Phishing Email

circle-exclamation
circle-info

We will be using the REMnuxarrow-up-right distribution which is specifically made for reverse engineering.

What is the return path of the email?

Let's first open the email using the Thunderbirdarrow-up-right client.

If we go to More > View Source, we can see the HTML source of the email.

There is also a Return-Path field which contains the answer.

Answer

What is the domain name of the url in this mail?

We can left click on the button and Copy Link Location to a notepad.

Since the question is asking for the domain name, we do not need the entire URL.

Answer

Is the domain mentioned in the previous question suspicious?

Using VirusTotalarrow-up-right we can check whether a URL is malicious or not.

It has been flagged as Phishing by Abusix.

Answer

What is the body SHA-256 of the domain?

Answer

Is this email a phishing email?

As we saw in the Virustotal analysis, the email is a phishing email.

Answer

Last updated