Author Topic: How to check phishing emails - any website to check?  (Read 1576 times)

How to check phishing emails - any website to check?
« on: 20 April, 2017, 08:42:30 am »
Just curious, does anyone know of a website that records email scams, phishing, etc.? I got one that I knew was dodgy but it was kind of convincing. I knew it was dodgy because it was related to something I have never had any interest in.

Jaded

  • The Codfather
  • Formerly known as Jaded
Re: How to check phishing emails - any website to check?
« Reply #1 on: 20 April, 2017, 10:37:22 am »
Have a look here

https://www.spamcop.net
It is simpler than it looks.

Afasoas

Re: How to check phishing emails - any website to check?
« Reply #2 on: 23 April, 2017, 10:22:00 am »
I think what Jaded is suggesting, is that you get the sending mail servers IP address and submit it here:
https://www.spamcop.net/bl.shtml

Thing is, SpamCop deals specifically with unsolicited bulk email senders, not phishing emails per se. You can check a mail server's IP/fully qualified domain name against: https://mxtoolbox.com/blacklists.aspx. That means it's evaluated against over 100 real time block lists, some of which will now doubt including known phishing sources.

The sending mail server's fully qualified domain name/IP address will be available in the email headers. Within the header there will be a line like this:

Code: [Select]
Received: from mail-out.spamhaus.org (mail-out.spamhaus.org
 [82.165.36.226]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
 (No client certificate requested) by blah.com (Postfix) with
 ESMTPS id 94BC0174073C for <blah@blah.com>; Thu, 24 Dec 2015 14:55:06
 +0000 (GMT)

In this instance, the mail server's fully qualified domain name is mail-out.spamhaus.org and it's IP address is 82.165.36.226. Your email client should let you view the headers/source/raw email. Even Microsoft Live Mail/Outlook365/Gmail let you do this in their webmail clients, although the option is often half hidden away on a 'Other actions' menu, usually accessed by clicking '...' next to the reply/reply all/forward/spam/delete options.

A mail server administrator might use spamcop and other real time block lists to prevent a mail server from accepting email from known spammers/phishers etc.. As an email user, your options are a bit more limited. Some on-line security products include anti-phishing tools that support some mail clients, like Outlook and some will even work with on-line webmail - Avast for example stops me downloading executable files from within Roundcube web mail when I'm using Edge or Explorer. Some research will be needed into the security product to ensure it works in your use case*.

I've italicised the word known because new spam/phishing sources crop up daily in large numbers. There are other tools that analyse email content to determine whether the email is ham or spam, but with some education these are evaded. These tools are implemented by the big email providers and they are also used on lots of mail servers. There are some tools you can get to work with email clients too - I think a classic old school tool is MailWasher - I'm not even sure it's still a thing.

So in summary, you can dig some information out of the email headers and determine whether or not the email in question has come from a known spam source. Or you can install an on-line security product that may or may not do this for you, depending on your actual use case.

*Combination of operating system, mail client/browser/webmail service etc. etc.

Re: How to check phishing emails - any website to check?
« Reply #3 on: 23 April, 2017, 10:57:33 am »
Mailwasher is still around.
Get a bicycle. You will never regret it, if you live- Mark Twain

Re: How to check phishing emails - any website to check?
« Reply #4 on: 23 April, 2017, 01:42:32 pm »
Just curious, does anyone know of a website that records email scams, phishing, etc.? I got one that I knew was dodgy but it was kind of convincing. I knew it was dodgy because it was related to something I have never had any interest in.

Phishing is now all about research.  The trick is to find out all about the target and use the information so the phishing does relate to you as personally as possible.  It's called spear phishing.  If you get a whaling attack be sure to tell us then we'll know you are someone important.

Phishing attacks often land you with a malicious dropper which gifts you some Rats (Remote Access Tools).  If these operate from within a sandbox then you will have hell's own job doing anything about it.
Move Faster and Bake Things

Re: How to check phishing emails - any website to check?
« Reply #5 on: 24 April, 2017, 11:27:55 am »
www.scammed.by

Seemed to work on checking out a dodgy email I received earlier.  Although in fairness, it was obviously a dodgy email.  I mean, who else offers me $5.5m dollars to help orphans in my country?

Re: How to check phishing emails - any website to check?
« Reply #6 on: 24 April, 2017, 01:51:37 pm »
Targeted right enough just they got the wrong company. I'd been looking at a Hong Kong based company making camping equipment like tents and they used a faked sales acknowledgment for a company selling spa days out but with the same name. My online activity was for an ul tent for actual dirty days away on a bike and they thought it was for the ultra clean holidays in a spa. Seriously! They could not get me more wrong. Grunge was a style that took it's inspiration from my school/student days. Positively Viking when on holiday (take a visit to Jorvik centre which I believe uses scents to give a better idea of what Viking York smelt like).