Writeup: Advent of Cyber 3 Day 19 - AtomicMaya/knowledge-base GitHub Wiki

Advent of Cyber - Day 19

Link: Advent Of Cyber 3 on TryHackMe

Question 1

Who was the email sent to? (Answer is the email address)

Answer: [email protected]

Question 2

Phishing emails use similar domains of their targets to increase the likelihood the recipient will be tricked into interacting with the email. Who does it say the email was from? (Answer is the email address)

Answer: [email protected]

Question 3

Sometimes phishing emails have a different reply-to email address. If this email was replied to, what email address will receive the email response?

Answer: [email protected]

Question 4

Less sophisticated phishing emails will have typos. What is the misspelled word?

Answer: stright

Question 5

The email contains a link that will redirect the recipient to a fraudulent website in an effort to collect credentials. What is the link to the credential harvesting website?

Answer: https://89xgwsnmo5.grinch/out/fishing/

Question 6

View the email source code. There is an unusual email header. What is the header and its value?

Answer: X-GrinchPhish: >;^)

Question 7

You received other reports of phishing attempts from other colleagues. Some of the other emails contained attachments. Open attachment.txt. What is the name of the attachment?

Answer: password-reset-instructions.pdf

Question 8

What is the flag in the PDF file?

Answer: THM{A0C_Thr33_Ph1sh1ng_An4lys!s}

Question 9

If you want to learn more about phishing, check out the "Phishing" module on TryHackMe.

Answer: No answer needed