PhishingAnalysis
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
STEP 1: INITIAL TRIAGE (DO NOT CLICK ANYTHING)#
# Before any analysis - NEVER click links or open attachments directly [ ] Do not click any links in the email [ ] Do not open attachments [ ] Do not reply to the sender [ ] Do not forward to others (yet) [ ] Take screenshots for documentation [ ] Note the time/date received [ ] Check if others received the same email # Export email as .eml file for analysis # In Outlook: File > Save As > .eml # In Gmail: Three dots > Download message # In Thunderbird: File > Save As > File
STEP 2: ANALYZE EMAIL HEADERS#
# View full headers: # Outlook: Open email > File > Properties > Internet Headers # Gmail: Three dots > Show original # Thunderbird: View > Headers > All # Key headers to examine:
1. AUTHENTICATION RESULTS#
# Check SPF (Sender Policy Framework) Authentication-Results: spf=pass/fail # Check DKIM (DomainKeys Identified Mail) Authentication-Results: dkim=pass/fail # Check DMARC (Domain-based Message Authentication) Authentication-Results: dmarc=pass/fail # RED FLAGS: - spf=fail or spf=softfail - dkim=fail or dkim=none - dmarc=fail
2. RECEIVED HEADERS (READ BOTTOM TO TOP)#
# Trace the email path - bottom is origin, top is destination Received: from [server] by [server] with [protocol] # Look for: - Suspicious originating IP addresses - Mismatched server names - Unusual geographic locations - Time gaps that don't make sense
3. FROM vs RETURN-PATH vs REPLY-TO#
From: display-name <actual@email.com> Return-Path: <bounce@different-domain.com> Reply-To: <reply@another-domain.com> # RED FLAGS: - From domain doesn't match Return-Path - Reply-To goes to different domain - Display name mimics legitimate company but email is different
4. MESSAGE-ID#
Message-ID: <unique-id@domain.com> # Should match sender's domain # Random/suspicious domains are red flags
5. X-ORIGINATING-IP#
X-Originating-IP: [192.168.1.1] # Research this IP for reputation
# HEADER ANALYSIS TOOLS#
# Online analyzers:
https://mxtoolbox.com/EmailHeaders.aspx
https://toolbox.googleapps.com/apps/messageheader/
https://www.mailheader.org/
# Command line:
# Extract headers from .eml file
cat email.eml | grep -E "^(From|To|Subject|Date|Received|Return-Path|Reply-To|Message-ID|X-Originating|Authentication)"
# Parse with Python
python3 -c "
import email
with open('email.eml', 'r') as f:
msg = email.message_from_file(f)
for header in ['From', 'To', 'Subject', 'Return-Path', 'Reply-To', 'Received', 'Authentication-Results']:
print(f'{header}: {msg.get_all(header)}')
"
STEP 3: ANALYZE SENDER DOMAIN#
# 1. WHOIS lookup whois suspicious-domain.com # Online: https://whois.domaintools.com/ # Look for: - Recently registered domain (< 30 days = suspicious) - Privacy protected registration - Registrant in unexpected country # 2. DNS Records dig suspicious-domain.com ANY dig suspicious-domain.com MX dig suspicious-domain.com TXT nslookup suspicious-domain.com nslookup -type=mx suspicious-domain.com # 3. Check domain reputation # VirusTotal https://www.virustotal.com/gui/domain/suspicious-domain.com # URLVoid https://www.urlvoid.com/scan/suspicious-domain.com # Talos Intelligence https://talosintelligence.com/reputation_center # 4. Check if domain is typosquatting # Compare to legitimate domain character by character # Common tricks: # - rn instead of m (arnazon vs amazon) # - 1 instead of l (paypa1 vs paypal) # - 0 instead of o (g00gle vs google) # - Extra letters (microsoftt,aborle) # - Different TLD (company.co vs company.com) # 5. Check domain age curl -s "https://input.payapi.io/v1/api/fraud/domain/age/suspicious-domain.com"
STEP 4: ANALYZE SENDER IP ADDRESS#
# Extract originating IP from headers # 1. IP Reputation Check # AbuseIPDB https://www.abuseipdb.com/check/[IP] curl -s "https://api.abuseipdb.com/api/v2/check?ipAddress=[IP]" -H "Key: YOUR_API_KEY" # VirusTotal https://www.virustotal.com/gui/ip-address/[IP] # Shodan https://www.shodan.io/host/[IP] shodan host [IP] # 2. Geolocation curl -s "http://ip-api.com/json/[IP]" geoiplookup [IP] # Online: https://www.iplocation.net/ # 3. Reverse DNS dig -x [IP] nslookup [IP] host [IP] # 4. Check if IP is on blocklists # MXToolbox https://mxtoolbox.com/blacklists.aspx # Spamhaus https://check.spamhaus.org/
STEP 5: ANALYZE URLs/LINKS (WITHOUT CLICKING)#
# 1. Extract URLs from email safely
# From .eml file:
grep -oE 'https?://[^"<>[:space:]]+' email.eml
grep -oE 'href="[^"]*"' email.eml
# Decode HTML entities
python3 -c "
import html
import re
with open('email.eml', 'r') as f:
content = f.read()
urls = re.findall(r'href=[\"']([^\"']+)[\"']', content)
for url in urls:
print(html.unescape(url))
"
# 2. Check for URL obfuscation techniques
# - URL shorteners (bit.ly, tinyurl, etc.)
# - Data URIs (data:text/html;base64,...)
# - JavaScript redirects
# - Hex encoded URLs (%68%74%74%70 = http)
# - Punycode/IDN (xn--) homograph attacks
# 3. Expand shortened URLs (without visiting)
curl -sI "https://bit.ly/xxxxx" | grep -i "location"
curl -Ls -o /dev/null -w '%{url_effective}' "https://bit.ly/xxxxx"
# Online unshorteners:
https://unshorten.it/
https://checkshorturl.com/
# 4. Analyze URL reputation
# VirusTotal
https://www.virustotal.com/gui/url/[URL]
# URLScan.io (safe sandbox scan)
https://urlscan.io/
curl -X POST "https://urlscan.io/api/v1/scan/" -H "Content-Type: application/json" -d '{"url": "http://suspicious-url.com"}'
# Google Safe Browsing
https://transparencyreport.google.com/safe-browsing/search
# PhishTank
https://www.phishtank.com/
# 5. Check URL structure
# RED FLAGS:
- IP address instead of domain (http://192.168.1.1/login)
- Suspicious subdomains (secure-paypal.malicious.com)
- Misspelled legitimate domains
- Excessive URL parameters
- Login pages on HTTP (not HTTPS)
- Random string domains
- Free hosting (000webhostapp, sites.google.com, etc.)
# 6. Safe URL Preview
# Use sandbox to view page without risk:
https://urlscan.io/
https://www.wannabrowser.net/
https://www.browserling.com/
STEP 6: ANALYZE ATTACHMENTS (IN SANDBOX)#
# NEVER open attachments on production machine # 1. Get file hash without opening # Windows: certutil -hashfile attachment.pdf SHA256 Get-FileHash attachment.pdf -Algorithm SHA256 # Linux/Mac: sha256sum attachment.pdf shasum -a 256 attachment.pdf md5sum attachment.pdf # 2. Check hash on VirusTotal https://www.virustotal.com/gui/search/[HASH] # CLI with API: curl -s "https://www.virustotal.com/api/v3/files/[HASH]" -H "x-apikey: YOUR_API_KEY" # 3. Identify file type (don't trust extension) file attachment.pdf file --mime-type attachment.pdf # Check for double extensions: # invoice.pdf.exe # document.docx.js # 4. Extract metadata exiftool attachment.pdf pdfinfo attachment.pdf # For Office documents: olevba attachment.docx # Check for macros oleid attachment.docx # Analyze OLE oleobj attachment.docx # Extract embedded objects # 5. Upload to sandbox for analysis # Any.Run (interactive sandbox) https://any.run/ # Hybrid Analysis https://www.hybrid-analysis.com/ # Joe Sandbox https://www.joesandbox.com/ # Triage https://tria.ge/ # 6. Analyze in isolated environment # Use VM (VirtualBox, VMware) with snapshot # Or use Docker container: docker run -it --rm -v $(pwd):/samples remnux/remnux-distro # 7. Check for malicious macros (Office docs) olevba --decode suspicious.docm mraptor suspicious.docm # 8. Analyze PDFs pdfid suspicious.pdf pdf-parser suspicious.pdf peepdf -i suspicious.pdf # Look for: - /JavaScript - /JS - /OpenAction - /Launch - /EmbeddedFile - /URI # 9. For HTML attachments # Check for phishing forms, JavaScript, redirects cat attachment.html | grep -E "(form|input|password|login|javascript|eval|document\.write)"
STEP 7: ANALYZE EMAIL CONTENT#
# 1. Check for urgency/pressure tactics
# RED FLAGS:
- "Your account will be suspended"
- "Act now or lose access"
- "Verify within 24 hours"
- "Unusual activity detected"
- "Payment failed"
- "You've won"
# 2. Check for impersonation
# Compare to legitimate emails from same sender
# Look for:
- Logo quality (blurry, wrong colors)
- Different email signature format
- Grammar/spelling errors
- Unusual greeting ("Dear Customer" vs your name)
# 3. Look for social engineering indicators
- Authority (CEO, IT Department, Bank)
- Scarcity (Limited time offer)
- Fear (Account compromised)
- Curiosity (You have a package)
# 4. Check embedded images
# Extract images:
munpack email.eml
ripmime -i email.eml -d ./extracted/
# Check for tracking pixels:
grep -E 'img.*width="1".*height="1"' email.eml
grep -E '<img[^>]+src="http' email.eml
# Reverse image search logos
https://images.google.com/
https://tineye.com/
STEP 8: VERIFY WITH LEGITIMATE SOURCE#
# NEVER use contact info from the suspicious email # 1. Find official contact independently - Go to official website directly (type URL, don't click) - Use phone number from official documentation - Use official app to check account status # 2. Check with IT Security team - Report to security@yourcompany.com - Check if others received same email - Check against known phishing campaigns # 3. Check known phishing databases https://www.phishtank.com/ https://openphish.com/ https://phishstats.info/
STEP 9: DOCUMENT FINDINGS#
# Create incident report with: 1. Email metadata: - Date/time received - Sender (display name and actual email) - Subject line - Recipients 2. Header analysis results: - SPF/DKIM/DMARC status - Originating IP - Email path 3. URL analysis: - All URLs found - Reputation check results - Screenshots from sandbox 4. Attachment analysis: - File names and types - Hashes (MD5, SHA256) - VirusTotal results - Sandbox results 5. Indicators of Compromise (IOCs): - Malicious IPs - Malicious domains - File hashes - Email addresses # IOC extraction script: ioc-finder email.eml
STEP 10: RESPONSE ACTIONS#
# 1. If confirmed phishing:
# Block sender
# In Exchange:
Set-MailboxJunkEmailConfiguration -Identity user@domain.com -BlockedSendersAndDomains @{Add="phisher@evil.com"}
# Block domain/IP at email gateway
# Depends on your email security solution
# 2. Delete from all mailboxes (Exchange)
# Search and delete:
Get-Mailbox -ResultSize Unlimited | Search-Mailbox -SearchQuery 'Subject:"Suspicious Subject" AND Received:today' -DeleteContent -Force
# Compliance search (O365):
New-ComplianceSearch -Name "Phishing Hunt" -ExchangeLocation All -ContentMatchQuery 'Subject:"Suspicious Subject"'
Start-ComplianceSearch -Identity "Phishing Hunt"
# 3. Report to authorities
# Report to Anti-Phishing Working Group
reportphishing@apwg.org
# Forward to:
spam@uce.gov (FTC)
phishing-report@us-cert.gov (CISA)
# Report to impersonated company
# (Each company has abuse/phishing reporting)
# 4. Update blocklists/filters
# Add to:
- Email gateway blocklist
- Web proxy blocklist
- Firewall rules
- SIEM detection rules
# 5. Alert users if widespread
# Send security awareness notification
USEFUL TOOLS SUMMARY#
# Header Analysis: - MXToolbox Header Analyzer - Google Admin Toolbox - mailheader.org # Domain/IP Analysis: - VirusTotal - AbuseIPDB - Shodan - Talos Intelligence - URLVoid # URL Analysis: - URLScan.io - PhishTank - Google Safe Browsing - Unshorten.it # Attachment Analysis: - VirusTotal - Any.Run - Hybrid Analysis - Joe Sandbox - Triage # Local Analysis Tools: - oletools (olevba, oleid, mraptor) - pdf-parser, pdfid, peepdf - exiftool - file, strings - REMnux (Linux distro for malware analysis) # Email Extraction: - munpack - ripmime - emlParser
QUICK REFERENCE COMMANDS#
# Full header extraction
cat email.eml | formail -x Received -x From -x To -x Subject -x Return-Path -x Reply-To
# Get all URLs
grep -oP 'https?://[^\s<>"]+' email.eml | sort -u
# Get all email addresses
grep -oE '[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}' email.eml | sort -u
# Check domain age and info
whois domain.com | grep -E "(Creation|Registrant|Name Server)"
# Hash file for VirusTotal
sha256sum attachment.* | awk '{print $1}'
# Quick malware check on attachment
file suspicious.* && exiftool suspicious.* && strings suspicious.* | head -50
COMMON PHISHING INDICATORS CHECKLIST#
[ ] Sender email doesn't match display name [ ] Reply-To different from From [ ] SPF/DKIM/DMARC failures [ ] Recently registered sender domain [ ] Urgency or threat language [ ] Generic greeting [ ] Grammar/spelling errors [ ] Suspicious links (hover to check) [ ] Mismatched or suspicious URLs [ ] Unexpected attachments [ ] Request for credentials/personal info [ ] Unusual request from "known" sender [ ] Too good to be true offers [ ] Pressure to act quickly [ ] Threatening consequences