Giter Site home page Giter Site logo

phishing's Introduction

Phishing

Analizar Headers

Aqui damos 3 ejemplos de tool que podemos usar porque siempre es bueno que tener varios tools por si uno nos falla.

Messageheader(Google)

Es un tool hecho por Google que nos ayuda analizar emails. https://toolbox.googleapps.com/apps/messageheader/analyzeheader

Message Header Analyzer(Azure)

Otro tool que hace los mismo que Messageheader(de google) https://mha.azurewebsites.net/

Mail Header Analysis

Otro tool similar a los anteriores https://mailheader.org/


Analizar Sender IP address

Las herramientas en continuacion nos ayudan a analizar sobre los Sender's IP address:

Ipinfo.io

EL primer tool que vamos a ver es https://ipinfo.io/ quote de la pagian

"With IPinfo, you can pinpoint your users’ locations, customize their experiences, prevent fraud, ensure compliance, and so much more".

URLscan.io

quote del site:

"urlscan.io is a free service to scan and analyse websites. When a URL is submitted to urlscan.io, an automated process will browse to the URL like a regular user and record the activity that this page navigation creates. This includes the domains and IPs contacted, the resources (JavaScript, CSS, etc) requested from those domains, as well as additional information about the page itself. urlscan.io will take a screenshot of the page, record the DOM content, JavaScript global variables, cookies created by the page, and a myriad of other observations. If the site is targeting the users one of the more than 400 brands tracked by urlscan.io, it will be highlighted as potentially malicious in the scan results".


Screenshot del website que nos manda link

URL2png

Link del Website: https://www.url2png.com/

Wannabrowser

NOs permite ver el websiate sin infectarnos https://www.wannabrowser.net/


Verificar integridad del website

Talos

Talos es una pagina de cisco que nos ayuda identificar si otros usuarios reportaron la pagina como maligna https://talosintelligence.com/reputation

Virustotal

Igual que Talos pero esta es la pagina mas usada para reputacion https://www.virustotal.com/gui/home/upload

Email Body

Los links los podemos extraer manualmente directamente del formato HTML como este ejemplo: Drag Racing

Tambien podemos hacer lo mismo con este tool que nos puede ayudar https://www.convertcsv.com/url-extractor.htm

Podemos copiar el raw header en el text box como el Paso 1 y Paso 2

![Pas02](image

Paso 3

image

Tambien podemos usar https://gchq.github.io/CyberChef/

image

es importante que tomemos en cuenta el root domain del website de done extraemos los links

Attachment

Si el email tiene un attachment podemos obtener el hash. Para chequiar la reputacion del file en Talos o VirusTotal

user@machine$ sha256sum Double\ Jackpot\ Slots\ Las\ Vegas.dot
c650f397a9193db6a2e1a273577d8d84c5668d03c06ba99b17e4f6617af4ee83  Double Jackpot Slots Las Vegas.dot

Despues que tengamos el hash podemos verificarlo en VirusTotal para ver su reputacion Aqui en el screenshot un ejemplo del mismo: image


Malware SandBox

Por suerte como defensores no necesitamos tener habilidades de analisis de malware. Hay website que nos ayudan a analizar los malware y decirnos que es lo que hacen. Como ejemplo podemos cojer un attachment que hay en los emails que parece malicioso con estos site

Any RUN

https://app.any.run/

"Analyze a network, file, module, and the registry activity. Interact with the OS directly from a browser. See the feedback from your actions immediately".

Hybrid Analysis:

https://www.hybrid-analysis.com/

"This is a free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology."

Joe Security

https://www.joesecurity.org/

"Joe Sandbox empowers analysts with a large spectrum of product features. Among them: Live Interaction, URL Analysis & AI based Phishing Detection, Yara and Sigma rules support, MITRE ATT&CK matrix, AI based malware detection, Mail Monitor, Threat Hunting & Intelligence, Automated User Behavior, Dynamic VBA/JS/JAR instrumentation, Execution Graphs, Localized Internet Anonymization and many more".

phishing's People

Contributors

jorgevillabarreras avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.