Phishing Investigations, Part 2: Sorting the Spam Messages

32 Hertz SOC Global Guardians logo

Written by

in

This article continues Phishing Investigations, Part 1, where I described how I began collecting suspicious messages for safe analysis.

Sorting the Spam Messages

After reviewing approximately 120 spam emails by hand, I was surprised—and somewhat relieved—to find that only about 17 appeared questionable enough to justify a deeper investigation. Most of the remaining messages were advertisements, unwanted marketing, or other low-value mail.

This does not mean the 17 messages have already been proven malicious. At this stage, they are simply suspicious messages that need to be classified and investigated carefully.

Most of them fit into one of two patterns:

  1. A sender claiming to be someone who worked with me many years ago when I was a line cook. The sender knew the correct restaurant and claimed to have old photographs that I needed to see.
  2. Messages claiming to come from Gmail and warning that I would lose my account and access to my email unless I followed a set of instructions.

Both campaigns looked convincing enough to deserve further review, so I separated them into two groups for investigation.

The “John Doe” Campaign

I began with the former-coworker messages because they appeared to be aimed at me personally and included information about someone I really knew. I will use the name “John Doe” throughout this project to protect the person’s identity. Nothing at this stage proves that the real person had any involvement in the messages.

How Did the Campaign Connect Me to an Old Coworker?

I started by searching my email history to see whether I had ever exchanged messages with the real John Doe. If I had, a compromised mailbox or address book could have been one possible explanation. I also hoped to find a trusted email address so I could warn him and ask whether he had received similar messages.

However, I found no past email conversation with him and did not have a verified way to contact him.

I am still in regular contact with another former employee from the same restaurant, so I asked whether she had received similar messages. She said she had not received messages using John Doe’s identity, but she had received repeated messages claiming to come from another former coworker, whom I will call “Jane Doe.”

She correctly chose not to open attachments, download files, or interact with the messages. Because I could not examine the original messages or their headers, I can treat her report only as supporting information—not confirmed technical evidence.

It was interesting that the messages sent to me used the identity of a man while the messages sent to her used the identity of a woman. However, that detail alone does not prove the campaigns came from the same source.

Developing a Working Hypothesis

The reports suggest that someone may be using information that connects several former restaurant employees. One possible source is old social-media content, such as public Facebook posts, tags, friend connections, or data collected through scraping.

That is only a hypothesis. Other possibilities include a compromised address book, a breached account belonging to someone in the group, an old contact database, or information gathered from multiple public sources.

A good investigation should separate observations from assumptions. At this point, I know that the messages reference real relationships and that another former employee reported a similar pattern. I do not yet know who sent the messages, how the relationships were discovered, or whether the two campaigns share the same operator.

What Comes Next

The next step is to examine the saved messages themselves. I will review their headers, sender domains, Reply-To addresses, authentication results, links, and other indicators that may help identify how the campaign works.

Any personal information will remain private, and conclusions will be based on evidence rather than speculation.

See you in Part 3.