Showing posts with label Email Forensics. Show all posts
Showing posts with label Email Forensics. Show all posts

Saturday, October 7, 2023

DIGITAL FORENSICS:Email header example

DIGITAL FORENSICS:Email header example

DIGITAL FORENSICS:Email header example

What is Email header?

An email header is a section of an email message that contains detailed information about the message's origin, transmission, and delivery. It is not typically visible to the recipient when reading the email in their inbox, but it can be viewed by accessing the email's properties or by examining the message's source code.

The email header typically includes the following types of information:

  1. From: The sender's email address.
  2. To: The recipient's email address(es).
  3. Subject: The subject line of the email.
  4. Date and Time: The date and time when the email was sent.
  5. Message ID: A unique identifier assigned to the email message by the email server.
  6. Return Path: The email address to which bounce-backs or non-delivery notifications are sent.
  7. Received: A series of entries indicating the email servers through which the message passed during transmission, including timestamps and server names.
  8. MIME-Version: The version of the MIME (Multipurpose Internet Mail Extensions) protocol used to format the email.
  9. Content-Type: Information about the type and format of the message content (e.g., text/plain for plain text, text/html for HTML content).
  10. X-Headers: Additional custom headers added by email servers or email clients for various purposes.

Email headers are essential for diagnosing delivery issues, tracing the path of an email message through the internet, and verifying the authenticity of an email. They provide valuable information for email administrators, forensic investigators, and individuals seeking to understand the journey of an email from sender to recipient.


DIGITAL FORENSICS:Email header example

Email Header Sample1

Download  (SHA-1: c7ddb3d355c770b0910ab35e7963751a90c7be01, Email header example.zip)

Email header example


Download (SHA1:b14f91b3150234db2122d05da231815d1cd4342a, email-header1.zip)

Email header example
 

Download , Mirror

(SHA-256: 42B6FD78DAF38C03E1A744ECA1A0CB44F6859AB892E0F32B01763EFD835B5648)

Download ,Mirror (SHA1:c233ce69a8412b680db883ff7e2813459c142eea, Email header example spoofed.zip)

Download Mirror (SHA1:338905820b6c75aba258f0c3f78d9289b31ed4e2, sample.zip)

DIGITAL FORENSICS:Email header example


Email Header Sample2

Email header example

Download

(SHA-256: a0b4b01357e4d83170729b67a19f697e6ad41f4d3c4cbc3e2b243af77630adb0)


Questions ?

1.Once you find the email sender's IP address, where can you retrieve more information about the IP?

Ans:
Hint:Whois

2.What is the sending email address (Email Header Sample2)?

Ans:
Hint:Return-Path  ,MXToolBox

3.Sender Ip address(Email Header Sample2)?


4. What is the email client or software was used to send an email.(Email Header Sample1)?

Ans:
Hint:Mobile

Creadit:
  • mailMeta 

 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Friday, February 19, 2021

Digital Forensics:แนวทางการตรวจสอบ E-Mail Header

Digital Forensics:แนวทางการตรวจสอบ E-Mail Header

ข้อมูล Email Header ที่เป็นประโยชน์

  • From:เก็บชื่อบัญชี Email ของผู้ส่ง
  • To: เก็บชื่อบัญชี Email ของผู้รับ
  • Subject:- เก็บหัวเรื่องของ Email
  • Date: เก็บวันเวลาที่อีเมลถูกส่ง
  • Message-ID: เก็บค่า ID ของ email  
  • Content: - เก็บค่ารูปแบบ email  
  • X-Mailer: เก็บค่าของซอฟต์แวร์ที่ใช้ในการส่ง Email
  • Received: เก็บค่าการส่ง email  ว่าถูกส่งผ่านที่ใดบ้าง
  • X-Originating-IP : IP address ของเครื่องที่ส่ง Email
  • Return-path: คือ บัญชีอีเมล์ต้นทาง (ผู้ส่ง)


ทั้งนี้จากรูปแบบการทำงานของ Email นั้นจะมีการบันทึกข้อมูลของช่องทางต่างๆ ที่ Email เดินทางมาถึงผู้รับ ตั้งแต่หมายเลขไอพีของผู้ส่งหรือหมายเลขไอพีของเครื่องเครื่องเซิร์ฟเวอร์ต้นทางที่ถูกใช้ส่งอีเมล  ข้อมูลต่างๆเหล่านี้จะปรากฎอยู่ในส่วนที่เรียกว่า  Email Header การใช้งานในกรณีปกติเมื่อผู้ใช้งานเปิดอ่านอีเมล จะไม่เห็นข้อมูลส่วนนี้แสดงออกมา  แต่พนักงานสอบสวนเปิดดูข้อมูลใน Email Header ได้   สามารถตรวจสอบเส้นทางสื่อสารของ Email หรือรู้ Email ที่แท้จริงของผู้ส่งEmailได้

เครื่องมือที่ช่วยในการวิเคราะห์ Email Header

1. Google Admin Toolbox Message header
 

 

2. iptrackeronline

3.  mxtoolbox

4. gaijin

แนวทางการตรวจสอบ E-Mail Header


Credit:ETDA Channel

 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป

ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD


Friday, January 8, 2021

Email Forensics: Metaspike CTF

Email Forensics: Metaspike CTF

วันนี้มาแนะนำการแข่งขัน Email Forensics CTF ซึ่งจัดโดยกลุ่ม Metaspike Community! กลุ่มเปิดให้ทุกคนพูดคุยเกี่ยวกับ digital forensics เข้าร่วมการสนทนาเพื่อแบ่งปันประสบการณ์คำแนะนำและเคล็ดลับและเรียนรู้จากผู้อื่น และมีจัดกิจกรรม Capture The Flag (CTF)  โดยกิจกรรมจะเปิดและปิดเป็นช่วง Jan- Feb 2021

Tools recommendations for the CTF

Text Editor

I strongly recommend using a capable text editor. My favorite is UltraEdit. Other good options are Sublime Text or Atom, possibly with some MIME syntax highlighters.

Conversions

I recommend using CyberChef for date and format conversions.

MAPI

When working with MSGs and PSTs, you can use MFCMAPI or OutlookSpy with Outlook.

General Metadata Extraction

You will likely need a general-purpose tool that can extract embedded files, file metadata, etc. Good candidates are X-Ways, Autopsy, or perhaps ExifTool or MetaDiver when you don’t feel like pulling out the big guns.

PDF Deep Dive

When you encounter PDFs, you will likely need a deep dive tool to look into them in detail. You can use PDF CanOpener (with Acrobat), PDF Stream Dumper, pdf-parser.py, etc.

ลองทำโจทย์ข้อ 1 Draft_Agreement.eml

(SHA-256: 42B6FD78DAF38C03E1A744ECA1A0CB44F6859AB892E0F32B01763EFD835B5648)

เป็นอีเมลปกติ ลงวันที่ 7 มีนาคม 2016 มีการสื่อสารระหว่าง Yahoo และ Gmail พร้อมไฟล์แนบ PDF
 ใช้ https://mxtoolbox.com ดู EML มีสองวิธีในการดูส่วนหัวของอีเมล  ทั้งในรูปแบบข้อความภายใต้“ ส่วนหัวของข้อความ” หรือแยกวิเคราะห์เป็นช่องภายใต้“ คุณสมบัติ” แต่เนื่องจากอีเมลอยู่ในรูปแบบ EML เราจึงสามารถดูได้ตามรูปที่แสดงผลลัพธ์ดังนี้
พบว่าในส่วนลายเซ็น DKIM   ซึ่งอาจจะไม่ถูกต้องก็ได้และ ใช้ในการตอบ 

ตอบ: F for Fack เป็นไปได้ว่าเป็นอีเมลที่ถูกปลอมขึ้น 


โจทย์ข้อที่ 2  ใช้ไฟล์จากโจทย์ข้อ 1  You will be examining the same email as in Part 1.

เราคิดอยู่แล้วว่าอีเมลนั้นหลอกลวง และเราทราบดีว่าเนื่องจากไฟล์นั้นเป็นไฟล์ EML จึงสามารถแก้ไขทุกอย่างที่อยู่ภายในอีเมลได้ โดยเฉพาะอย่างยิ่งการประทับเวลาที่ระบุได้ง่าย

หากเราดูการประทับเวลาทุกครั้ง เราจะเห็นวันที่มาตรฐานที่หลากหลาย รวมถึงการประทับเวลาแบบยูนิกซ์ การถอดรหัสทั้งหมดนั้นค่อนข้างเป็นการประทับเวลาเดียวกันและก็ผิดด้วย  

Mon, 7 Mar 2016 14:38:34 -0800 (PST)
Mon, 07 Mar 2016 14:38:34 -0800 (PST)
Mon, 07 Mar 2016 14:38:34 -0800 (PST)
Mon, 7 Mar 2016 22:38:33 +0000
Mon, 7 Mar 2016 22:38:31 +0000 (UTC)



Mon, 7 Mar 2016 22:38 Incorrect 

Email Forensics Workshop

 where we solved the first five challenges in Metaspike's Email Forensics Capture The Flag (CTF) competition. We covered topics such as:

• Examining emails in MIME format
• Message headers
• Leveraging DKIM and ARC
• Working with MAPI
• Investigating IMAP servers
• Server metadata
• Q&A


Creadit:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


Monday, December 8, 2008

Digital Forensics: Email Investigation

Digital Forensics: Email Investigation Part I.

เป็นงานแรกๆ ที่ admin  เริ่มทำ  โดยการหาข้อมูลจาก Email ว่าใครส่ง ส่งมาจากไหน ประเทศอะไร IP address อะไร บลาๆ

การสืบสวนหาผู้ส่งจดหมายอิเล็กทรอนิกส์ โดยวิเคราะห์จากอีเมล์เฮดเดอร์ (Email Header)
โดยทั่วไปการสืบสวนรวบรวมพยานหลักฐาน ในความผิดที่มีจดหมายอิเล็กทรอนิกส์ เข้ามาเกี่ยวข้องด้วยนั้น การวิเคราะห์ที่มาของจดหมายดังกล่าว นับเป็นขั้นตอนการดำเนินการหนึ่งซึ่งจะทำให้ผู้ทำการสืบสวน สามารถวิเคราะห์ได้ว่า จดหมายที่ถูกส่งมาจากผู้ส่งที่แท้จริงหรือไม่  หรือถูกปลอมแปลงโดยวิธีใด ซึ่้งนับเป็นส่วนสาระสำคัญต่อการสืบสวนเป็นอย่างยิ่ง
 
Email  Header เป็นส่วนหัวของอีเมล์  เป็นส่วนที่แสดงถึงรายละเอียดต่างๆของอีเมล์ ได้แก่ Message-ID: ของ E-mail (message header), วันที่และเวลาที่ส่ง, เซิร์ฟเวอร์ที่ใช้ส่งออกอีเมล์, ชื่อผู้รับ, ชื่อผู้ส่ง เช่น ข้อมูลเกี่ยวกับผู้รับ/ผู้ส่ง, IP ADDRESS, วันที่, เวลา EMAIL ที่คุณได้รับ บอกละเอียดถึงกับว่าถูกส่งมาจากคอมพิวเตอร์เครื่องใด รหัสเครื่องใด อย่างละเอียด ซึ่งรายละเอียดต่าง ๆ นี้จะไม่ปรากฏในเนื้อหาของ Email ทั่ว ๆ ไปที่เราเห็น  ส่วนหัวของอีเมล์(Email Header) ในแต่ละข้อมูลจะประกอบไปด้วยรายละเอียดดังต่อไปนี้

To: เก็บชื่อบัญชี Email ผู้รับ
Subject:- เก็บหัวเรื่อง
Date: เก็บวันเวลาที่อีเมลถูกส่ง
Message-ID: เก็บค่า ID ของ email จดหมายอิเล็กทรอนิกส์
Content: - เก็บค่ารูปแบบ email จดหมายอิเล็กทรอนิกส์
X-Mailer: เก็บค่าของซอฟต์แวร์ที่ใช้ในการส่ง Email จดหมายอิเล็กทรอนิกส์
X-Originating-IP : IP address ที่ส่ง Email จดหมายอิเล็กทรอนิกส์
Return-path: คือ บัญชีอีเมล์ต้นทาง (ผู้ส่ง)
Envelope-to: คือ บัญชีอีเมล์ปลายทาง (ผู้รับ)
Delivered-To: examplegolf@gmail.com เป็นการแจ้งว่าส่งเมลถึง Email account อะไร
Delivery-date: คือ วันที่และเวลาที่ข้อความอีเมล์มาถึงผู้รับ
Received: from ......... คือ ชื่อ Server ของผู้ส่ง และจะบอก IP Address ด้วยว่าต้นทางส่งมาจากที่ใด เก็บค่าส่งอีเมลว่าถูกส่งจากที่ใดบ้าง

ตัวอย่าง
#ผู้ส่งส่งจาก ip 171.101.200.246 : ซึ่งเป็น internet ของ TRUE ISP
Received: from cm-171-101-200-246.revip11.asianet.co.th ([171.101.200.246] helo=abc)
by ns.packetlove.com with esmtpa (Exim 4.84)
(envelope-from )
id 1aXRW2-00076Q-4a

SPF Record หรือ Sender Policy Framework คือ ค่าที่ระบุ Server email ที่ได้รับอนุญาติให้ส่ง email ในนาม Domain ผู้ส่งซึ่งจะระบุเป็น IP Address ของ mail server

ตัวอย่าง
#google.com ทำการเชค SPF ของ domain : systems.co.th เรียบร้อยอนุญาตให้รับเข้ามาได้
Received-SPF: pass (google.com: domain of abc@systems.co.th designates 103.246.123.123 as permitted sender) client-ip=103.246.123.123;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of abc@systems.co.th designates 103.246.123.123 as permitted sender) smtp.mailfrom=abc@systems.co.th;

dkim=pass header.i=@systems.co.th


DKIM ย่อมาจากคำว่า Domain Keys Identified Mail ซึ่งตัว feature นี้จะเอาไว้คล้ายๆ เซ็นต์ลายเซ็นต์ของอีเมลเรา แล้วส่งออกไป เพื่อป้องกันการปลอมแปลงอีเมลในขาส่งออก โดยทางเซิฟเวอร์ปลายทางจะทำการตรวจสอบได้ โดยอาศัยการใช้ ลายเซ็นต์สาธารณะ

ตัวอย่าง 
# มีการ DKIM สำหรับ domain keys systems.co.th อย่างถูกต้อง
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=systems.co.th; s=x;
h=Content-Type:MIME-Version:Message-ID:Date:Subject:To:From; bh=WHJu+w3CuK2R;

b=fxoHVMzttU;

ตัวอย่าง 
#มีการรับอีเมลเข้ามาโดย IP 10.55.145.7 วันที่ 21 Feb 2016 , เวลา 02:45:31 ในส่วนของ timezone -0800 (PST) ถ้ามองให้เป็นเวลา (ICT) +0700 ต้องทำการ จะเท่ากับ
### +1500 -0800 = +0700 นะครับในกรณีนี้จะเป็น 02:45:31 + 15hr = 17:45:31 (ICT) เวลาไทยๆครับผม
Received: by 10.55.145.7 with SMTP id t7csp712793qkd;
Sun, 21 Feb 2016 02:45:31 -0800 (PST)
X-Received: by 10.66.62.134 with SMTP id y6mr30397395par.43.1456051531356;

Sun, 21 Feb 2016 02:45:31 -0800 (PST)

วิธี View Source เพื่อดู Header ของอีเมล์



ตัวอย่าง Email  ที่ส่งมาจาก google



ตัวอย่าง Spam 
เป็น Spam ที่ปลอมว่ามาจาก Samsung ส่งมาแต่  Message-ID เป็นของที่ไหนก็ไม่รู้ @localhost.localdomain

ทำการ Lookup ค่า SPF IP address   พบว่าเป็น IP ของ amazonaws.com

รายละเอียดเหล่านี้จะมีการบันทึกข้อมูลที่อีเมลเดินทาง จะอยู่ใน E-Mail Header

 E-mail and Social Media Investigations





อ่านเพิ่มเติม  Digital Forensics: Email Investigation Part II.


ที่มา:
 https://bit.ly/2c0XTda
https://bit.ly/2Ja5t3D

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

 

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...