About two months ago, we posted about a phishing scam that used Google Docs and Google Drive. This same scam is out again, but this time it's more effective than the millions of phishing emails we see every day because the Google Drive phishing page is served over SSL by the legitimate Google Drive service itself.
Those who examine whether a page is phishing focus more on the visual inspection of the URL to ensure the connection is secure. It is a good approach, but it will not help prevent this specific attack.
As in the past, the intruder's phishing message uses a simple Google Docs theme and contains a URL that points to a phishing page hosted on the Google Drive file storage service:
Figure 1 . Google Drive phishing page
However, this time the phishers have made a small mistake. In the lower corner of the page, there is a language selection window. For someone who is cautious, this could be a red flag that something is wrong. It appears that the phishers accidentally broke the page, as some language names are displayed with a question mark on each side:
Figure 2 . Corrupted language options
This corruption is probably because Google lists the languages written as they are in the countries where they are spoken: for example, Korean is listed in the native language of Korea with the Hangul alphabet: 한국어. When phishers saved a copy of Google's page, they most likely did not use UTF-8 character encoding but ISO-8859-1 (Latin-1), which causes this font error.
Many victims cannot notice this error on the page because it is in a corner and is not visible. Even if the victim notices the wrong fonts, they may think it is a small bug or a problem with their own computer.
The stolen credentials are sent to a PHP script located on a compromised server:
According to Symantec this script has the same name (performact.php) that we saw in the scam we published two months ago, indicating that the attackers' group is the same (or at least they use the same phishing package). The script redirects the victim to a document hosted on Google Drive and is designed to send the credentials to the attackers.
Source: secnews.gr


