{"id":900,"date":"2022-10-18T08:22:05","date_gmt":"2022-10-18T15:22:05","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=900"},"modified":"2022-10-18T08:22:31","modified_gmt":"2022-10-18T15:22:31","slug":"phishing-from-10-18-2022-daniel-gamel-shared-the-folder-new-proposal-from-daniel-gamel-with-you","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/900","title":{"rendered":"Phishing from 10\/18\/2022: &#8220;Daniel Gamel shared the folder &#8216;New Proposal from Daniel Gamel&#8217; with you.&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"498\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-1024x498.png\" alt=\"\" class=\"wp-image-902\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-1024x498.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-300x146.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-768x373.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish.png 1202w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link initially led to a shared document on OneDrive. The OneDrive document contained a link to a phishing site designed to steal your credentials. Notice the URL smoggy-prairie-option[.]glitch[.]me. That is not an Adobe or Microsoft site. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"591\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1-1024x591.png\" alt=\"\" class=\"wp-image-903\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1-1024x591.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1-300x173.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1-768x443.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1-1440x831.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link1-1.png 1496w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"587\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-1024x587.png\" alt=\"\" class=\"wp-image-904\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-1024x587.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-300x172.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-768x441.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-1536x881.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2-1440x826.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/10\/10-18-22-onedrive-phish-link2.png 1726w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: danielmgamel[@]hotmail[.]com<br><strong>Subject<\/strong>: Daniel Gamel shared the folder &#8220;New Proposal from Daniel Gamel&#8221; with you.<\/p>\n\n\n\n<p>Daniel Gamel shared a folder with you<br>Daniel Gamel shared the folder &#8220;New Proposal from Daniel Gamel&#8221; with you.<\/p>\n\n\n\n<p>New Proposal from Daniel Gamel<\/p>\n\n\n\n<p>Open<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Where Did the Link Lead? The link initially led to a shared document on OneDrive. The OneDrive document contained a link to a phishing site designed to steal your credentials. Notice the URL smoggy-prairie-option[.]glitch[.]me. That is not an Adobe or Microsoft site. Text of Phishing Message From: danielmgamel[@]hotmail[.]comSubject: Daniel Gamel shared the [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":904,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=900"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/900\/revisions"}],"predecessor-version":[{"id":905,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/900\/revisions\/905"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/904"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}