{"id":634,"date":"2022-02-10T11:44:41","date_gmt":"2022-02-10T19:44:41","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=634"},"modified":"2022-02-10T11:50:07","modified_gmt":"2022-02-10T19:50:07","slug":"phishing-from-2-10-2022-susan-caico-shared-activities-intramurals-sp22-with-you","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/634","title":{"rendered":"Phishing from 2\/10\/2022: &#8220;Susan Caico shared &#8216;Activities &amp; Intramurals SP22&#8217; with you.&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message, please simply delete it as it is NOT legitimate. Never enter your password on forms.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"715\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-phish.png\" alt=\"\" class=\"wp-image-635\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-phish.png 1000w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-phish-300x215.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-phish-768x549.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon &#8220;Caution&#8221; banner prepended to the message. The banner is applied on messages that match patterns of other phishing emails. Use extra caution to check the sender and investigate any links\/attachments.<\/li><li>Notice the typo in spelling the president&#8217;s name.<\/li><li>Many phishing attempts utilize legitimate cloud collaboration services such as Google Drive, SharePoint, OneDrive, Dropbox, etc. If you\u2019re not expecting a shared document and\/or do not know the sender, it is most likely NOT legitimate.<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a SharePoint document that asked you to click another link to view the file. The second link led to a Google Form asking for your credentials. <strong><em>Never<\/em><\/strong><em> <\/em>enter your username\/password information on a form. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"586\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-1024x586.png\" alt=\"\" class=\"wp-image-636\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-1024x586.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-300x172.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-768x439.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-1536x878.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1-1440x824.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepoint-link-1.png 1731w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"501\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-1024x501.png\" alt=\"\" class=\"wp-image-637\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-1024x501.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-300x147.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-768x375.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-1536x751.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2-1440x704.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-sharepiont-link-2.png 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, please simply delete it as it is NOT legitimate. Never enter your password on forms. Tips for Detection Notice the maroon &#8220;Caution&#8221; banner prepended to the message. The banner is applied on messages that match patterns of other phishing emails. Use extra caution to check the [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":635,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-634","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=634"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/634\/revisions"}],"predecessor-version":[{"id":641,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/634\/revisions\/641"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/635"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}