{"id":966,"date":"2023-01-26T13:37:18","date_gmt":"2023-01-26T21:37:18","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=966"},"modified":"2023-01-26T17:04:16","modified_gmt":"2023-01-27T01:04:16","slug":"phishing-from-01-26-23-document-shared-with-you-2023-faculty-evaluation-pdf-docx","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/966","title":{"rendered":"PHISHING FROM 01\/26\/23: \u201cDocument shared with you: &#8220;2023 FACULTY EVALUATION.pdf.docx&#8221;\u201d"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><strong>From:\u00a0<\/strong>drive-shares-dm-noreply[@]google[.]com<br><strong>Display name:<\/strong> Emma Zaragoza<br><strong>Subject:\u00a0<\/strong>Document shared with you: &#8220;2023 FACULTY EVALUATION.pdf.docx&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"695\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-1024x695.png\" alt=\"\" class=\"wp-image-967\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-1024x695.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-300x203.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-768x521.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish.png 1094w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice that the individual sharing the document is\u00a0<strong><em>outside\u00a0<\/em><\/strong>Puget Sound. When you see the yellow\/orange banner in a Google Drive share email that says \u201c[<em>email address<\/em>] is outside your organiztion\u201d, please use extra caution.<\/li><li>Look for mismatches between the email address in the body of the email versus the display name.<\/li><li>Many phishing attempts utilize legitimate cloud collaboration services such as Google Drive, OneDrive, Dropbox, etc.<\/li><li>If you\u2019re not expecting a shared document, use extra caution before clicking on the link.<\/li><li>Be wary of document shares that you are not expecting. Online collaboration tools are a frequent method of phishing attacks.<\/li><li>Many document share phishing emails contain enticing subject lines like &#8220;Memo&#8221;, \u201cDept Evaluation\u201d, \u201cDept Assessment\u201d, or \u201cAnnual Faculty Evaluations\u201d.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Where Did the Link Lead?<\/h2>\n\n\n\n<p>Though the link does indeed go to Google Drive, the file contains a link to another site that aims to harvest your credentials. Use extra caution with shortened URLs such as tinyurl.com or bit.ly as it\u2019s difficult to tell where the link will actually lead.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Tips to reveal the full URL behind a shortened URL \u2013 For tinyurl links, type\u00a0<strong>preview<\/strong>\u00a0between the\u00a0<strong>https:\/\/<\/strong>\u00a0and\u00a0<strong>tinyurl<\/strong>\u00a0in the hyperlink. For bitl.y links, add a\u00a0<strong>+<\/strong>\u00a0at the end of the URL. There are various websites that provide link expanding services as well.<\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-1024x573.png\" alt=\"\" class=\"wp-image-968\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-1024x573.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-300x168.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-768x430.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-1536x860.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link-1440x806.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/01\/1-26-23-doc-share-phish-link.png 1560w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Text of Phishing Message<\/h2>\n\n\n\n<p> <strong>From:\u00a0<\/strong>drive-shares-dm-noreply[@]google[.]com<br><strong>Display name:<\/strong> Emma Zaragoza<br><strong>Subject:\u00a0<\/strong>Document shared with you: &#8220;2023 FACULTY EVALUATION.pdf.docx&#8221; <\/p>\n\n\n\n<p>Emma Zaragoza shared a document <\/p>\n\n\n\n<p>Emma Zaragoza (emma.zaragoza[@]sheboyganchristian[.]com) has invited you to view the following document:<\/p>\n\n\n\n<p>FWD: Amy Hackett has invited you to view the following file that need urgent attention.<\/p>\n\n\n\n<p>2023 FACULTY EVALUATION.pdf.docx<\/p>\n\n\n\n<p>If you don&#8217;t want to receive files from this person, block the sender from Drive.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From:\u00a0drive-shares-dm-noreply[@]google[.]comDisplay name: Emma ZaragozaSubject:\u00a0Document shared with you: &#8220;2023 FACULTY EVALUATION.pdf.docx&#8221; Tips for Detection Notice that the individual sharing the document is\u00a0outside\u00a0Puget Sound. When you see the yellow\/orange banner in a Google Drive share email that says \u201c[email address] is outside your organiztion\u201d, please use extra caution. Look for mismatches between the email [&hellip;]<\/p>\n","protected":false},"author":643,"featured_media":967,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-966","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/966","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/643"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=966"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/966\/revisions"}],"predecessor-version":[{"id":1036,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/966\/revisions\/1036"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/967"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}