Phishing Analysis Tools

capitalone.com

Copy Link Location

#454326_PDF.exe

Netflix

N e t f I i x <JGQ47wazXe1xYVBrkeDg-JOg7ODDQwWdR@JOg7ODDQwWdR-yVkCaBkTNp.gogolecloud.com>

209[.]85[.]167[.]226

etekno[.]xyz

hxxps[://]t[.]co/yuxfZm8KPg?amp==1

Suspicious activity

What is the name of the PDF file?

Payment-updateid.pdf

cc6f1a04b10bcb168aeec8d870b97bd7c20fc161e8310b5bce1af8ed420e2c24

What two IP addresses are classified as malicious? Defang the IP addresses. (answer: IP_ADDR,IP_ADDR


2[.]16[.]107[.]24,2[.]16[.]107[.]83

svchost.exe

Malicious activity

CBJ200620039539.xlsx

5f94a66e0ce78d17afc2dd27fc17b44b3ffc13ac5f42d3ad6a5dcfb36715f3eb

biz9holdings[.]com,findresults[.]site,ww38[.]findresults[.]site

75[.]2[.]11[.]242,103[.]224[.]182[.]251,204[.]11[.]56[.]48

CVE-2017-11882