Explanation
In this case, the phishing mail leads the user to believe that there is a shared document. By clicking on the link “Ouvrir” the user is presented a fake Microsoft OneNote page, showing a link to a fake invoice (View | Download File).
After clicking on the fake link, they are redirected to a fake generic login form collecting email credentials.
Example