← Back to list

PhishHunt Challenge from Hacktrace Ranges

Write-ups written by DRax / Hacktrace Ranges

Dimas Rizki · 2026-05-04 15:24 · 0 claps · 2.2 min read
#phishing #cybersecurity #securitylabs
Open on Medium ↗
Wiki topics: SOC · Sociology & Politics 🔒 · Cybersecurity

PhishHunt Challenge from Hacktrace Ranges

icon created by Hacktrace Ranges

icon created by Hacktrace Ranges

Write-ups written by DRax / Hacktrace Ranges

Labs Scenario

An employee from the Finance Division named Sarah is the target in this scenario. Sarah is an experienced accountant who often receives emails from various vendors, customers, and colleagues regarding the company’s financial transactions. These emails are very convincing and appear to be official emails from the bank. Please help Sarah ensure whether the email originates from an official bank source or not.

Introduction

To begin the challenge, download the file named PhishHunt.zip provided from Hacktrace Ranges on PhishHunt Labs. After extract the file, you will get PhishHunt.eml so this labs you will analyzing malicious emails. EML analyzer, Thunderbird Mail will help you to find the answer.

Step by step

Analyze the file on EML Analyzer so you can get more information. U will get hash SHA256 “f4f068ce78be6381eaaa55a7074d3770b6f175fa690527e9957a40dcddced8ff” to analyze on Virus Total

1) Please provide the sender’s email address

Answer :

2) Please provide the recipient’s email address!

Answer :

3) If the email recipient replies to the email, who will receive it?

Answer :

4) At what time was the email received by the recipient?

Format: DD MM YYYY HH:MM:SS +XXXX

Answer : 6 Jul 2023 08:19:21 +0000

5) What is the sender’s IP address?

Answer :

6) From which country does the sender’s IP originate?

after you got IP, you can track them or the clue is from sender mail “???.cn”

Answer : Canada

7) What is the name of the attachment file in the email?

Answer :

8) What are the names of the files inside?

Answer :

9) What is the original name of the file?

the clue is using ripmime

Answer :work in progress

10) What type of malware was the file detected as?

threat categories trojan

Answer : trojan

Keep it up and stay analyzing


메타데이터
post_id
f0ed2d6c8bcc
slug
phishhunt-challenge-from-hacktrace-ranges-f0ed2d6c8bcc
url
https://medium.com/@blurax12/phishhunt-challenge-from-hacktrace-ranges-f0ed2d6c8bcc
canonical_url
https://medium.com/@blurax12/phishhunt-challenge-from-hacktrace-ranges-f0ed2d6c8bcc
author_url
https://medium.com/@blurax12
status
ok
fetched_at
2026-07-13 06:23:13