Home BTLO - Phishing Analysis
Post
Cancel

BTLO - Phishing Analysis

BlueTeamsOnline - Phishing Analysis

img-description

Hello there! Today we are going to perform some analysis on a phishing email. This is a challenge on Blue Teams Lab Online.
In this challenge, I will be using the following tools

  1. Phishtool
  2. Outlook
  3. URL2PNG

The level of difficulty is easy.

Who is the primary recipient of this email? (1 points) img-description

What is the subject of this email? (1 points) img-description What is the date and time the email was sent? (1 points)

What is the Originating IP? (1 points) img-description

img-description

Perform reverse DNS on this IP address, what is the resolved host? (whois.domaintools.com) (1 points) img-description

What is the name of the attached file? (2 points) img-description

What is the URL found inside the attachment? (1 points) img-description What service is this webpage hosted on? (1 points)
Ans: blogspot

Using URL2PNG, what is the heading text on this page? (Doesn’t matter if the page has been taken down!) (1 points) img-description

Hooray!! That’s it img-description

Summary

That was just but one example of how to perform phishing email analysis. Watch out for another example yet

This post is licensed under CC BY 4.0 by the author.