This is a continuation of Phishing Investigations, Part 5.
So, in the last part of the investigation, we ended while I was searching for information about the email addresses sending me the suspicious links to view photos.
I searched each of the 17 email addresses three ways.
First, I searched for each full email address in quotation marks, using this made-up example:
"unknown.sender@example.com"
This search asks whether that exact address has appeared in a publicly indexed source. Finding it would be a useful clue, but it would not prove that the mailbox was genuine or that its apparent owner sent the messages. Email addresses can be copied, spoofed, or connected to compromised accounts.
Next, I searched for the username and organization separately, using a search like this:
"unknown.sender" "example.com"
I used this because exact email addresses are often not indexed, even when a person and organization are public. This loosens the search while still looking for both pieces. It asks, essentially, “Does this username appear to be connected with this organization even if the site does not publish the full email address?” Once again, a match would be a clue, not proof of identity or responsibility.
Finally, I searched the full email address with the word phishing, using a search like this:
"unknown.sender@example.com" phishing
This tests whether someone else has reported that address as abused, compromised, or connected with suspicious email. A result could show that the address had been mentioned before, but I would still need to evaluate the source and consider whether the address had been spoofed or the account compromised.
After applying these searches to all 17 email addresses, I found only one clue: a real name appeared in one of the addresses.
Unfortunately, after checking the public search results associated with that name, including professional-networking and social-media profiles, I did not find any clear evidence that the person sent the emails or was connected with the organization the messages appeared to come from. I did not contact anyone, publish the name, or treat a profile match as proof. I was essentially back at the beginning.
Next, I searched the exact email text without the link to see whether there were any matches. I looked for phrases that included:
- “We’ve been meaning to send these two images way sooner”
- “These pics should ring a bell”
Again, I found nothing.
The next thing I will do is start looking at the organizations and domains tied to the email addresses. In the made-up example above, that would be the example.com part of the address. I will look for credible reports that the domains or organizations have experienced compromised accounts or phishing abuse. Even if I find such reports, they will be leads to examine—not proof that an organization intentionally sent these messages or that the same person was responsible.
We’ll talk about what I find in the next article.
See you next time!
