{"id":604,"date":"2022-02-04T13:20:13","date_gmt":"2022-02-04T21:20:13","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=604"},"modified":"2022-02-04T13:37:28","modified_gmt":"2022-02-04T21:37:28","slug":"phishing-from-2-4-2022-document-shared-with-you-annual-faculty-evaluations-docx","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/604","title":{"rendered":"Phishing from 2\/4\/2022: &#8220;Document shared with you: &#8216;Annual Faculty Evaluations.docx'&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message or a message similar to this, please simply delete it as this message is NOT legitimate.<\/em><\/strong><\/p>\n\n\n\n<p><strong>From:<\/strong> IT HelpDesk (via Google Drive) &lt;drive-shares-dm-noreply[@]google[.]com><br><strong>Subject:<\/strong> Document shared with you: &#8220;Annual Faculty Evaluations.docx&#8221; <\/p>\n\n\n\n<p>The body of the email will likely contain text like &#8220;[<em>Department Chair<\/em>] shared a file with you.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"840\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-1024x840.png\" alt=\"\" class=\"wp-image-608\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-1024x840.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-300x246.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-768x630.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-1536x1259.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-1440x1181.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish.png 1638w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice that the individual sharing the document is <strong><em>outside <\/em><\/strong>Puget Sound. When you see the yellow\/orange banner in a Google Drive share email that says &#8220;[<em>email address<\/em>] is outside your organiztion&#8221;, please use extra caution. <\/li><li>Look for mismatches between the email address in the body of the email versus the display name. <\/li><li>Many phishing attempts utilize legitimate cloud collaboration services such as Google Drive, OneDrive, Dropbox, etc.<\/li><li>If you&#8217;re not expecting a shared document, use extra caution before clicking on the link. <\/li><\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>If you would like to prevent an email address from being able to use Google Drive to share files with you, you can block them: <a href=\"https:\/\/support.google.com\/drive\/answer\/10613533\">https:\/\/support.google.com\/drive\/answer\/10613533<\/a>. <\/p><\/blockquote>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>Though the link does indeed go to Google Drive, the file contains a link to another site that aims to harvest your credentials. The hyperlinked text goes to tinyurl[.]com\/5xarpmev. Use extra caution with shortened URLs such as tinyurl.com or bit.ly as it&#8217;s difficult to tell where the link will actually lead. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Tips to reveal the full URL behind a shortened URL &#8211; For tinyurl links, type <strong>preview<\/strong> between the <strong>https:\/\/<\/strong> and <strong>tinyurl<\/strong> in the hyperlink. For bitl.y links, add a <strong>+<\/strong> at the end of the URL. There are various websites that provide link expanding services as well. <\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"426\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-link-1024x426.png\" alt=\"\" class=\"wp-image-607\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-link-1024x426.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-link-300x125.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-link-768x319.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-4-22-google-drive-phish-link.png 1431w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message or a message similar to this, please simply delete it as this message is NOT legitimate. From: IT HelpDesk (via Google Drive) &lt;drive-shares-dm-noreply[@]google[.]com>Subject: Document shared with you: &#8220;Annual Faculty Evaluations.docx&#8221; The body of the email will likely contain text like &#8220;[Department Chair] shared a file with [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=604"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/604\/revisions"}],"predecessor-version":[{"id":613,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/604\/revisions\/613"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/608"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}