Advent of Cyber 2022 [Day6] Email Analysis — It’s beginning to look a lot like phishing by Karthikeyan Nagaraj

Advent of Cyber 2022 Day 6 — It’s beginning to look a lot like phishing Walkthrough Answers

Karthikeyan Nagaraj
InfoSec Write-ups

--

  1. What is the email address of the sender?

Click Split view in the top and open the File in the Machine

Ans: Answer is in the Above image --> (From: )

2. What is the return address?

Answer is in the Above Image

3. On whose behalf was the email sent?

Answer is in the Above Image

Ans: Chief elf

4. What is the X-spam score?

Answer is in the Above Image

Ans: 3

5. What is hidden in the value of the Message-ID field?

We have to Decode the base64 String

Ans: AoC2022_Email_Analysis

6. Visit the email reputation check website provided in the task.
What is the reputation result of the sender’s email address?

Open the Website emailrep

Ans: Risky

7. Check the attachments. What is the filename of the attachment?

For Further Investigations, I’m Sending the File from Remote machine to my Machine!!

Sender — Remote Machine
Receiver — My Machine
Ans: Answer is in the Above Image (filename: )

8. What is the hash value of the attachment?

Use this Analyser to Analye the .eml File

You will get the Hash

Ans: Answer is in the Above Image

9. Visit the Virus Total website and use the hash value to search.
Navigate to the behaviour section.
What is the second tactic marked in the Mitre ATT&CK section?

Open Virustotal and Search for the hash

Ans: Answer is in the Above Image (2nd Subtitle)

10. Visit the InQuest website and use the hash value to search.
What is the subcategory of the file.

Open Inquest and Click Indicator Lookup and Search with the Hash

Ans: Macro_hunter

Thank you for Reading~~

Happy Hacking ~

Author : Karthikeyan Nagaraj ~ Cyberw1ng

Tryhackme , Advent of Cyber 4 2022 Answers/writeups/walkthrough

From Infosec Writeups: A lot is coming up in the Infosec every day that it’s hard to keep up with. Join our weekly newsletter to get all the latest Infosec trends in the form of 5 articles, 4 Threads, 3 videos, 2 GitHub Repos and tools, and 1 job alert for FREE!

--

--

Security Researcher | Bug Hunter | Web Pentester | CTF Player | TryHackme Top 1% | AI Researcher | Blockchain Developer