{"id":1039,"date":"2023-03-09T13:21:53","date_gmt":"2023-03-09T21:21:53","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1039"},"modified":"2023-03-10T08:20:31","modified_gmt":"2023-03-10T16:20:31","slug":"phishing-from-03-09-23-document-shared-with-you-pugetsound-review","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1039","title":{"rendered":"Phishing from 03\/09\/23: \u201cDocument shared with you: &#8216;Pugetsound\/review'&#8221;"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><strong>From:&nbsp;<\/strong>drive-shares-dm-noreply[@]google[.]com \/\/ &nbsp;wright.jasper[@]newton[.]k12[.]ga[.]us<br><strong>Display name:<\/strong> Jasper Wright<br><strong>Subject:&nbsp;<\/strong>Document shared with you: &#8220;Pugetsound\/review&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"906\" height=\"716\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish.png\" alt=\"\" class=\"wp-image-1040\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish.png 906w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-300x237.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-768x607.png 768w\" sizes=\"auto, (max-width: 906px) 100vw, 906px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice that the individual sharing the document is&nbsp;<strong><em>outside&nbsp;<\/em><\/strong>Puget Sound. When you see the yellow\/orange banner in a Google Drive share email that says \u201c[<em>email address<\/em>] is outside your organiztion\u201d, please use extra caution.<\/li><li>Look for mismatches between the email address in the body of the email versus the display name.<\/li><li>Many phishing attempts utilize legitimate cloud collaboration services such as Google Drive, OneDrive, Dropbox, etc.<\/li><li>If you\u2019re not expecting a shared document, use extra caution before clicking on the link.<\/li><li>Be wary of document shares that you are not expecting. Online collaboration tools are a frequent method of phishing attacks.<\/li><li>Many document share phishing emails contain enticing subject lines like &#8220;Memo&#8221;, \u201cDept Evaluation\u201d, \u201cDept Assessment\u201d, or \u201cAnnual Faculty Evaluations\u201d.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Where Did the Link Lead?<\/h2>\n\n\n\n<p>Though the link does indeed go to Google Drive, the file contains a link to a Google Form that aims to harvest your credentials. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"588\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link1-1024x588.png\" alt=\"\" class=\"wp-image-1041\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link1-1024x588.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link1-300x172.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link1-768x441.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link1.png 1377w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Never enter your password in an online form or on a website you do not recognize.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"550\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2-1024x550.png\" alt=\"\" class=\"wp-image-1042\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2-1024x550.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2-300x161.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2-768x413.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2-1440x774.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/03\/3-9-23-google-doc-share-phish-link2.png 1472w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Text of Phishing Message<\/h2>\n\n\n\n<p><strong>From:&nbsp;<\/strong>drive-shares-dm-noreply[@]google[.]com<br><strong>Display name:<\/strong> Jasper Wright<br><strong>Subject:&nbsp;<\/strong>Document shared with you: &#8220;Pugetsound\/review&#8221; <\/p>\n\n\n\n<p>Jasper Wright (wright.jasper[@]newton[.]k12[.]ga[.]us) has invited you to&nbsp;<strong>view<\/strong>&nbsp;the following document:<\/p>\n\n\n\n<p>Jasper Wright shared a document <\/p>\n\n\n\n<p>Pugetsound\/review <\/p>\n\n\n\n<p>Open<\/p>\n\n\n\n<p>If you don&#8217;t want to receive files from this person, block the sender from Drive.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From:&nbsp;drive-shares-dm-noreply[@]google[.]com \/\/ &nbsp;wright.jasper[@]newton[.]k12[.]ga[.]usDisplay name: Jasper WrightSubject:&nbsp;Document shared with you: &#8220;Pugetsound\/review&#8221; Tips for Detection Notice that the individual sharing the document is&nbsp;outside&nbsp;Puget Sound. When you see the yellow\/orange banner in a Google Drive share email that says \u201c[email address] is outside your organiztion\u201d, please use extra caution. Look for mismatches between the email [&hellip;]<\/p>\n","protected":false},"author":643,"featured_media":1040,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-1039","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1039","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/643"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1039"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1039\/revisions"}],"predecessor-version":[{"id":1047,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1039\/revisions\/1047"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1040"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1039"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1039"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}