June 17, 2023
Unmasking the Shadows: A Deep Dive into Phishing and Spam in My Decade-Old Email Account
Join me as I analyse 5 Suspicious Emails from my Decade-Old Email Account.

By Joshua Clarke
13 min read
Note: This is my first post! I am not a writer, yet here I am. Let's see how this goes! If you like it, maybe I will write some more.
Introduction
So I have had a Hotmail account for over 10 years, it's been subject to many breaches and it receives hundreds of phishing and spam emails every single day. I was thinking that with everything this account has been through wouldn't it be interesting to dive into this old email account and analyze some of the phishing and spam emails? Maybe we can even report some of our findings along the way, and potentially disrupt some of these malicious operations.
The tools that I will be using in this post:
Securing The Account
Despite appearing in 24 breaches, the account has never been compromised. I put this down to always having Multi-Factor Authentication enabled and the outdated nature of leaked passwords from previous breaches. That being said the account was still subject to hundreds of login attempts every single day. (You can check for login activity on your account here: Microsoft Recent Activity Page)
Given the persistent login attempts on my account, I wanted to make it impossible for someone to access my Microsoft account via the leaked email address, while still allowing me to receive emails and log in to my Microsoft account. This is where aliases come into play. Microsoft offers the option to create multiple aliases for a single account. For example, if your account is JoeBloggs@hotmail.com, you can create an additional alias such as JoeBloggsMain@outlook.com or even a username like joe_blogs. (You can manage aliases here: https://account.live.com/names/manage).
Microsoft also provides a convenient option to disable sign-in for specific email addresses, so once you have aliases set up, you can disable sign-in for the leaked email address but continue to access your emails and Microsoft account through your new alias. (You can disable sign-in here: https://account.live.com/SignInPreferences.) This makes your leaked email address useless for anyone trying to sign in to your Microsoft account.
Configuring Sublime Text
If you open email headers in a fresh install of sublime text it will render as plain text:
However thanks to a little package created by Richard Davis over at 13cubed. We can easily parse the headers to get some nice syntax highlighting. (https://github.com/13Cubed/EmailHeader)
- With sublime text open, press the shortcut SHIFT+CTRL+P to open up package control and click on "Install Package":
- Search for "Email Header":
- Click to install the package.
You will now see that the content type has changed to "Email Header" and now, as if by magic, all of the headers will be highlighted for you. Thanks 13cubed:
Email 1: Prime Video Account Activity On-Hold
Most people should recognise this as a malicious email straight away:
- The sender name "Prime Video" does not match the email address "required-119340[at]fepcts.oakvillevideoconferencing.com"
- The subject line tries to imply urgency "Reminder: Account activity on-hold [ Payment renew required ] Saturday, 10 June 2023 (UTC-7)"
- The body has no context: "# Case -FU77U765334 "Recovery Reminder"
- The attachment is from an unknown sender and has a generic name: "User-Receipt"
Dropping the file into VirusTotal we can see that it is undetected by AV:
1.1 Opening the PDF file
Note: Don't try this at home! Unless you know what you are doing and have an appropriate secure environment to do so.
When I opened the file in my secure environment, I couldn't help but notice that it looked more put together than the email. But boy, did it fall short when I actually read what it had to say:
- Spelling Mistakes: Right off the bat, I spotted a bunch of spelling mistakes in the document. Seriously, it made me question if the person behind it even owns a dictionary. Legitimate organizations usually pay attention to these things and make sure their stuff is error-free.
- Generic Greeting: Instead of addressing you by your name or something specific, they went with a super generic "Dear Customers." Ugh, talk about impersonal. This is a classic move by phishers who want to cast a wide net without actually knowing who you are. Legit emails usually use your name or provide some personal info.
- Lack of Real Information: So here's the kicker — the document didn't have any real info at all. It was just a bunch of fluff with a sketchy link thrown in. Legit emails give you actual details about your account or something specific to make it seem legit. This one was just begging for you to click on that link.
Bottom line, I advise you to be super careful with these kinds of files. Phishers love playing these tricks to fool people and get their hands on sensitive info. Always double-check the legitimacy of documents, emails, or links, especially if they have these warning signs. Don't let them reel you in!
When I looked into the link behind the "Continue" button (in my secure environment), it redirected me to a Google Drawings link. But, guess what? The link had already been taken down. Nightmare! Our little adventure with this phishing attempt came to an abrupt end. However, it's reassuring to know that Google was quick to take action against this malicious actor.
Email 2: Urgent: [SECURITY CHANGER] Login Detect Your Account
Another obvious one here:
- From Address: The email is sent from the domain "c948ud5.jpbaaic.allrisk.com.pe," which does not appear to be associated with the company mentioned in the email.
- Email Content: The subject line is designed to create a sense of urgency by mentioning "Urgent" and "SECURITY CHANGER." This tactic is often used by scammers to manipulate recipients into taking immediate action without questioning the email's legitimacy. The email has no body other than an unsolicited PDF.
- Unfamiliar Domain: The domain in the "To" address, "zseabff5w3st84onukdh.com" is not recognizable and appears suspicious. Legitimate companies typically use their own domain or well-known email service providers.
- Filename: The email has an attached PDF document named "apx-termcondt_amz18487415.pdf". As we know attackers sometimes use PDF attachments to deliver malware, trick recipients into opening malicious files, and to visit phishing sites.
2.1 Opening the PDF file
Note: Don't try this at home! Unless you know what you are doing and have an appropriate secure environment to do so.
Are you noticing a pattern here? I am! Another PDF designed to get you to click out to an external site.
The PDF has similar characteristics to the ones we discussed before:
- Spelling Mistakes.
- Generic Greeting.
- Lack of Real Information (with a goal of getting you to click a link).
This attachment has no security vendor hits in VirusTotal, but does have 1 sandbox hit as "Greyware":
Interestingly, the link here is for LinkedIn:
To gain insight into this phishing tactic, a quick search will reveal an article by Krebs on Security from last year (you can find it here: https://krebsonsecurity.com/2022/02/how-phishers-are-slinking-their-links-into-linkedin/). The article highlights how phishers have been capitalising on LinkedIn's slinking feature to disguise their malicious links. By leveraging the trust associated with LinkedIn, scammers exploit unsuspecting users and trick them into visiting harmful websites.
Popping the link into URLScan we can see where the redirect ends up:
Oh no! That site is down as well, so we can't go any further. Let's see if we can find anything fresher.
Email 3: MetaMask Deactivated Account
MetaMask is a cryptocurrency wallet and browser extension.
There are a few suspicious aspects of this email that you should be cautious about:
- Sender's email address: The sender's email address is "kewellysanne@jrj[.]cl" which does not appear to be an official email address associated with MetaMask. Legitimate emails from MetaMask would typically come from an official domain, such as "@metamask[.]io." The email domain "jrj[.]cl" seems to be unrelated to MetaMask.
- To email address: The actor has set the "to" line to "noreply@Ꮇеtаmаѕk[.]io" to make the email appear more legitimate and increase the chances of deceiving the recipient. By using an email address that resembles the official domain of MetaMask ("@metamask[.]io"), they aim to trick the recipient into believing that the email is genuinely from MetaMask. However, it is actually from the "jrj.cl" domain and my email is likely included in the BCC line.
- Poor formatting and Cyrillic Characters: The formatting of the email is inconsistent and contains strange characters. For example, the letter "a" in "MetaMask" is replaced with the character "а" (U+0430 Cyrillic small letter a), and the letter "e" in "MetaMask" is replaced with the character "е" (U+0435 Cyrillic small letter e). Cyrillic characters are often used as an attempt to bypass email filters.
- Urgent request: The email claims that your account needs to be deactivated permanently due to your country's regulations. Scammers often use urgency and fear tactics to manipulate recipients into taking immediate action without thinking. It is unusual for a legitimate service provider like MetaMask to request the permanent deactivation of an account via email without any prior notice or opportunity to resolve the issue.
- Suspicious attachment: The email mentions an attached PDF file that supposedly contains details about the problem. Exercise caution when opening attachments from unknown or suspicious sources, as they can potentially contain malware or phishing attempts. It is advisable not to download or open such attachments unless you are certain about their legitimacy.
3.1 Opening the PDF file
Note: Don't try this at home! Unless you know what you are doing and have an appropriate secure environment to do so.
"Your METAMASK is disable" — I think you mean to say disabled. Here's another example of a really suspicious attachment:
- Spelling and grammatical mistakes.
- Sense of urgency to create fear.
- Lack of specific details.
- Aims to get the reader to click on a link.
This attachment has no hits in VirusTotal:
Let's take a look at that link:
We can see that the page is running on Google's App Script service, this leans on the reputation of Google to make unsuspecting users trust the webpage.
Let's get this reported to Google, if anyone knows a better place to report abuse to Google, please let me know:
Looking at the code here we can see that this "reCAPTCHA" is actually just a link to another site:
Oops it looks like this site is currently down, maybe I can revisit this email later:
Email 4: Next of Kin
My inbox is flooded with emails like this, all claiming that I'm sitting on a goldmine without providing any proof. You know the ones — emails that want you to reply ASAP before they drop the bombshell: "Send us some cash and we'll shower you with riches!" It's like a never-ending game of cat and mouse with these sneaky scammers.
Before you count that money let's look at what is wrong with this email!
- Sender's name and email address: The name "Smith Adams" sounds really generic and quite frankly made up! (sorry if that is your name). The email account here is "support@smpn1wirosari[.]sch[.]id", that doesn't match the name, does it? More on this later.
- Subject: "Hello" — Do I need to say anymore? If this is genuinely someone with a client, don't you think the email would be a little more professional?
- Attempt to Establish Trust: The email attempts to build trust by mentioning that you share the same last name as their late client. But what is that last name? Why not include it in the email? Scammers commonly use this technique to establish a false sense of familiarity and credibility, despite actually giving no real information.
- Poor Grammar and Wording: Now I don't claim to be any good at grammar, in fact, I would say I'm not great at it at all! This is either a sign that the sender isn't fluent in English or that the email was hastily written. I mean, if someone is representing a client, shouldn't we expect a bit more attention to detail? Come on Smith, you can do better!
Email 4 — Let's dig into that domain a little
The domain "smpn1wirosari[.]sch[.]id" ends with ".id", which is the country code top-level domain (ccTLD) for Indonesia and ".sch+[ccTLD]" is normally associated with schools in the given country.
Searching the domain in Google gives us a hit for a website:
Using Google Translate I can see that this does indeed appear to be a School:
Let's throw the URL into URLScan.io to see what it looks like:
It looks like a legitimate Indonesian School WordPress site, a quick Google search shows us that it's a real place. You know with a building and everything.
So why is a School in Indonesia sending me a spam email? Well, the likelihood is it's not! Spammers often use hacked email accounts to send out their spam for a number of reasons, including but not limited to:
- It looks legit: By using real accounts, their emails seem trustworthy (obviously not in this case, but that's the idea).
- They dodge filters: Hacked accounts can often bypass spam filters, allowing them to successfully reach inboxes.
- It protects their reputation: Simply because spamming from their own servers can get them blacklisted.
- Trust with contacts: Accessing an established email address will often give them a list of existing contacts and these contacts are much more likely to expect emails from the established email address. This can lead to more people falling for the scam emails.
Looking at the Email Headers for this email we can see that it has X-AntiAbuse, these are typically added to emails that are sent by PHP scripts to help identify any abuse. In this case we can see an interesting header that gives us a good idea of what has happened here:
This email header tells us that we have an email that was sent with a PHP Script located in the directory "/public_html/wp-content/plugins". Guess what? The most common source of vulnerabilities in a WordPress site is outdated plugins and themes!
Given that the site is running on HTTP, not HTTPS and WordPress is version 5.2.18 which is from May 2019, it's safe to say that this site hasn't been updated for quite some time and is highly likely to be compromised:
I have reported this email to the hosting provider and I hope they will assist the customer in resolving the problem.
Email 5–$10 million anyone?
This one really sticks out like a sore thumb, here are some things wrong with it:
- Sender's email address: This email is meant to be from Mr. Oswald Bruce however the sender's email is "mrchrisobi2@gmail[.]com", make your mind up are you "Chris" or are you "Bruce"? The email address also doesn't match what you would expect from the "United States Postal Service" (USPS). It's odd of them to use a generic Gmail address, isn't it?
- Grammar and formatting issues: The email has lots of grammar mistakes, missing punctuation, and inconsistent capitalization. Not what you would expect from an organization like USPS.
- Informal language: The phrases "Yours affectionately" and "the world's great success stories" sound too casual for an official postal service email.
- Asking for personal information: They want you to give them personal details like your full name, address, phone number, ID card, and passport or driver's license. Most organizations don't usually request such information through email, especially unsolicited ones.
- Unrealistic promise: They claim to be sending you an ATM Master Card worth $10.5 million USD. Emails promising big sums of money out of the blue are often linked to scams. Although, I am still holding out for that big lottery win to land!
- No official branding: The email lacks official logos, branding, and contact information.
- Suspicious call to action: The email asks you to reply to "postalservicedeliverycompany@fastservice[.]com". You would expect this to match the USPS name and domain. w
A quick Google search of "fastservice[.]com" shows that it is a popular domain used for many different scams.
I have reported the Gmail account here to Google, if it's fake hopefully they will shut it down. But if it belongs to an unfortunate victim of email hacking, I hope they get their email back!
Conclusion
In this dive into my decade-old email account, we uncovered some shady tactics used in phishing and spam emails. From fake Prime Video alerts to MetaMask deactivation threats and crazy inheritance promises, scammers continue to find ways to trick unsuspecting recipients.
Even though the emails shown in this post are obviously suspicious to most, the key takeaway here is to stay vigilant and skeptical when encountering suspicious emails. Watch out for red flags like unusual To/From lines, unexpected attachments, generic greetings, poor grammar and spelling, lack of specific information, and urgency to take immediate action. Remember, legitimate organizations pay attention to details and provide relevant details when they contact you.
To protect yourself, enable multi-factor authentication on everything, don't re-use passwords, and disable sign-in for leaked email addresses (if you can). Also, always be cautious when opening attachments or clicking on links from unknown sources.
By sharing my findings and reporting these malicious attempts, hopefully, we can contribute to disrupting their operations and protecting others. Stay safe online and always verify the legitimacy of emails, documents, and links before taking any action.
Sign Off
I hope this dive into the shadows of my email account was insightful, and if you liked it, stay tuned I might write more stuff like this in the future. Stay safe, stay curious, and keep unmasking the shadows!
Joshua Clarke
The Gray Area is a collection of great cybersecurity and computer science posts. Become a writer for The Gray Area by filling out this form! To get updates whenever The Gray Area publishes an article, check out our Twitter page, @TGAonMedium.
The Gray Area For all kinds of developers, hackers, and tech-savvy readers | Free newsletters each Wednesday on the newest tech…