Abstract Aliens On Flying Saucers Northern Lights Lighthouse Mountains Water Tree Sun Background Gradient Unidentified Flying Object Ufo Stars Vector Design Style Landscape
Phish Files

[Name] shared staff performance and evaluation forms

Posted in: Fraud

screenshot of a phishing attack considered fraud. Email states it is coming from someone at the university sending a file to staff.

Screenshot of the webpage that is produced by the shared performance files. Page shows files prepared to download.

Why this looks valid:

  • Email states that it is coming from a faculty/staff member that would have access to these type of files.
  • Email links to a legitimate MSU email address within the body of the email.
  • Link within email body links to a forms page supported by Microsoft 365.

Why this is phishing?

  • Email is not coming from an official MSU email
  • Link on form page is coming from another countries domain (i.e. .ru, .de, .jp, etc.)
  • Once the link within the form page is accessed the user is prompted to authenticate via Google in order to gain access to the PDF containing a malicious payload.

Additional Notes: