serious diseases that can infect humans and animals, including severe acute respiratory syndrome (SARS) and Middle East respiratory syndrome (MERS).\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But here\u2019s the takeaway we want you to focus on: Even in the grimmest of circumstances, when governments worldwide are trying to slow the spread of the virus among their populations, cybercriminals aren\u2019t taking a break. In fact, they\u2019re ramping up their efforts, using the global health crisis as an opportunity to steal information from unsuspecting individuals who are trying to stay informed. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To you, hackers, we have one thing to say: You suck.\nSeriously. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To businesses and organizations, both in the U.S. and\nabroad, we say the following: Stay informed and keep your employees informed as\nwell. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-protect-your-organization-from-fake-coronavirus-phishing-sites\">How to Protect Your Organization from Fake Coronavirus Phishing Sites<\/h2>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Avoid these nasty coronavirus scams\" width=\"960\" height=\"540\" src=\"https:\/\/www.youtube.com\/embed\/XVrlCTxlWQE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For businesses and IT administrators, you know this means\nthat there\u2019s a chance you or some of your organization\u2019s users may find\nthemselves on one of these sites.&nbsp;&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What you can do to help prevent users from falling for these\nphishing scams is:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-keep-employees-informed\">Keep Employees Informed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Send out information via official channels to keep your\nemployees abreast of the latest Coronavirus news so they don\u2019t go looking for\nit themselves. Also keep them informed of any Coronavirus-themed threads such\nas new websites and email scams to look out for. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-share-official-resources\">Share Official Resources <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Provide employees with links to valid, official Coronavirus\ntracking sites and resources. Here\u2019s a list of trustworthy and reputable\nresources to help you get started:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.cdc.gov\/coronavirus\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">CDC information about the Coronavirus<\/a><\/li><li><a href=\"https:\/\/www.nytimes.com\/interactive\/2020\/world\/coronavirus-maps.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">The New York Times\u2019 Coronavirus Map<\/a><\/li><li><a href=\"https:\/\/www.cdc.gov\/coronavirus\/2019-ncov\/community\/home\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Coronavirus resources for households<\/a><\/li><li><a href=\"https:\/\/www.phe.gov\/Preparedness\/planning\/405d\/Pages\/hic-practices.aspx\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Health industry cybersecurity best practices<\/a><\/li><li><a href=\"https:\/\/staysafeonline.org\/press-release\/ncsa-encourages-coronavirus-vigilance\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Cybersecurity best practices for remote workers<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-update-your-cyber-awareness-training\">Update Your Cyber Awareness Training <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Educate users about the dangers of phishing emails and\nwebsites via cybersecurity awareness training. Teach them how to recognize\nsuspicious emails and websites, and use best practices to avoid becoming\nvictims. &nbsp;<\/p>\n\n\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-verify-don-t-blindly-trust\">Verify, Don\u2019t (Blindly) Trust<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Institute policies and processes that stipulate that before\nany sensitive information can be shared, wire transfers can be made, or any\nother actions can be taken, employees must first verify the request directly with\nthe source. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, for example, if you receive an urgent email from CFO\nJohn Smith saying that he\u2019s in a meeting (or otherwise unavailable) and that\nyou need to perform a wire transfer immediately for a vendor, make it so that\nyour employees must: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>carefully check the email header information\n(the \u201cfrom\u201d field), such as the email address and domain name, to verify that\nit matches the contact information for that individual. <\/li><li>never respond to the email sender directly.<\/li><li>get phone verification by calling via an\nofficial phone number (such as from your internal directory).<\/li><li>implement a code word or phrase that can be used\nto authenticate a user.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-recent-related-news\">Recent Related News<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Updated on March 2, 2021<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.axios.com\/scammers-seize-on-covid-confusion-b40cca88-c288-4d94-9f5a-1df19ac01812.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Scammers seize on COVID confusion<\/a><\/li><li><a href=\"https:\/\/www.wsj.com\/articles\/covid-19-vaccine-scams-grow-leveraging-confusion-about-how-to-get-the-shot-11614076200\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Covid-19 Vaccine Scams Grow, Leveraging Confusion About How to Get the Shot<\/a><\/li><li><a href=\"https:\/\/www.aarp.org\/money\/scams-fraud\/info-2021\/covid-19-vaccination-card-data-risk.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Don&#8217;t Flaunt Your COVID-19 Vaccine Card on Facebook<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>As COVID-19 fears grow, hundreds of Coronavirus-themed domains are being used to spread malware and steal information Amongst growing fears of this global pandemic, Coronavirus scams and malicious websites are&#8230;<\/p>\n","protected":false},"author":17,"featured_media":12165,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200,13114],"tags":[11036,7970,10373,166],"class_list":["post-12164","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","category-updated","tag-cyber-threats","tag-email-security","tag-https-phishing","tag-phishing","post-with-tags"],"views":23630,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/coronavirus-screenshot.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12164"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12164\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12165"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}