Advertisement
fedelemantuano

SpamScope analysis of phishing

Jul 28th, 2018
1,232
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
JSON 5.83 KB | None | 0 0
  1. {
  2.   "_source": {
  3.     "to": [
  4.       [
  5.         "",
  6.         "gwenaelle.bauza@test.it"
  7.       ]
  8.     ],
  9.     "tags": [
  10.       "mails",
  11.       "analysis",
  12.       "geoip"
  13.     ],
  14.     "x-mimeole": "Produced By Microsoft MimeOLE V6.1.7601.17514",
  15.     "mailbox": "postfix",
  16.     "sha1": "04cdbb2515fa9abacf13829edc2f6a4e4db2d392",
  17.     "x-original-to": "gwenaelle.bauza@test.it",
  18.     "@timestamp": "2018-07-26T13:50:17.443Z",
  19.     "subject": "Avete Messaggio urgente",
  20.     "thread-index": "Acx6h4269uya6487x6h4269uya6487==",
  21.     "to_domains": [
  22.       "test.it"
  23.     ],
  24.     "ssdeep": "48:sUreUVEl9YMHicF+KkTDOppklHkIGHkI+kJU4IaAtv7Ushk/xVU:9e4w9sZOp2oFW7XWsInU",
  25.     "content-type": "multipart/alternative;\n\tboundary=\"----=_NextPart_000_0034_01D42500.058CC117\"",
  26.     "date": "2018-07-26T16:27:39",
  27.     "body": ".style1 { COLOR: #ffffff}.style2 { COLOR: #001f6b}// \n&nbsp;\nSalve\n&nbsp;\nIl suo profilo e stato chiuso\n&nbsp;\nPremere sul link per effettuare lo sblocco\n&nbsp;\nhttps://www.intesasanpaolo.com/bloccato/ID-72242916/ \n\n\nGrazie, Intesasanpaolo.\n--- mail_boundary ---\n<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.0 Transitional//EN\">\n<HTML><HEAD>\n<META content=\"text/html; charset=us-ascii\" http-equiv=Content-Type>\n<META name=GENERATOR content=\"MSHTML 8.00.7601.17514\"></HEAD>\n<BODY>\n<DIV><SPAN class=941117457-26072018><FONT size=2 \nface=Arial><STYLE type=text/css>.style1 {\n\n COLOR: #ffffff\n\n}\n\n.style2 {\n\n COLOR: #001f6b\n\n}\n\n</STYLE>\n\n\n\n<SCRIPT type=colorScheme>// <![CDATA[\n\n {\n\n \"name\":\"Default\",\n\n \"bgBody\":\"ffffff\",\n\n \"link\":\"fff\",\n\n \"color\":\"555555\",\n\n \"bgItem\":\"ffffff\",\n\n \"title\":\"181818\"\n\n }\n\n// ]]></SCRIPT>\n\n</HEAD>\n\n<BODY>\n\n<DIV><FONT size=2 face=Arimo><IMG border=0 hspace=0 alt=\"\" \n\nsrc=\"https://media.smau.it/x-exhibition/upload/partner/2015/09/26/001-B1010-dwl02.jpg\" \n\nwidth=276 height=34></FONT></DIV>\n\n<DIV>&nbsp;</DIV>\n\n<DIV><FONT size=2 face=Arimo>Salve</FONT></DIV>\n\n<DIV>\n\n<DIV><FONT face=Arimo></FONT>&nbsp;</DIV>\n\n<DIV align=left><FONT size=2 face=Arimo>Il suo profilo e stato chiuso</FONT></DIV>\n\n<DIV><FONT face=Arimo></FONT>&nbsp;</DIV>\n\n<DIV align=left><FONT size=2 face=Arimo>Premere sul link per effettuare lo sblocco</FONT></DIV>\n\n<DIV align=left><FONT size=2 face=Arimo></FONT>&nbsp;</DIV>\n\n<DIV align=left><FONT size=2><A href=\"http://hanumaninternationalmission.com/yOegkh.html\"><FONT \n\nface=Arimo>https://www.intesasanpaolo.com/bloccato/ID-72242916/</FONT></A></A></A><FONT \n\nface=Arimo> </FONT></FONT></DIV>\n\n<DIV align=left><FONT size=2><FONT face=Arimo></A></A></FONT></FONT></DIV>\n\n<DIV align=left><FONT size=2 face=Arimo></FONT></DIV>\n\n<DIV><FONT face=Arimo>Grazie, Intesasanpaolo.</FONT></DIV></FONT></SPAN></DIV></BODY></HTML>",
  28.     "size": 3078,
  29.     "sha512": "4a157a4425b55067ff0307ef1f2f2fc27f3cd819f5ca2f9d1d89a37c0054068b54e2fd4e3f87c60465bbac112e95e1cfbb71d01f0eeed691b5ccbc8567f9c9c1",
  30.     "from": [
  31.       [
  32.         "Intesasanpaolo",
  33.         "security@intesasanpaolo.com"
  34.       ]
  35.     ],
  36.     "analisys_date": "2018-07-26T13:50:17.443124",
  37.     "received": [
  38.       {
  39.         "date_utc": "2018-07-26T13:50:11",
  40.         "date": "Thu, 26 Jul 2018 13:50:11 +0000 UTC",
  41.         "by": "localhost Postfix",
  42.         "hop": 1,
  43.         "with": "ESMTP id DD3171E20DE for <gwenaelle.bauza@test.it>",
  44.         "delay": 0,
  45.         "from": "94.187.48.124 unknown 94.187.48.124"
  46.       }
  47.     ],
  48.     "@version": "1",
  49.     "sender_ip": "94.187.48.124",
  50.     "mail_file": "1532613012.Vfe00I184c16M637300.6d12ed72789c",
  51.     "delivered-to": [
  52.       [
  53.         "",
  54.         "root@localhost"
  55.       ]
  56.     ],
  57.     "urls": {
  58.       "body": [
  59.         {
  60.           "fragment": null,
  61.           "subdomain": "media",
  62.           "domain_without_tld": "smau",
  63.           "scheme": "https",
  64.           "domain": "smau.it",
  65.           "tld": "it",
  66.           "port": null,
  67.           "url": "https://media.smau.it/x-exhibition/upload/partner/2015/09/26/001-B1010-dwl02.jpg",
  68.           "resource_path": "/x-exhibition/upload/partner/2015/09/26/001-B1010-dwl02.jpg",
  69.           "host": "media.smau.it",
  70.           "query_string": null
  71.         },
  72.         {
  73.           "fragment": null,
  74.           "subdomain": null,
  75.           "domain_without_tld": "hanumaninternationalmission",
  76.           "scheme": "http",
  77.           "domain": "hanumaninternationalmission.com",
  78.           "tld": "com",
  79.           "port": null,
  80.           "url": "http://hanumaninternationalmission.com/yOegkh.html",
  81.           "resource_path": "/yOegkh.html",
  82.           "host": "hanumaninternationalmission.com",
  83.           "query_string": null
  84.         }
  85.       ]
  86.     },
  87.     "network": {
  88.       "is_filtered": false
  89.     },
  90.     "geoip": {
  91.       "ip": "94.187.48.124",
  92.       "region_code": "BA",
  93.       "city_name": "Beirut",
  94.       "timezone": "Asia/Beirut",
  95.       "country_code2": "LB",
  96.       "longitude": 35.5097,
  97.       "latitude": 33.8719,
  98.       "continent_code": "AS",
  99.       "region_name": "Beyrouth",
  100.       "country_name": "Lebanon",
  101.       "country_code3": "LB",
  102.       "location": {
  103.         "lon": 35.5097,
  104.         "lat": 33.8719
  105.       }
  106.     },
  107.     "return-path": "<security@intesasanpaolo.com>",
  108.     "x-mailer": "Microsoft Office Outlook 11",
  109.     "with_attachments": false,
  110.     "raw_mail": {
  111.       "is_filtered": false
  112.     },
  113.     "priority": 10,
  114.     "mime-version": "1.0",
  115.     "mail_server": "spamscope",
  116.     "sha256": "8aace268c4b2e3e2b9bcd957d28068d0efa3bd6139e947207d4906a48228452b",
  117.     "phishing": {
  118.       "score": 33,
  119.       "targets": [
  120.         "Intesa Sanpaolo Spa"
  121.       ],
  122.       "score_expanded": [
  123.         "mail_body",
  124.         "mail_from"
  125.       ],
  126.       "with_phishing": true
  127.     },
  128.     "md5": "814e9490109e5e21ef9d8d88f888f27c",
  129.     "message-id": "<003701d42500$05908673$9cc59c8e$@intesasanpaolo.com>",
  130.     "is_filtered": false,
  131.     "has_defects": false
  132.   }
  133. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement