โ† All cheat sheets

PhishingAnalysis

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

STEP 1: INITIAL TRIAGE (DO NOT CLICK ANYTHING)#

# Before any analysis - NEVER click links or open attachments directly

[ ] Do not click any links in the email
[ ] Do not open attachments
[ ] Do not reply to the sender
[ ] Do not forward to others (yet)
[ ] Take screenshots for documentation
[ ] Note the time/date received
[ ] Check if others received the same email

# Export email as .eml file for analysis
# In Outlook: File > Save As > .eml
# In Gmail: Three dots > Download message
# In Thunderbird: File > Save As > File

STEP 2: ANALYZE EMAIL HEADERS#

# View full headers:
# Outlook: Open email > File > Properties > Internet Headers
# Gmail: Three dots > Show original
# Thunderbird: View > Headers > All

# Key headers to examine:

1. AUTHENTICATION RESULTS#

# Check SPF (Sender Policy Framework)
Authentication-Results: spf=pass/fail

# Check DKIM (DomainKeys Identified Mail)
Authentication-Results: dkim=pass/fail

# Check DMARC (Domain-based Message Authentication)
Authentication-Results: dmarc=pass/fail

# RED FLAGS:
- spf=fail or spf=softfail
- dkim=fail or dkim=none
- dmarc=fail

2. RECEIVED HEADERS (READ BOTTOM TO TOP)#

# Trace the email path - bottom is origin, top is destination
Received: from [server] by [server] with [protocol]

# Look for:
- Suspicious originating IP addresses
- Mismatched server names
- Unusual geographic locations
- Time gaps that don't make sense

3. FROM vs RETURN-PATH vs REPLY-TO#

From: display-name <actual@email.com>
Return-Path: <bounce@different-domain.com>
Reply-To: <reply@another-domain.com>

# RED FLAGS:
- From domain doesn't match Return-Path
- Reply-To goes to different domain
- Display name mimics legitimate company but email is different

4. MESSAGE-ID#

Message-ID: <unique-id@domain.com>

# Should match sender's domain
# Random/suspicious domains are red flags

5. X-ORIGINATING-IP#

X-Originating-IP: [192.168.1.1]

# Research this IP for reputation

# HEADER ANALYSIS TOOLS#

# Online analyzers:
https://mxtoolbox.com/EmailHeaders.aspx
https://toolbox.googleapps.com/apps/messageheader/
https://www.mailheader.org/

# Command line:
# Extract headers from .eml file
cat email.eml | grep -E "^(From|To|Subject|Date|Received|Return-Path|Reply-To|Message-ID|X-Originating|Authentication)"

# Parse with Python
python3 -c "
import email
with open('email.eml', 'r') as f:
    msg = email.message_from_file(f)
    for header in ['From', 'To', 'Subject', 'Return-Path', 'Reply-To', 'Received', 'Authentication-Results']:
        print(f'{header}: {msg.get_all(header)}')
"

STEP 3: ANALYZE SENDER DOMAIN#

# 1. WHOIS lookup
whois suspicious-domain.com
# Online: https://whois.domaintools.com/

# Look for:
- Recently registered domain (< 30 days = suspicious)
- Privacy protected registration
- Registrant in unexpected country

# 2. DNS Records
dig suspicious-domain.com ANY
dig suspicious-domain.com MX
dig suspicious-domain.com TXT

nslookup suspicious-domain.com
nslookup -type=mx suspicious-domain.com

# 3. Check domain reputation
# VirusTotal
https://www.virustotal.com/gui/domain/suspicious-domain.com

# URLVoid
https://www.urlvoid.com/scan/suspicious-domain.com

# Talos Intelligence
https://talosintelligence.com/reputation_center

# 4. Check if domain is typosquatting
# Compare to legitimate domain character by character
# Common tricks:
# - rn instead of m (arnazon vs amazon)
# - 1 instead of l (paypa1 vs paypal)
# - 0 instead of o (g00gle vs google)
# - Extra letters (microsoftt,aborle)
# - Different TLD (company.co vs company.com)

# 5. Check domain age
curl -s "https://input.payapi.io/v1/api/fraud/domain/age/suspicious-domain.com"

STEP 4: ANALYZE SENDER IP ADDRESS#

# Extract originating IP from headers

# 1. IP Reputation Check
# AbuseIPDB
https://www.abuseipdb.com/check/[IP]
curl -s "https://api.abuseipdb.com/api/v2/check?ipAddress=[IP]" -H "Key: YOUR_API_KEY"

# VirusTotal
https://www.virustotal.com/gui/ip-address/[IP]

# Shodan
https://www.shodan.io/host/[IP]
shodan host [IP]

# 2. Geolocation
curl -s "http://ip-api.com/json/[IP]"
geoiplookup [IP]

# Online: https://www.iplocation.net/

# 3. Reverse DNS
dig -x [IP]
nslookup [IP]
host [IP]

# 4. Check if IP is on blocklists
# MXToolbox
https://mxtoolbox.com/blacklists.aspx

# Spamhaus
https://check.spamhaus.org/
# 1. Extract URLs from email safely

# From .eml file:
grep -oE 'https?://[^"<>[:space:]]+' email.eml
grep -oE 'href="[^"]*"' email.eml

# Decode HTML entities
python3 -c "
import html
import re
with open('email.eml', 'r') as f:
    content = f.read()
    urls = re.findall(r'href=[\"']([^\"']+)[\"']', content)
    for url in urls:
        print(html.unescape(url))
"

# 2. Check for URL obfuscation techniques
# - URL shorteners (bit.ly, tinyurl, etc.)
# - Data URIs (data:text/html;base64,...)
# - JavaScript redirects
# - Hex encoded URLs (%68%74%74%70 = http)
# - Punycode/IDN (xn--) homograph attacks

# 3. Expand shortened URLs (without visiting)
curl -sI "https://bit.ly/xxxxx" | grep -i "location"
curl -Ls -o /dev/null -w '%{url_effective}' "https://bit.ly/xxxxx"

# Online unshorteners:
https://unshorten.it/
https://checkshorturl.com/

# 4. Analyze URL reputation
# VirusTotal
https://www.virustotal.com/gui/url/[URL]

# URLScan.io (safe sandbox scan)
https://urlscan.io/
curl -X POST "https://urlscan.io/api/v1/scan/" -H "Content-Type: application/json" -d '{"url": "http://suspicious-url.com"}'

# Google Safe Browsing
https://transparencyreport.google.com/safe-browsing/search

# PhishTank
https://www.phishtank.com/

# 5. Check URL structure
# RED FLAGS:
- IP address instead of domain (http://192.168.1.1/login)
- Suspicious subdomains (secure-paypal.malicious.com)
- Misspelled legitimate domains
- Excessive URL parameters
- Login pages on HTTP (not HTTPS)
- Random string domains
- Free hosting (000webhostapp, sites.google.com, etc.)

# 6. Safe URL Preview
# Use sandbox to view page without risk:
https://urlscan.io/
https://www.wannabrowser.net/
https://www.browserling.com/

STEP 6: ANALYZE ATTACHMENTS (IN SANDBOX)#

# NEVER open attachments on production machine

# 1. Get file hash without opening
# Windows:
certutil -hashfile attachment.pdf SHA256
Get-FileHash attachment.pdf -Algorithm SHA256

# Linux/Mac:
sha256sum attachment.pdf
shasum -a 256 attachment.pdf
md5sum attachment.pdf

# 2. Check hash on VirusTotal
https://www.virustotal.com/gui/search/[HASH]

# CLI with API:
curl -s "https://www.virustotal.com/api/v3/files/[HASH]" -H "x-apikey: YOUR_API_KEY"

# 3. Identify file type (don't trust extension)
file attachment.pdf
file --mime-type attachment.pdf

# Check for double extensions:
# invoice.pdf.exe
# document.docx.js

# 4. Extract metadata
exiftool attachment.pdf
pdfinfo attachment.pdf

# For Office documents:
olevba attachment.docx  # Check for macros
oleid attachment.docx   # Analyze OLE
oleobj attachment.docx  # Extract embedded objects

# 5. Upload to sandbox for analysis
# Any.Run (interactive sandbox)
https://any.run/

# Hybrid Analysis
https://www.hybrid-analysis.com/

# Joe Sandbox
https://www.joesandbox.com/

# Triage
https://tria.ge/

# 6. Analyze in isolated environment
# Use VM (VirtualBox, VMware) with snapshot
# Or use Docker container:
docker run -it --rm -v $(pwd):/samples remnux/remnux-distro

# 7. Check for malicious macros (Office docs)
olevba --decode suspicious.docm
mraptor suspicious.docm

# 8. Analyze PDFs
pdfid suspicious.pdf
pdf-parser suspicious.pdf
peepdf -i suspicious.pdf

# Look for:
- /JavaScript
- /JS
- /OpenAction
- /Launch
- /EmbeddedFile
- /URI

# 9. For HTML attachments
# Check for phishing forms, JavaScript, redirects
cat attachment.html | grep -E "(form|input|password|login|javascript|eval|document\.write)"

STEP 7: ANALYZE EMAIL CONTENT#

# 1. Check for urgency/pressure tactics
# RED FLAGS:
- "Your account will be suspended"
- "Act now or lose access"
- "Verify within 24 hours"
- "Unusual activity detected"
- "Payment failed"
- "You've won"

# 2. Check for impersonation
# Compare to legitimate emails from same sender
# Look for:
- Logo quality (blurry, wrong colors)
- Different email signature format
- Grammar/spelling errors
- Unusual greeting ("Dear Customer" vs your name)

# 3. Look for social engineering indicators
- Authority (CEO, IT Department, Bank)
- Scarcity (Limited time offer)
- Fear (Account compromised)
- Curiosity (You have a package)

# 4. Check embedded images
# Extract images:
munpack email.eml
ripmime -i email.eml -d ./extracted/

# Check for tracking pixels:
grep -E 'img.*width="1".*height="1"' email.eml
grep -E '<img[^>]+src="http' email.eml

# Reverse image search logos
https://images.google.com/
https://tineye.com/

STEP 8: VERIFY WITH LEGITIMATE SOURCE#

# NEVER use contact info from the suspicious email

# 1. Find official contact independently
- Go to official website directly (type URL, don't click)
- Use phone number from official documentation
- Use official app to check account status

# 2. Check with IT Security team
- Report to security@yourcompany.com
- Check if others received same email
- Check against known phishing campaigns

# 3. Check known phishing databases
https://www.phishtank.com/
https://openphish.com/
https://phishstats.info/

STEP 9: DOCUMENT FINDINGS#

# Create incident report with:

1. Email metadata:
   - Date/time received
   - Sender (display name and actual email)
   - Subject line
   - Recipients

2. Header analysis results:
   - SPF/DKIM/DMARC status
   - Originating IP
   - Email path

3. URL analysis:
   - All URLs found
   - Reputation check results
   - Screenshots from sandbox

4. Attachment analysis:
   - File names and types
   - Hashes (MD5, SHA256)
   - VirusTotal results
   - Sandbox results

5. Indicators of Compromise (IOCs):
   - Malicious IPs
   - Malicious domains
   - File hashes
   - Email addresses

# IOC extraction script:
ioc-finder email.eml

STEP 10: RESPONSE ACTIONS#

# 1. If confirmed phishing:

# Block sender
# In Exchange:
Set-MailboxJunkEmailConfiguration -Identity user@domain.com -BlockedSendersAndDomains @{Add="phisher@evil.com"}

# Block domain/IP at email gateway
# Depends on your email security solution

# 2. Delete from all mailboxes (Exchange)
# Search and delete:
Get-Mailbox -ResultSize Unlimited | Search-Mailbox -SearchQuery 'Subject:"Suspicious Subject" AND Received:today' -DeleteContent -Force

# Compliance search (O365):
New-ComplianceSearch -Name "Phishing Hunt" -ExchangeLocation All -ContentMatchQuery 'Subject:"Suspicious Subject"'
Start-ComplianceSearch -Identity "Phishing Hunt"

# 3. Report to authorities
# Report to Anti-Phishing Working Group
reportphishing@apwg.org

# Forward to:
spam@uce.gov (FTC)
phishing-report@us-cert.gov (CISA)

# Report to impersonated company
# (Each company has abuse/phishing reporting)

# 4. Update blocklists/filters
# Add to:
- Email gateway blocklist
- Web proxy blocklist
- Firewall rules
- SIEM detection rules

# 5. Alert users if widespread
# Send security awareness notification

USEFUL TOOLS SUMMARY#

# Header Analysis:
- MXToolbox Header Analyzer
- Google Admin Toolbox
- mailheader.org

# Domain/IP Analysis:
- VirusTotal
- AbuseIPDB
- Shodan
- Talos Intelligence
- URLVoid

# URL Analysis:
- URLScan.io
- PhishTank
- Google Safe Browsing
- Unshorten.it

# Attachment Analysis:
- VirusTotal
- Any.Run
- Hybrid Analysis
- Joe Sandbox
- Triage

# Local Analysis Tools:
- oletools (olevba, oleid, mraptor)
- pdf-parser, pdfid, peepdf
- exiftool
- file, strings
- REMnux (Linux distro for malware analysis)

# Email Extraction:
- munpack
- ripmime
- emlParser

QUICK REFERENCE COMMANDS#

# Full header extraction
cat email.eml | formail -x Received -x From -x To -x Subject -x Return-Path -x Reply-To

# Get all URLs
grep -oP 'https?://[^\s<>"]+' email.eml | sort -u

# Get all email addresses
grep -oE '[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}' email.eml | sort -u

# Check domain age and info
whois domain.com | grep -E "(Creation|Registrant|Name Server)"

# Hash file for VirusTotal
sha256sum attachment.* | awk '{print $1}'

# Quick malware check on attachment
file suspicious.* && exiftool suspicious.* && strings suspicious.* | head -50

COMMON PHISHING INDICATORS CHECKLIST#

[ ] Sender email doesn't match display name
[ ] Reply-To different from From
[ ] SPF/DKIM/DMARC failures
[ ] Recently registered sender domain
[ ] Urgency or threat language
[ ] Generic greeting
[ ] Grammar/spelling errors
[ ] Suspicious links (hover to check)
[ ] Mismatched or suspicious URLs
[ ] Unexpected attachments
[ ] Request for credentials/personal info
[ ] Unusual request from "known" sender
[ ] Too good to be true offers
[ ] Pressure to act quickly
[ ] Threatening consequences