This is a continuation of Phishing Investigations, Part 3. If you are new here, you can start at the beginning.
Researching the email links
When I analyzed each of the phishing emails in my folder last time, one of the things I noticed was that every email contained a link I was supposed to follow to “view the pictures” offered in the subject. In every case, the link was unique and contained a unique domain name. As I wrapped up the last article, I decided to research those links to see what I could find.
To begin my research, I used three free websites that are helpful for this type of work:
For each email, I checked the link and the domain extracted from it on all three websites. I did not open the suspicious links directly in my browser, and I am not sharing the real links or domains here. Full phishing URLs can contain personal or victim-specific tracking information. It is also important to know whether a service is only searching existing records or submitting a new public scan before entering a suspicious URL.
Each one returned no useful results:
- No current DNS resolution
- No useful public ICANN/RDAP record
- No meaningful VirusTotal history
- No usable urlscan history
- No meaningful search-engine footprint
My working theory is that the campaign may use short-lived, disposable web infrastructure. Each message uses a unique lure domain, and the domains were already non-resolving by the time I checked them, leaving no useful public DNS, registration, scanning, or indexed footprint that I could find.
However, the missing results do not prove that theory. Public tools do not contain everything, registration information can be hidden or unavailable, and a domain might never have been scanned before it stopped resolving. The safest conclusion is simply that I found no useful public record when I checked.
Unfortunately, that does not give me many clues to move forward, but there are still plenty of things I can investigate, including domain-naming patterns, sender organization types, infrastructure countries, Microsoft tenant and mail-routing clues, message timing and cadence, subject and lure construction, and URL structure. These things might help me understand how the system is automated even though the link infrastructure appears to be gone.
The next thing I am going to do is take a closer look at the sender domains and the Microsoft-related mail information in the headers. I will investigate what public information is available about the sender domains, including whether they appear connected to personal or business services and what infrastructure countries appear in the records. A country connected to a domain, server, or data center does not necessarily reveal where the person sending the email is physically located, so I will treat that information as an infrastructure clue rather than proof of the sender’s location.
I will also look at the timing of the emails to see if there is a pattern that might be helpful.
See you next time.
