Skip to content

thekage404/phishing-mail-forensics

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 

Repository files navigation

EMAIL FORENSICS INVESTIGATION REPORT


Report ID: MFR-S001 Report Date: 22-03-2026 Investigated By: Subhadeep Chakraborty Investigation Period: 21-03-2026 to 22-03-2026


1. Executive Summary

This report documents the findings of a digital forensics investigation into a suspected phishing email to compromise banking credentials of legitimate clients. The mail originates from US impersonating Bradesco Bank of Brazil to gather credentials. The mail's subject line implies urgency by notifying the user to immediately redeem expiring 92,990 points on the card.

Analysis of the mail headers, attachments and metadata indeed indicates that the mail did not originate from the bank's original infrastructure. The sender spoofed the mail structure of the actual Bradesco Bank (Brazil).

Conclusion: The mail was an mass phishing campaign targeted towards the legitimate clients of Bradesco Bank (Brazil) to compromise banking credentials.


2. Scope and Objective

2.1 Objective

  • Identify the true origin of the mail.
  • Extract IOC's, artifacts and evidences from the mail header, body and attachment(s).
  • Preserve artefacts in a forensically sound manner using hashes.

2.2 In-Scope

  • The .eml phishing mail including headers, body and attachments.
  • Domains and IP addresses part of the attacker's infrastructure.

2.3 Out of Scope

  • Third-party cloud IP's being part of the campaign.
  • Personally identifiable indicators of the users, if mentioned within the mail.

3. Methodology & Tools

3.1 Evidence Acquisition

The original mail was gathered from phish-tank's public phishing repository hosted on github. A SHA-256 hash of the .eml file was created to preserve the original contents of the file and to prevent modifications of the original file.

3.2 Hash Verification

File SHA-256 Hash
banking_phishing_campaign.eml aa54196256075340e18adb9a85f24a0e33612faf33dd06d38a59334bf1130634

3.3 Tools Used

Tool Version Purpose
MXToolbox Header Analysis Online Email header analysis
VirusTotal Online URL & attachment analysis
WHOIS (ICANN) Online Domain & IP lookup
Cyberchef Online SHA-256 hashing and decrypting
Claude Sonnet 4.6 Report outline & formatting

4. Evidences & Artefacts

4.1 Email Overview

Field Value
From (spoofed) banco[.]bradesco@atendimento[.]com[.]br
Actual From (Return-Path) root@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (Mis-configured VPS)
Sender's IP 137.184.34.4
To phishing@pot
Subject (English Translation) PRIME CLIENT - BRADESCO LIVELO: Your card has 92,990 LIVELO points expiring today!
Date Tue, 19 Sep 2023 18:35:49 +0000 UTC
Message-ID 20230919183549.39DEA3F725@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06

Note: The IP address (137.184.34.4) is part of DigitalOcean's ASN14061 of 137.184.00/16 CIDR network range. Domain lookup indicates that the domain (atendimento[.]com[.]br) was registered on 20-09-2018 19:21:39 UTC under the email kaerjek@yahoo[].com[.]br.


4.2 Email Header Analysis

The full raw headers are reproduced in Appendix A. Key findings are summarized below.

4.2.1 Received Chain

Received: from SA3PR19MB7370.namprd19.prod.outlook.com (::1) by
 MN0PR19MB6312.namprd19.prod.outlook.com with HTTPS; Tue, 19 Sep 2023 18:36:46
 +0000
 
Received: from BN0PR03CA0023.namprd03.prod.outlook.com (2603:10b6:408:e6::28)
 by SA3PR19MB7370.namprd19.prod.outlook.com (2603:10b6:806:317::17) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.27; Tue, 19 Sep
 2023 18:36:45 +0000
 
Received: from BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
 (2603:10b6:408:e6:cafe::23) by BN0PR03CA0023.outlook.office365.com
 (2603:10b6:408:e6::28) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.28 via Frontend
 Transport; Tue, 19 Sep 2023 18:36:45 +0000
 
Authentication-Results: spf=temperror (sender IP is 137.184.34.4)
 smtp.mailfrom=ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06; dkim=none (message not
 signed) header.d=none;dmarc=temperror action=none
 header.from=atendimento.com.br;compauth=fail reason=001
 
Received-SPF: TempError (protection.outlook.com: error in processing during
 lookup of ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06: DNS Timeout)
 
Received: from ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (137.184.34.4) by
 BN8NAM11FT066.mail.protection.outlook.com (10.13.177.138) with Microsoft SMTP
 Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
 15.20.6813.19 via Frontend Transport; Tue, 19 Sep 2023 18:36:44 +0000

The email was sent from the IP 137.184.34.4. This IP is associated with DigitalOcean's 14061 ASN and is flagged as malicious by 1/91 VirusTotal security vendors. (see Section 4.3).

4.2.2 SPF / DKIM / DMARC Results

Check Result Detail
SPF FAIL atendimento.com.br has no published SPF record
DKIM NONE No DKIM signature found
DMARC FAIL No DMARC policy on spoofed domain; alignment failed against atendimento.com.br

All three authentication mechanisms failed, confirming the email did not originate from Bradesco Bank's authorized mail infrastructure.

4.2.3 Display Name Spoofing

The From: header used the display name BANCO DO BRADESCO LIVELO translating to BANK OF BRADESCO LIVELO with a fraudulent domain. Many email clients show only the display name to end users, making this deception effective to casual inspection.


4.3 Sending IP & Domain Analysis

IP Address: 137.184.34.4

Attribute Detail
ASN AS 14061 (DigitalOcean, LLC)
Geolocation United States
Abuse contact abuse@digitalocean.com

Domain: atendimento.com.br

Attribute Detail
Registrar Hostgator.
Registered On 09-12-2018
Registrant REDACTED
Name Servers ns822.hostgator.com.br, ns823.hostgator.com.br
MX Record mail.atendimento.com.br

4.4 Embedded URL Analysis

The email had an embedded URL foe the register button: https://blog1seguimentmydomaine2bra.me

Attribute Detail
Full URL https://blog1seguimentmydomaine2bra.me
Host Can't be confirmed (Offline)
Protocol HTTPS (encrypted)
VirusTotal Not Flagged
URL Status Not active at the time of investigation

5. Findings

  1. The email was intended to spoof Bradesco Bank of Brazil, and was targeted towards legitimate clients of the bank to compromise their credentials.

  2. The faked sender's domain atendimento.com.br being entirely different from the actual bank's domain with no attempt of domain masking - indicates an amateur attacker.

  3. The email attempts to raise urgency by notifying the clients of expiring credit points, using the subject line "PRIME CLIENT - BRADESCO LIVELO: Your card has 92,990 LIVELO points expiring today!"

  4. The IP address 137.184.34.4 associated with the sender's mail is registered with DigitalOcean's ASN range in San Francisco implying a temporary an easy to replace infrastructure.

  5. No attempts were made to spoof or bypass the spam-filtering and content-integrity checks for both the mail authentication and Microsoft's spam filters.

  6. The phishing domain used in the register button's link blog1seguimentmydomaine2bra.me is absolutely different and doesn't even attempt to match the actual bank's domain - again indicating an amateur attacker.

  7. At the time of investigation the domains - both including the sender's and the email body are offline and has not been changed since 2025 (Register button's domain).


6. Conclusion

The investigation concludes with high confidence that the email was an bulk phishing campaign targeted towards the legitimate clients of Bradesco Bank. The external attacker relied on cloud infrastructure to setup and send mails from an incomplete configuration as implied by the missing Return-Path field of the mail headers. During the time of investigation the domains associated with the attacker are not online and neither are they updated/changed after 2025 (As per the WHOIS registration information).

Recommendations:

  1. Report the fraudulent domains to Namecheap or other phishing report website.
  2. The IP address associated with the attacker should be reported to the DigitalOcean for phishing attempt.
  3. The bank should conduct an phishing awareness programme for its clients to better differentiate such attacks in the future.

Appendices

Appendix A - Full Raw Email header

Received: from SA3PR19MB7370.namprd19.prod.outlook.com (::1) by
 MN0PR19MB6312.namprd19.prod.outlook.com with HTTPS; Tue, 19 Sep 2023 18:36:46
 +0000
Received: from BN0PR03CA0023.namprd03.prod.outlook.com (2603:10b6:408:e6::28)
 by SA3PR19MB7370.namprd19.prod.outlook.com (2603:10b6:806:317::17) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.27; Tue, 19 Sep
 2023 18:36:45 +0000
Received: from BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
 (2603:10b6:408:e6:cafe::23) by BN0PR03CA0023.outlook.office365.com
 (2603:10b6:408:e6::28) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.28 via Frontend
 Transport; Tue, 19 Sep 2023 18:36:45 +0000
Authentication-Results: spf=temperror (sender IP is 137.184.34.4)
 smtp.mailfrom=ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06; dkim=none (message not
 signed) header.d=none;dmarc=temperror action=none
 header.from=atendimento.com.br;compauth=fail reason=001
Received-SPF: TempError (protection.outlook.com: error in processing during
 lookup of ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06: DNS Timeout)
Received: from ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (137.184.34.4) by
 BN8NAM11FT066.mail.protection.outlook.com (10.13.177.138) with Microsoft SMTP
 Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
 15.20.6813.19 via Frontend Transport; Tue, 19 Sep 2023 18:36:44 +0000
X-IncomingTopHeaderMarker:
 OriginalChecksum:3B61F64750F88C5569DF38A496B2374685F23D8BC662A6A19B6823B2F6745D54;UpperCasedChecksum:62071BC7A7CF5B0844A7B406B0E9EFCDAA2CB94988E687CF8C56555AD4B52D30;SizeAsReceived:544;Count:9
Received: by ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06 (Postfix, from userid 0)
	id 39DEA3F725; Tue, 19 Sep 2023 18:35:49 +0000 (UTC)
Content-type: text/html; charset=UTF-8
Content-Transfer-Encoding: base64
Subject: CLIENTE PRIME - BRADESCO LIVELO: Seu cartão tem 92.990 pontos LIVELO expirando hoje!
From: BANCO DO BRADESCO LIVELO<banco.bradesco@atendimento.com.br>
To: phishing@pot
Message-Id: <20230919183549.39DEA3F725@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06>
Date: Tue, 19 Sep 2023 18:35:49 +0000 (UTC)
X-IncomingHeaderCount: 9
Return-Path: root@ubuntu-s-1vcpu-1gb-35gb-intel-sfo3-06
X-MS-Exchange-Organization-ExpirationStartTime: 19 Sep 2023 18:36:44.2236
 (UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
 b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic:
 BN8NAM11FT066:EE_|SA3PR19MB7370:EE_|MN0PR19MB6312:EE_
X-MS-Exchange-Organization-AuthSource:
 BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-UserLastLogonTime: 9/19/2023 6:25:15 PM
X-MS-Office365-Filtering-Correlation-Id: b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 137.184.34.4
X-SID-PRA: BANCO.BRADESCO@ATENDIMENTO.COM.BR
X-SID-Result: NONE
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-SCL: 5
X-Microsoft-Antispam: BCL:9;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Sep 2023 18:36:44.1298
 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b9106deb-bd54-4815-e5c9-08dbb93f5fab
X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-AuthSource:
 BN8NAM11FT066.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg:
 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA3PR19MB7370
X-MS-Exchange-Transport-EndToEndLatency: 00:00:02.6179349
X-MS-Exchange-Processed-By-BccFoldering: 15.20.6792.025
X-Microsoft-Antispam-Mailbox-Delivery:
	wl:1;pcwl:1;ucf:0;jmr:0;ex:0;psp:0;auth:0;dest:I;OFR:TrustedSenderList;ENG:(5062000305)(920221119095)(90000117)(920221120095)(91040095)(9050020)(9075021)(9100341)(944500132)(2008001134)(4810010)(4910033)(9610028)(9560006)(10180021)(9439006)(9310011)(9220031)(120001);
X-Message-Info:
qZelhIiYnPlgo3oeAkqKQrb/Je8fpvpPmRGjYwLej8PYXc5p/l16IG5I8gDUPoij+JWSvja0BAMLtkgrOcbx5zEN7V98T2UZUZs4k8BX/DcDfI7QJ0t2aouiqx4ENvkR1M3sDKP/XN09+50x9Rxi6onUtDV4eqq36VUi2qAa0zCzkJwjdl3Y9DzNE1OkaWjrHAizeUyMZ/UtK/Pz9zhA2A==
MIME-Version: 1.0

Appendix B - VirusTotal Scores

  • atendimento[.]com[.]br - 1/91 (Phishing)
  • 137.184.34.4 - 1/91 (Malicious) + 2 Suspicious Flags

Appendix C - WHOIS Lookup Data

domain:      atendimento.com.br
owner:       Maximilian Gregory Peisker Lacerda
ownerid:     ***.658.560-**
country:     BR
owner-c:     MGPLA3
tech-c:      MGPLA3
nserver:     ns822.hostgator.com.br
nsstat:      20260512 QREFUSED
nslastaa:    20230917
nserver:     ns823.hostgator.com.br
nsstat:      20260512 QREFUSED
nslastaa:    20230917
saci:        yes
created:     20180920 #18801717
changed:     20250822
expires:     20270920
status:      published

nic-hdl-br:  MGPLA3
person:      Maximilian Gregory Peisker Lacerda
e-mail:      kaerjek@yahoo.com.br
country:     BR
created:     20151209
changed:     20250115

End of Report - MFR-S001 Investigation By - Subhadeep Chakraborty | Date: 22-03-2026

About

Forensics investigation of real-world phishing mails

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

No releases published

Packages

 
 
 

Contributors