Page 1 of 1

Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 1:05 pm
by xeo
There seems to be a lot of this being spammed around recently to email accounts. Don't trust it. Ever.

2n1aJnj.png

Re: Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 1:28 pm
by Riyame
Thanks for the heads up. Thankfully I don't use OneDrive :D

Re: Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 1:37 pm
by xeo
Riyame wrote:Thanks for the heads up. Thankfully I don't use OneDrive :D


You don't have to. I don't have OneDrive. They're using OneDrive to host malware.

Re: Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 3:54 pm
by Riyame
xeo wrote:
Riyame wrote:Thanks for the heads up. Thankfully I don't use OneDrive :D


You don't have to. I don't have OneDrive. They're using OneDrive to host malware.


What I meant was I would know it is a scam since I don't use it and I don't know anyone that does. Same thing with linkedin, whats app, and a bunch of other crap. Although those free red lobster and burger king certificates sure are tempting :lol:

Re: Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 4:09 pm
by aeporia
Basic infosec rule: don’t trust email attachments, of the old school or new n’ swanky cloud-file hosted variety.

I personally wouldn’t touch any MS Office files sent via email, full stop — it’s one of the largest attach vectors in popping winboxes (I realise this is hard advice to follow for many folks).

Re: Beware: OneDrive Trojan/Phishing

PostPosted: Thu Dec 03, 2015 10:16 pm
by Josephus
aeporia wrote:Basic infosec rule: don’t trust email attachments, of the old school or new n’ swanky cloud-file hosted variety.

I personally wouldn’t touch any MS Office files sent via email, full stop — it’s one of the largest attach vectors in popping winboxes (I realise this is hard advice to follow for many folks).


Not an attachment: a link. Generally the link goes to a spoofed login page to steal credentials. Attachments are easily scanned and sanitized anymore so things get clever.