{"id":9143,"date":"2024-04-19T00:32:55","date_gmt":"2024-04-19T00:32:55","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=9143"},"modified":"2024-04-20T23:32:43","modified_gmt":"2024-04-20T23:32:43","slug":"shall-we-say-good-bye-phishing-queue-part-2","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2024\/04\/19\/shall-we-say-good-bye-phishing-queue-part-2\/","title":{"rendered":"Shall we say\u2026 Good bye, phishing queue? Part 2"},"content":{"rendered":"\n<p>In my older <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/07\/07\/shall-we-say-good-bye-phishing-queue\/\" data-type=\"post\" data-id=\"8143\">piece<\/a> I argued that we should stop caring about phishing alerts. Of course, it was a bit of a parable&#8230;<\/p>\n\n\n\n<p>Still, there is a lot of quick wins I described there that can be implemented\/incorporated into phishing workflows easily &#8211; as long as you have some sort of automation\/SOAR in place&#8230;<\/p>\n\n\n\n<p>As I mentioned back then, any emails marked as phish that come from all these &#8216;noreply&#8217;, &#8216;no-reply&#8217;, &#8216;donotreply&#8217; mailboxes coming from well known domains can be (most of the time) auto-closed w\/o any investigation&#8230;<\/p>\n\n\n\n<p>Easy to say, but what are these really&#8230;?<\/p>\n\n\n\n<p>While I have personally collected a long list of these nothingburger email senders before, I got curious how many of these generic &#8216;do not reply&#8217; type of email accounts are really out there, and not within a single company&#8217;s scope, but in general (that is, just email account names hosted on popular domains that belong to the &#8216;do nothing&#8217; category).<\/p>\n\n\n\n<p>If asked about listing these passive account names from the top of your head I bet you would start with &#8216;noreply&#8217;, &#8216;no-reply&#8217;, and all the variants of &#8216;donotreply&#8217;, then you would perhaps follow with &#8216;contact&#8217;, &#8216;info&#8217;, &#8216;abuse&#8217;, &#8216;webmaster&#8217;, and so on and so forth, but &#8230; this is just a guesswork. I thought this approach was too speculative and that we can build a more more comprehensive list of these w\/o guessing. And mind you, this IS a very difficult request to fulfill. Unless you work for a company working in the mail security business, that is&#8230;<\/p>\n\n\n\n<p>And since I don&#8217;t, let&#8217;s get creative&#8230;<\/p>\n\n\n\n<p>I wrote a quick &amp; dirty script that goes through a batch of files containing email addresses extracted from various public e-mail dumps. It reads them one by one and it tries to extract some basic stats about them. A lot of results are quite boring and non-actionable, many are discarded &#8216;on the fly&#8217;, but after running it for a few days, adjusting it here and there, my goal of building an _inaccurate_ histogram of the most commonly used do-not-reply account names started to bring fruits. And while I am writing this, my script is still running, but there are a lot of juicy results already, so I am going to share them below&#8230;<\/p>\n\n\n\n<p>Before I do so, let me help you with an interpretation.<\/p>\n\n\n\n<p>For every account name I am listing, try to find out if any of these come from the domains that are generally trustworthy. And the good news is &#8212; chances are, many of them contribute to your phishing alert volumes!<\/p>\n\n\n\n<p>For example, a noreply@facebook.com is trustworthy, but noreply@skdjfhskdjfgj.com is not.<\/p>\n\n\n\n<p>Now that we have all these pieces of information in place, let&#8217;s look at the actual list of email accounts of &#8216;no interest&#8217;:<\/p>\n\n\n\n<ul>\n<li>info@<\/li>\n\n\n\n<li>mail@<\/li>\n\n\n\n<li>admin@<\/li>\n\n\n\n<li>net@<\/li>\n\n\n\n<li>office@<\/li>\n\n\n\n<li>sales@<\/li>\n\n\n\n<li>contact@<\/li>\n\n\n\n<li>master@<\/li>\n\n\n\n<li>life@<\/li>\n\n\n\n<li>best@<\/li>\n\n\n\n<li>webmaster@<\/li>\n\n\n\n<li>email@<\/li>\n\n\n\n<li>home@<\/li>\n\n\n\n<li>support@<\/li>\n\n\n\n<li>purchase@<\/li>\n\n\n\n<li>myspace@<\/li>\n\n\n\n<li>boss@<\/li>\n\n\n\n<li>sample@<\/li>\n\n\n\n<li>style@<\/li>\n\n\n\n<li>smile@<\/li>\n\n\n\n<li>av@<\/li>\n\n\n\n<li>online@<\/li>\n\n\n\n<li>accounts@<\/li>\n\n\n\n<li>design@<\/li>\n\n\n\n<li>box@<\/li>\n\n\n\n<li>test@<\/li>\n\n\n\n<li>web@<\/li>\n\n\n\n<li>service@<\/li>\n\n\n\n<li>www@<\/li>\n\n\n\n<li>world@<\/li>\n\n\n\n<li>null@<\/li>\n\n\n\n<li>bill@<\/li>\n\n\n\n<li>live@<\/li>\n\n\n\n<li>no@<\/li>\n\n\n\n<li>post@<\/li>\n\n\n\n<li>game@<\/li>\n\n\n\n<li>hot@<\/li>\n\n\n\n<li>off@<\/li>\n\n\n\n<li>new@<\/li>\n\n\n\n<li>marketing@<\/li>\n\n\n\n<li>all@<\/li>\n\n\n\n<li>spam@<\/li>\n\n\n\n<li>shop@<\/li>\n\n\n\n<li>club@<\/li>\n\n\n\n<li>demon@<\/li>\n\n\n\n<li>sex@<\/li>\n\n\n\n<li>org@<\/li>\n\n\n\n<li>hi@<\/li>\n\n\n\n<li>team@<\/li>\n\n\n\n<li>kontakt@<\/li>\n\n\n\n<li>student@<\/li>\n\n\n\n<li>house@<\/li>\n\n\n\n<li>games@<\/li>\n\n\n\n<li>here@<\/li>\n\n\n\n<li>work@<\/li>\n\n\n\n<li>city@<\/li>\n\n\n\n<li>job@<\/li>\n\n\n\n<li>fly@<\/li>\n\n\n\n<li>free@<\/li>\n\n\n\n<li>hello@<\/li>\n\n\n\n<li>weber@<\/li>\n\n\n\n<li>top@<\/li>\n\n\n\n<li>fun@<\/li>\n\n\n\n<li>user@<\/li>\n\n\n\n<li>money@<\/li>\n\n\n\n<li>player@<\/li>\n\n\n\n<li>auto@<\/li>\n\n\n\n<li>personal@<\/li>\n\n\n\n<li>price@<\/li>\n\n\n\n<li>link@<\/li>\n\n\n\n<li>time@<\/li>\n\n\n\n<li>beauty@<\/li>\n\n\n\n<li>manager@<\/li>\n\n\n\n<li>geo@<\/li>\n\n\n\n<li>manu@<\/li>\n\n\n\n<li>seo@<\/li>\n\n\n\n<li>jenkins@<\/li>\n\n\n\n<li>project@<\/li>\n\n\n\n<li>dummy@<\/li>\n\n\n\n<li>photo@<\/li>\n\n\n\n<li>business@<\/li>\n\n\n\n<li>company@<\/li>\n\n\n\n<li>records@<\/li>\n\n\n\n<li>show@<\/li>\n\n\n\n<li>productions@<\/li>\n\n\n\n<li>foto@<\/li>\n\n\n\n<li>legend@<\/li>\n\n\n\n<li>dev@<\/li>\n\n\n\n<li>space@<\/li>\n\n\n\n<li>cash@<\/li>\n\n\n\n<li>miles@<\/li>\n\n\n\n<li>first@<\/li>\n\n\n\n<li>bot@<\/li>\n\n\n\n<li>help@<\/li>\n\n\n\n<li>core@<\/li>\n\n\n\n<li>facebook@<\/li>\n\n\n\n<li>beer@<\/li>\n\n\n\n<li>blog@<\/li>\n\n\n\n<li>unit@<\/li>\n\n\n\n<li>agent@<\/li>\n\n\n\n<li>song@<\/li>\n\n\n\n<li>flash@<\/li>\n\n\n\n<li>opt@<\/li>\n\n\n\n<li>list@<\/li>\n\n\n\n<li>noemail@<\/li>\n\n\n\n<li>gaming@<\/li>\n\n\n\n<li>secret@<\/li>\n\n\n\n<li>ads@<\/li>\n\n\n\n<li>travel@<\/li>\n\n\n\n<li>market@<\/li>\n\n\n\n<li>football@<\/li>\n\n\n\n<li>speed@<\/li>\n\n\n\n<li>trade@<\/li>\n\n\n\n<li>mini@<\/li>\n\n\n\n<li>freedom@<\/li>\n\n\n\n<li>services@<\/li>\n\n\n\n<li>postmaster@<\/li>\n\n\n\n<li>ebay@<\/li>\n\n\n\n<li>corp@<\/li>\n\n\n\n<li>staff@<\/li>\n\n\n\n<li>unknown@<\/li>\n\n\n\n<li>lost@<\/li>\n\n\n\n<li>bug@<\/li>\n\n\n\n<li>login@<\/li>\n\n\n\n<li>moto@<\/li>\n\n\n\n<li>editor@<\/li>\n\n\n\n<li>sound@<\/li>\n\n\n\n<li>force@<\/li>\n\n\n\n<li>vkontakte@<\/li>\n\n\n\n<li>wizard@<\/li>\n\n\n\n<li>english@<\/li>\n\n\n\n<li>people@<\/li>\n\n\n\n<li>party@<\/li>\n\n\n\n<li>abuse@<\/li>\n\n\n\n<li>dhl@<\/li>\n\n\n\n<li>fedex@<\/li>\n\n\n\n<li>ups@<\/li>\n\n\n\n<li>studio@<\/li>\n\n\n\n<li>play@<\/li>\n\n\n\n<li>submit@<\/li>\n\n\n\n<li>biuro@<\/li>\n\n\n\n<li>yahoo@<\/li>\n\n\n\n<li>soft@<\/li>\n\n\n\n<li>account@<\/li>\n\n\n\n<li>booking@<\/li>\n\n\n\n<li>kids@<\/li>\n\n\n\n<li>adidas@<\/li>\n\n\n\n<li>system@<\/li>\n\n\n\n<li>expert@<\/li>\n\n\n\n<li>freelife@<\/li>\n\n\n\n<li>forum@<\/li>\n\n\n\n<li>mailbox@<\/li>\n\n\n\n<li>photography@<\/li>\n\n\n\n<li>fantasy@<\/li>\n\n\n\n<li>production@<\/li>\n\n\n\n<li>administrator@<\/li>\n\n\n\n<li>designer@<\/li>\n\n\n\n<li>chef@<\/li>\n\n\n\n<li>inbox@<\/li>\n\n\n\n<li>official@<\/li>\n\n\n\n<li>social@<\/li>\n\n\n\n<li>minecraft@<\/li>\n\n\n\n<li>shopping@<\/li>\n\n\n\n<li>paypal@<\/li>\n\n\n\n<li>united@<\/li>\n\n\n\n<li>entertainment@<\/li>\n\n\n\n<li>customerservice@<\/li>\n\n\n\n<li>creative@<\/li>\n\n\n\n<li>consulting@<\/li>\n\n\n\n<li>reception@<\/li>\n\n\n\n<li>invitado@<\/li>\n\n\n\n<li>consult@<\/li>\n\n\n\n<li>vision@<\/li>\n\n\n\n<li>away@<\/li>\n\n\n\n<li>network@<\/li>\n\n\n\n<li>education@<\/li>\n\n\n\n<li>robot@<\/li>\n\n\n\n<li>nomail@<\/li>\n\n\n\n<li>nothing@<\/li>\n\n\n\n<li>digital@<\/li>\n\n\n\n<li>solutions@<\/li>\n\n\n\n<li>taxi@<\/li>\n\n\n\n<li>training@<\/li>\n\n\n\n<li>noreply@<\/li>\n\n\n\n<li>today@<\/li>\n\n\n\n<li>agency@<\/li>\n\n\n\n<li>purchasing@<\/li>\n\n\n\n<li>security@<\/li>\n\n\n\n<li>commerciale@<\/li>\n\n\n\n<li>community@<\/li>\n\n\n\n<li>studios@<\/li>\n\n\n\n<li>connect@<\/li>\n\n\n\n<li>newsletter@<\/li>\n\n\n\n<li>nobody@<\/li>\n\n\n\n<li>food@<\/li>\n\n\n\n<li>youth@<\/li>\n\n\n\n<li>oops@<\/li>\n\n\n\n<li>construction@<\/li>\n\n\n\n<li>society@<\/li>\n\n\n\n<li>registrar@<\/li>\n\n\n\n<li>transport@<\/li>\n\n\n\n<li>audio@<\/li>\n\n\n\n<li>nospam@<\/li>\n\n\n\n<li>member@<\/li>\n\n\n\n<li>junkmail@<\/li>\n\n\n\n<li>secretary@<\/li>\n\n\n\n<li>enquiry@<\/li>\n\n\n\n<li>surveys@<\/li>\n\n\n\n<li>articles@<\/li>\n\n\n\n<li>enterprise@<\/li>\n\n\n\n<li>bookings@<\/li>\n\n\n\n<li>segreteria@<\/li>\n\n\n\n<li>information@<\/li>\n\n\n\n<li>communication@<\/li>\n\n\n\n<li>commercial@<\/li>\n\n\n\n<li>event@<\/li>\n\n\n\n<li>photos@<\/li>\n\n\n\n<li>yourmail@<\/li>\n\n\n\n<li>central@<\/li>\n\n\n\n<li>inform@<\/li>\n\n\n\n<li>tours@<\/li>\n\n\n\n<li>operator@<\/li>\n\n\n\n<li>factory@<\/li>\n\n\n\n<li>direct@<\/li>\n\n\n\n<li>import@<\/li>\n\n\n\n<li>realtor@<\/li>\n\n\n\n<li>misc@<\/li>\n\n\n\n<li>xpress@<\/li>\n\n\n\n<li>virtual@<\/li>\n\n\n\n<li>premium@<\/li>\n\n\n\n<li>amazon@<\/li>\n\n\n\n<li>capital@<\/li>\n\n\n\n<li>research@<\/li>\n\n\n\n<li>exclusive@<\/li>\n\n\n\n<li>biznes@<\/li>\n\n\n\n<li>oracle@<\/li>\n\n\n\n<li>corporation@<\/li>\n\n\n\n<li>summit@<\/li>\n\n\n\n<li>inquiry@<\/li>\n\n\n\n<li>daemon@<\/li>\n\n\n\n<li>massage@<\/li>\n\n\n\n<li>officiel@<\/li>\n\n\n\n<li>associates@<\/li>\n\n\n\n<li>culture@<\/li>\n\n\n\n<li>cartoon@<\/li>\n\n\n\n<li>navigator@<\/li>\n\n\n\n<li>platinum@<\/li>\n\n\n\n<li>poczta@<\/li>\n\n\n\n<li>sazonova@<\/li>\n\n\n\n<li>redaktion@<\/li>\n\n\n\n<li>local@<\/li>\n\n\n\n<li>website@<\/li>\n\n\n\n<li>partners@<\/li>\n\n\n\n<li>johncena@<\/li>\n\n\n\n<li>realestate@<\/li>\n\n\n\n<li>firefox@<\/li>\n\n\n\n<li>resident@<\/li>\n\n\n\n<li>advertising@<\/li>\n\n\n\n<li>anonim@<\/li>\n\n\n\n<li>source@<\/li>\n\n\n\n<li>technik@<\/li>\n\n\n\n<li>response@<\/li>\n\n\n\n<li>mobility@<\/li>\n\n\n\n<li>traffic@<\/li>\n\n\n\n<li>custom@<\/li>\n<\/ul>\n\n\n\n<p>There are many more and I recommend that you look at your phishing queue and analyze senders, and people who are too trigger-happy to submit phish reports to your SOC. Stats like this can give you plenty of opportunities to both automate auto-closures, and educate trigger-happy users.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my older piece I argued that we should stop caring about phishing alerts. Of course, it was a bit of a parable&#8230; Still, there is a lot of quick wins I described there that can be implemented\/incorporated into phishing &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2024\/04\/19\/shall-we-say-good-bye-phishing-queue-part-2\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[46,118,101],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/9143"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=9143"}],"version-history":[{"count":5,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/9143\/revisions"}],"predecessor-version":[{"id":9149,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/9143\/revisions\/9149"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=9143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=9143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=9143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}