1
1

00:00:00,240  -->  00:00:03,090
<v Instructor>Email indicators of compromise.</v>
2

2

00:00:03,090  -->  00:00:06,600
Now, email issues are on the rise year after year.
3

3

00:00:06,600  -->  00:00:09,510
Spam and phishing are common social engineering attacks
4

4

00:00:09,510  -->  00:00:12,000
that use email as their delivery vector.
5

5

00:00:12,000  -->  00:00:13,170
And you've already learned about them
6

6

00:00:13,170  -->  00:00:17,250
in your previous A+, Network+, and Security+ studies.
7

7

00:00:17,250  -->  00:00:19,860
As a quick review, though, the definition of spam
8

8

00:00:19,860  -->  00:00:23,760
is the unsolicited and unwanted junk email sent out in bulk
9

9

00:00:23,760  -->  00:00:26,010
to an indiscriminate recipient list.
10

10

00:00:26,010  -->  00:00:27,570
Now, the reason why they send things out
11

11

00:00:27,570  -->  00:00:30,600
in this spam manner is because if you send out a wide net,
12

12

00:00:30,600  -->  00:00:34,260
you'll catch some people, and that's the idea behind spam.
13

13

00:00:34,260  -->  00:00:35,490
Now, this goes a step further
14

14

00:00:35,490  -->  00:00:37,170
when you start talking about phishing.
15

15

00:00:37,170  -->  00:00:38,790
Phishing is the fraudulent practice
16

16

00:00:38,790  -->  00:00:40,680
of sending out emails purporting to be
17

17

00:00:40,680  -->  00:00:43,650
from a reputable company in order to induce individuals
18

18

00:00:43,650  -->  00:00:45,270
to reveal personal information,
19

19

00:00:45,270  -->  00:00:47,880
such as passwords or credit card numbers.
20

20

00:00:47,880  -->  00:00:49,710
This happens a lot as part of spam,
21

21

00:00:49,710  -->  00:00:52,800
but with this more malicious intent, it becomes phishing.
22

22

00:00:52,800  -->  00:00:54,960
Now, one of the big things inside of phishing
23

23

00:00:54,960  -->  00:00:56,820
is you have to have a pretext.
24

24

00:00:56,820  -->  00:00:59,280
Now, a pretext is a form of social engineering
25

25

00:00:59,280  -->  00:01:02,370
in which the individual lies and provides false motive
26

26

00:01:02,370  -->  00:01:04,140
to obtain privileged data.
27

27

00:01:04,140  -->  00:01:05,550
You've probably seen phishing emails
28

28

00:01:05,550  -->  00:01:07,410
that use a pretext like this one.
29

29

00:01:07,410  -->  00:01:09,360
For instance, I am from PayPal.
30

30

00:01:09,360  -->  00:01:10,770
Your account has been compromised.
31

31

00:01:10,770  -->  00:01:13,020
You need to click this link to set up something
32

32

00:01:13,020  -->  00:01:14,250
or fix something.
33

33

00:01:14,250  -->  00:01:15,870
Or there's been this big charge that's happening.
34

34

00:01:15,870  -->  00:01:17,580
You need to click here to verify it.
35

35

00:01:17,580  -->  00:01:19,200
Those type of things happen.
36

36

00:01:19,200  -->  00:01:21,870
And this is just a way of doing spam and phishing
37

37

00:01:21,870  -->  00:01:24,750
using a pretext that is somewhat believable.
38

38

00:01:24,750  -->  00:01:25,860
Now, if we take it a step further,
39

39

00:01:25,860  -->  00:01:27,360
we can move into spear phishing.
40

40

00:01:27,360  -->  00:01:28,410
Now, with spear phishing,
41

41

00:01:28,410  -->  00:01:30,480
we're dealing with an email spoofing attack
42

42

00:01:30,480  -->  00:01:33,180
that targets a specific organization or individual
43

43

00:01:33,180  -->  00:01:36,270
by seeking unauthorized access to sensitive information.
44

44

00:01:36,270  -->  00:01:38,610
For example, let's say your bank has been compromised
45

45

00:01:38,610  -->  00:01:39,570
in the past.
46

46

00:01:39,570  -->  00:01:41,130
Now the attackers have a list
47

47

00:01:41,130  -->  00:01:43,050
of all the people who use that bank,
48

48

00:01:43,050  -->  00:01:45,390
so now they can specifically target people
49

49

00:01:45,390  -->  00:01:48,510
who are users of that bank because they know who they are.
50

50

00:01:48,510  -->  00:01:51,210
And so they can use the pretext of being from that bank
51

51

00:01:51,210  -->  00:01:52,950
and targeting a specific list of people
52

52

00:01:52,950  -->  00:01:54,690
who are customers of that bank.
53

53

00:01:54,690  -->  00:01:56,430
For instance, if you get a spear phishing email
54

54

00:01:56,430  -->  00:01:57,263
saying there's something wrong
55

55

00:01:57,263  -->  00:01:58,470
with your Bank of America account
56

56

00:01:58,470  -->  00:02:00,870
and click here to log into the website to fix it,
57

57

00:02:00,870  -->  00:02:02,130
you're more likely to do that
58

58

00:02:02,130  -->  00:02:03,930
if you're a Bank of America customer.
59

59

00:02:03,930  -->  00:02:05,280
I don't bank with Bank of America,
60

60

00:02:05,280  -->  00:02:07,680
so if I got that through a generic phishing campaign,
61

61

00:02:07,680  -->  00:02:10,290
I would just ignore it because I know it's not my bank.
62

62

00:02:10,290  -->  00:02:11,910
That's the idea of dealing with spear phishing.
63

63

00:02:11,910  -->  00:02:13,230
It's a little bit more targeted
64

64

00:02:13,230  -->  00:02:14,820
than a regular phishing attack.
65

65

00:02:14,820  -->  00:02:17,970
Now, this all relies on the concept of impersonation.
66

66

00:02:17,970  -->  00:02:19,470
The idea with a lot of these attacks is
67

67

00:02:19,470  -->  00:02:21,630
to try to trick you into giving us some information.
68

68

00:02:21,630  -->  00:02:22,980
If we can get some information about you
69

69

00:02:22,980  -->  00:02:26,640
like your name, your email, password, your login,
70

70

00:02:26,640  -->  00:02:29,490
things like that, we can then use it to impersonate you.
71

71

00:02:29,490  -->  00:02:31,650
And when we deal with impersonation, this is an attack
72

72

00:02:31,650  -->  00:02:34,530
in which an adversary successfully assumes the identity
73

73

00:02:34,530  -->  00:02:36,810
of one of the legitimate parties in a system
74

74

00:02:36,810  -->  00:02:38,850
or in a communications protocol.
75

75

00:02:38,850  -->  00:02:41,640
So for example, if I have figured out a particular person
76

76

00:02:41,640  -->  00:02:42,777
who works at your company
77

77

00:02:42,777  -->  00:02:45,060
and I can send out emails pretending to be them,
78

78

00:02:45,060  -->  00:02:48,150
I can impersonate them and get you to do things for me.
79

79

00:02:48,150  -->  00:02:49,320
When an attacker does this,
80

80

00:02:49,320  -->  00:02:53,070
it's usually part of a business email compromise, or a BEC.
81

81

00:02:53,070  -->  00:02:55,200
Now, when you're dealing with a business email compromise,
82

82

00:02:55,200  -->  00:02:57,000
this is an impersonation attack
83

83

00:02:57,000  -->  00:02:59,550
in which the attacker gains control of an employee's account
84

84

00:02:59,550  -->  00:03:01,710
and then uses it to convince other employees
85

85

00:03:01,710  -->  00:03:03,780
to perform fraudulent actions.
86

86

00:03:03,780  -->  00:03:06,090
For example, if somebody used a phishing
87

87

00:03:06,090  -->  00:03:08,940
or a spear phishing campaign to trick one of my employees
88

88

00:03:08,940  -->  00:03:11,250
to click the link and take over their account,
89

89

00:03:11,250  -->  00:03:14,070
now they can send emails as if they're one of my employees.
90

90

00:03:14,070  -->  00:03:15,300
And if they send me an email
91

91

00:03:15,300  -->  00:03:16,860
as if they're one of my employees
92

92

00:03:16,860  -->  00:03:18,607
from that employee's account saying,
93

93

00:03:18,607  -->  00:03:21,330
"Hey, you need to release funds to pay XYZ vendor,"
94

94

00:03:21,330  -->  00:03:23,430
if I'm not careful, I could say, "Okay,"
95

95

00:03:23,430  -->  00:03:25,080
and I can send the money to that vendor.
96

96

00:03:25,080  -->  00:03:26,730
Well, that vendor isn't really a vendor.
97

97

00:03:26,730  -->  00:03:29,460
It's one of their friends who we've now sent that money to.
98

98

00:03:29,460  -->  00:03:32,280
And this is the whole idea with a business email compromise.
99

99

00:03:32,280  -->  00:03:35,340
Now, another way this is done is by using email spoofing.
100

100

00:03:35,340  -->  00:03:36,360
Now, with email spoofing,
101

101

00:03:36,360  -->  00:03:37,980
you can actually send out the message
102

102

00:03:37,980  -->  00:03:41,130
and make it look like it's coming from a particular person.
103

103

00:03:41,130  -->  00:03:43,260
So again, if I was able to use social engineering
104

104

00:03:43,260  -->  00:03:44,400
and gather information
105

105

00:03:44,400  -->  00:03:46,650
and I know who your chief financial officer is,
106

106

00:03:46,650  -->  00:03:47,910
I know what their email address is,
107

107

00:03:47,910  -->  00:03:49,170
I know what their name is,
108

108

00:03:49,170  -->  00:03:50,850
I might even have some of their emails in the past
109

109

00:03:50,850  -->  00:03:52,770
so I can mimic their writing style,
110

110

00:03:52,770  -->  00:03:54,870
I can then spoof you and make you think
111

111

00:03:54,870  -->  00:03:57,540
that I am your chief financial officer as an attacker
112

112

00:03:57,540  -->  00:03:59,160
and tell you you need to send a payment
113

113

00:03:59,160  -->  00:04:00,450
from one place to another
114

114

00:04:00,450  -->  00:04:02,040
and give you the routing information.
115

115

00:04:02,040  -->  00:04:03,870
And you would fall for it, right?
116

116

00:04:03,870  -->  00:04:05,880
Especially if you're not careful in verifying
117

117

00:04:05,880  -->  00:04:08,190
whether or not that email really came from them.
118

118

00:04:08,190  -->  00:04:09,210
Now, there's a couple of ways
119

119

00:04:09,210  -->  00:04:11,010
that this email spoofing can occur.
120

120

00:04:11,010  -->  00:04:12,030
One of the most common, though,
121

121

00:04:12,030  -->  00:04:13,560
is what's known as forwarding.
122

122

00:04:13,560  -->  00:04:15,060
When you're dealing with forwarding,
123

123

00:04:15,060  -->  00:04:16,740
a phishing email is going to be formatted
124

124

00:04:16,740  -->  00:04:19,680
so it appears to have come as part of a reply or a chain.
125

125

00:04:19,680  -->  00:04:22,980
So for example, if I know somebody who works in your office
126

126

00:04:22,980  -->  00:04:24,420
who may not be the CFO.
127

127

00:04:24,420  -->  00:04:26,100
Let's say it's not the head person,
128

128

00:04:26,100  -->  00:04:27,990
but instead it's their assistant.
129

129

00:04:27,990  -->  00:04:31,320
I can then forward the email saying, from the CFO,
130

130

00:04:31,320  -->  00:04:34,590
they said transfer money from X account to Y account.
131

131

00:04:34,590  -->  00:04:36,180
Regards, this assistant.
132

132

00:04:36,180  -->  00:04:37,830
And then have the forward chain below that
133

133

00:04:37,830  -->  00:04:40,530
that looks like it came from the CFO.
134

134

00:04:40,530  -->  00:04:42,510
Well, whether it did or not, if it looked like it,
135

135

00:04:42,510  -->  00:04:43,410
you may fall for that.
136

136

00:04:43,410  -->  00:04:44,760
And that's the idea of forwarding,
137

137

00:04:44,760  -->  00:04:47,280
where you basically can compromise a lower-level employee
138

138

00:04:47,280  -->  00:04:48,840
and then forward the email
139

139

00:04:48,840  -->  00:04:51,240
of what is supposedly a higher-level employee
140

140

00:04:51,240  -->  00:04:52,980
to get people to do what you want.
141

141

00:04:52,980  -->  00:04:55,260
Now, many spoofing attempts can be detected
142

142

00:04:55,260  -->  00:04:57,660
by a close examination of the internet headers
143

143

00:04:57,660  -->  00:04:59,130
that are attached to a message.
144

144

00:04:59,130  -->  00:05:00,390
When you open up an email,
145

145

00:05:00,390  -->  00:05:02,760
there is this hidden header that you really don't see.
146

146

00:05:02,760  -->  00:05:04,620
If you use Gmail, for example,
147

147

00:05:04,620  -->  00:05:06,480
at the top you'll see the to line,
148

148

00:05:06,480  -->  00:05:09,450
the CC line, the from line, and the subject line,
149

149

00:05:09,450  -->  00:05:11,430
but there is a lot more to it than that,
150

150

00:05:11,430  -->  00:05:12,690
and this is all what we call
151

151

00:05:12,690  -->  00:05:14,760
the email message internet header.
152

152

00:05:14,760  -->  00:05:16,590
And we're going to talk about that in the next lesson
153

153

00:05:16,590  -->  00:05:17,913
and how to analyze those.
