{"id":47,"date":"2020-09-16T19:05:52","date_gmt":"2020-09-16T19:05:52","guid":{"rendered":"http:\/\/blogs.pugetsound.edu\/infosec\/?p=47"},"modified":"2020-09-23T12:49:31","modified_gmt":"2020-09-23T19:49:31","slug":"phishing-example-from-5-19-20-mail-serv-shared-a-file-with-you","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/47","title":{"rendered":"Phishing Example from 5\/19\/20: &#8220;Mail Serv. shared a file with you&#8221;"},"content":{"rendered":"<blockquote><p>Security Tip: If you are not expecting a shared document from Google Drive or Dropbox or Office 365 from outside the organization, <strong>use caution<\/strong>. If you are sharing a document using cloud services, also notify the recipient by another means of communication.<\/p><\/blockquote>\n<h3>Tips for Detection:<\/h3>\n<ul>\n<li>Sending address is @hotmail.com<\/li>\n<li>Many phishing emails attempt to impersonate the provost or academic department chairs<\/li>\n<li>The link does in fact lead to a legitimate document stored on Office 365, but the document asks the user to click another link to a malicious site (not shown)<\/li>\n<\/ul>\n<h3>Original Phishing Message:<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-19\" src=\"http:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish.png\" alt=\"\" width=\"1850\" height=\"1380\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish.png 1850w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish-300x224.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish-768x573.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish-1024x764.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2020\/09\/5-19-20-eval-phish-1440x1074.png 1440w\" sizes=\"auto, (max-width: 1850px) 100vw, 1850px\" \/><\/p>\n<h3>Text of Phishing Message:<\/h3>\n<p>Mail Serv. shared a file with you<\/p>\n<p>Kindly check the new school transcript. Laura L. Behling Provost University of Puget Sound<\/p>\n<p>Open [link removed]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Tip: If you are not expecting a shared document from Google Drive or Dropbox or Office 365 from outside the organization, use caution. If you are sharing a document using cloud services, also notify the recipient by another means of communication. Tips for Detection: Sending address is @hotmail.com Many phishing emails attempt to impersonate [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":19,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-47","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/47","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=47"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/47\/revisions"}],"predecessor-version":[{"id":48,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/47\/revisions\/48"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/19"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=47"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=47"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=47"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}