Home / Community Lab / Week 01
Week 01 Beginner 50 Points

Phishing Email Analysis

Analyze a sample phishing email to identify red flags. Learn to spot malicious links, sender spoofing, and social engineering tactics used by attackers.

The Email

Questions to Consider

1What is suspicious about the sender's email address?

The domain uses a zero (0) instead of the letter 'o' in "amazon" - a common typosquatting technique. Real Amazon emails come from @amazon.com.

2What psychological tactics are being used to pressure the recipient?

The email uses urgency ("URGENT", "24 hours"), fear ("compromised", "permanently deleted"), and authority ("Security Team") to bypass rational thinking.

3What red flags can you identify in the URL provided?

The domain "amaz0n-verify-account.com" is not amazon.com. It uses a zero instead of 'o' and adds extra words. Legitimate links would be on amazon.com.

4What is unusual about the timing of this email?

The email was sent at 3:47 AM, which is unusual for legitimate business communications and may indicate automated phishing campaigns operating from different time zones.

Capture the Flag

Based on your analysis, what is the fake domain being used? Format: flag{domain.com}