{"id":570,"date":"2020-05-28T09:58:36","date_gmt":"2020-05-28T19:58:36","guid":{"rendered":"https:\/\/www.hawaii.edu\/testinfosec\/?page_id=570"},"modified":"2020-07-09T10:46:22","modified_gmt":"2020-07-09T20:46:22","slug":"spearphishing","status":"publish","type":"page","link":"https:\/\/www.hawaii.edu\/infosec\/spearphishing\/","title":{"rendered":"Spearphishing"},"content":{"rendered":"

What is a Spearphish?<\/h2>\n

A malicious email that targets an individual which appears to be from a trusted sender. The spearphish will contain a link or attachment that appears to be safe to open. If the link is clicked or the attachment opened, malicious software can be silently installed on the computer. This gives the cybercriminals remote access to the computer who can then steal all the individual’s personal information, business files, and passwords stored on the hard drive and network shared folders as well as search for and compromise other computers in the organization in order to steal more data.<\/p>\n

Examples of Suspicious Attachments<\/h2>\n

Note: The following are tested on Windows 10 and Office 2013 (other versions may display different messages or none at all).<\/p>\n

Click on the images to enlarge them.<\/p>\n

\n
\n
\n \"Word<\/a>\n <\/div>\n
\n \"Excel<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

1. Word Macro \u2014 Word file (.doc, .docm) contains a script. Warning appears in yellow bar at the top.<\/p>\n<\/p><\/div>\n

\n

2. Excel Macro \u2014 Excel file (.xls, .xlsm) contains a script. Warning appears in yellow bar at the top.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Word<\/a>\n <\/div>\n
\n \"Word<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

3. Word VBS 1 \u2014 Word file (.doc) contains a script. Warning appears if script is double-clicked.<\/p>\n<\/p><\/div>\n

\n

4. Word VBS 2 \u2014 Word file (.docx) contains a script. Warning appears if script is double-clicked.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"PDF<\/a>\n <\/div>\n
\n \"Word<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

5. Acrobat Script \u2014 PDF file (.pdf) contains a script. Warning appears.<\/p>\n<\/p><\/div>\n

\n

6. CVE-2017-0199 \u2014 Word file (.doc) contains an exploit. Warning appears.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Office<\/a>\n <\/div>\n
\n \"Office<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n \"Office<\/a>\n <\/div>\n
\n \"Word<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

7. CVE-2012-0158 a-d \u2014 Word file (.doc) contains an exploit. Additional Office components is installed then document is converted but no warning appears.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Word<\/a>\n <\/div>\n
\n \"PowerPoint<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

8. CVE-2017-8759 \u2014 Word file (.doc) contains an exploit. Warning appears.<\/p>\n<\/p><\/div>\n

\n

9. PowerPoint \u2014 PowerPoint file (.ppsx) contains a script that activates when user mouseovers the link. Warning appears.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Word<\/a>\n <\/div>\n
\n \"Word<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

10. Word DDE \u2014 Word file (.docx) contains a link. Warning appears.<\/p>\n<\/p><\/div>\n

\n

11. Word Callback \u2014 Word file (.doc) contains link. No warning in Word 2010.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"PDF<\/a>\n <\/div>\n
\n \"Word<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

12. Acrobat Word \u2014 PDF file (.pdf) contains Word doc. Warning appears.<\/p>\n<\/p><\/div>\n

\n

13. CVE-2017-11882 \u2014 Word file (.doc) contains an exploit. No warning.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Excel<\/a>\n <\/div>\n
\n \"OneNote<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

14. Excel Package \u2014 Excel file (.xlsx) contains a script. Warning appears.<\/p>\n<\/p><\/div>\n

\n

15. OneNote \u2014 OneNote file (.one) contains Word doc. No warning.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Excel<\/a>\n <\/div>\n
\n \"Excel<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

16. CSV a-b \u2014 CSV file (.csv) opened in Excel which contains a link. Warning appears.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n

\n
\n \"Email<\/a>\n <\/div>\n<\/p><\/div>\n
\n
\n

17. Email Resume \u2014 Email contains webbug. Missing graphic icon appears if image download is blocked.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n


<\/p>\n

What should I do if I receive a spearphish?<\/h3>\n

Ask the sender to confirm he\/she sent it (preferably via telephone call), scan the attachment with anti-virus, and report it to your department’s IT staff.<\/p>\n

The following emails would be considered suspicious:<\/p>\n