Questions
- What is the originating IP address of the sender?
- Which mail server relayed this email before reaching the victim?
- What is the sender’s email address?
- What is the ‘Reply-To’ email address specified in the email?
- What is the SPF (Sender Policy Framework) result for this email?
- What is the domain used in the phishing URL inside the email?
- secure.business-finance.com
- What is the fake company name used in the email?
- What is the name of the attachment included in the email?
- What is the SHA-256 hash of the attachment?
- 8379c41239e9af845b2ab6c27a7509ae8804d7d73e455c800a551b22ba25bb4a
- What is the filename of the malicious file contained within the ZIP attachment?
- Which MITRE ATT&CK techniques are associated with this attack?