Phish Trap Challenge Packet
RESTRICTED // EYES ONLY CYBER INCIDENT RESPONSE UNIT (CIRU)
CODE: OP-PHISH-TRAP
OPERATION PHISH TRAP
Cyber Threat Defense & Anti-Phishing Incident Escape Packet
Lead Analyst:
Squad / Date:
System Time: 00:45:00 REMAINING
CISO INCIDENT ADVISORY // BREACH IMMINENT
At 0842 hours, threat actor group "Shadow Phish" launched an orchestrated social-engineering and credential-harvesting attack against the municipal power grid data network. Four firewall gates have been compromised. Your team must investigate the evidence across four stations to extract security passcodes and broadcast the Master Override Sequence before data exfiltration begins.
FIREWALL OVERRIDE CONSOLE // LOCK TRACKER
ALL 4 REQUIRED
Lock 01 // Inbox
4-Digit PIN
[ ]
STATION 1 PIN
Lock 02 // Links
4-Letter Word
[ ]
STATION 2 KEY
Lock 03 // Vault
4-Digit Hash
[ ]
STATION 3 HASH
Lock 04 // Social
4-Digit Vector
[ ]
STATION 4 CODE
TACTICAL DECRYPTION MATRIX // ALPHANUMERIC CONVERSION
STANDARDIZED INDEX
Use this standardized conversion matrix when translating station tokens into lock numbers or letters.
<table class="w-full text-center text-[10px] font-mono border-collapse border border-slate-300 bg-white"><tbody><tr class="bg-slate-800 text-white font-bold"><td class="border border-slate-600 py-0.5">A</td><td class="border border-slate-600">B</td><td class="border border-slate-600">C</td><td class="border border-slate-600">D</td><td class="border border-slate-600">E</td><td class="border border-slate-600">F</td><td class="border border-slate-600">G</td><td class="border border-slate-600">H</td><td class="border border-slate-600">I</td><td class="border border-slate-600">J</td><td class="border border-slate-600">K</td><td class="border border-slate-600">L</td><td class="border border-slate-600">M</td></tr><tr class="bg-slate-50 text-slate-700 font-semibold border-b border-slate-300"><td class="border border-slate-300 py-0.5">1</td><td class="border border-slate-300">2</td><td class="border border-slate-300">3</td><td class="border border-slate-300">4</td><td class="border border-slate-300">5</td><td class="border border-slate-300">6</td><td class="border border-slate-300">7</td><td class="border border-slate-300">8</td><td class="border border-slate-300">9</td><td class="border border-slate-300">10</td><td class="border border-slate-300">11</td><td class="border border-slate-300">12</td><td class="border border-slate-300">13</td></tr><tr class="bg-slate-800 text-white font-bold"><td class="border border-slate-600 py-0.5">N</td><td class="border border-slate-600">O</td><td class="border border-slate-600">P</td><td class="border border-slate-600">Q</td><td class="border border-slate-600">R</td><td class="border border-slate-600">S</td><td class="border border-slate-600">T</td><td class="border border-slate-600">U</td><td class="border border-slate-600">V</td><td class="border border-slate-600">W</td><td class="border border-slate-600">X</td><td class="border border-slate-600">Y</td><td class="border border-slate-600">Z</td></tr><tr class="bg-slate-50 text-slate-700 font-semibold"><td class="border border-slate-300 py-0.5">14</td><td class="border border-slate-300">15</td><td class="border border-slate-300">16</td><td class="border border-slate-300">17</td><td class="border border-slate-300">18</td><td class="border border-slate-300">19</td><td class="border border-slate-300">20</td><td class="border border-slate-300">21</td><td class="border border-slate-300">22</td><td class="border border-slate-300">23</td><td class="border border-slate-300">24</td><td class="border border-slate-300">25</td><td class="border border-slate-300">26</td></tr></tbody></table>
OPERATIONAL PROTOCOL & RULES OF ENGAGEMENT
- Inspect Before You Act: Attackers hide traps in domain names, fake urgent language, and double extensions.
- Document Evidence: Complete each station's triage analysis before calculating the firewall lock codes.
- Master Sequence Goal: Once all 4 lock codes are acquired, assemble them on Page 5 to halt the network attack!
INCIDENT BRIEFING // OP-PHISH-TRAP PAGE 1 OF 5
STATION 01
THE SUSPICIOUS INBOX // EMAIL HEADER FORENSICS
TARGET: LOCK 01 (PIN)
Mission Objective: Three suspect emails bypassed perimeter spam filters. Analyze sender headers, display name spoofing, reply-to mismatches, and grammatical urgency triggers to reveal the 4-digit firewall passkey.
MSG ALPHA Date: Today, 08:14 AM
From: "IT Support Desk" support@powergrid-corp.net.auth-portal9.com
Reply-To: admin@powergrid-corp.net.auth-portal9.com
Subject: MANDATORY ACTION: Password expires in 15 minutes!
"Dear User: Our security systems flagged unusual activity. You must verify credentials immediately at https://powergrid.corp-validate.com or your account will be permanently locked."
MSG BETA Date: Today, 08:29 AM
From: "Evelyn Vance, CEO" executive.office8812@gmail.com
Reply-To: urgent.replies.wire@gmail.com
Subject: CONFIDENTIAL: Quick errand for board meeting (Do not call)
"I'm stuck in an executive meeting and cannot take calls. Purchase four $250 Apple gift cards for partner incentives right now and email me the back scratch-off codes."
MSG GAMMA Date: Today, 08:35 AM
From: "Enterprise Benefits Portal" benefits@powergrid-corp.com
Reply-To: harvest-inbox@stealth-domain.cc
Subject: Q4 Health Insurance Open Enrollment Form Attached
"Greetings Team: Open enrollment runs through next month. Review your current coverage on the secure intranet server or reply to this email with questions."
EVIDENCE ANALYSIS LOG // STATION 1
| Message | Classification | Primary Red Flag Identified | Flag Value Code |
|---|
| ALPHA | Legit Phish | Spoofed domain: auth-portal9.com + artificial 15-min panic | VALUE: 3 |
| BETA | Legit Phish | Executive impersonation via external Gmail + gift card demand | VALUE: 8 |
| GAMMA | Legit Phish | Reply-To address mismatch directs data to stealth-domain.cc | VALUE: 4 |
LOCK 01 EXTRACTION FORMULA
NUMERIC 4-DIGIT PIN
Calculate the four digits of Lock 01 using this forensic algorithm:
• Digit 1 = [Value of ALPHA] | • Digit 2 = [Value of BETA] | • Digit 3 = [Value of GAMMA] | • Digit 4 = [Count of Phishing messages detected (1 to 3)]
STATION 1 FINAL PIN:
(Transfer to Page 1 Lock Tracker)
OPERATION PHISH TRAP // CIRU INVESTIGATION PAGE 2 OF 5
STATION 02
THE DECEPTIVE LINK LAB // URL DISSECTION & SPOOFING
TARGET: LOCK 02 (WORD)
ANATOMY OF A WEB ADDRESS (URL) - INSPECT BEFORE CLICKING!
Protocolhttps:// Subdomainportal.secure. Registered Domainmicrosoft TLD.com Path/File/login/verify
Key Rule: Attackers often insert brand names into subdomains (e.g., paypal.com.evil-hacker.net). The true destination is always the domain immediately before the Top Level Domain (.com, .net, etc.)!
INTERCEPTED HYPERLINKS IN TRANSIT
LINK 1 https://login.micros0ft-support.com/auth
Visible Anchor: "Click Here to Sign in to Office 365"
TYPOSQUATTING (0=O) Code Token: H
LINK 2 https://citibank.com.verify-security-alert.org/session
Visible Anchor: "Review Unauthorized Transaction"
SUBDOMAIN TRICK Code Token: A
LINK 3 https://vpn.powergrid-corp.com/remote/access
Visible Anchor: "Internal Employee Portal"
LEGITIMATE DOMAIN Code Token: X
LINK 4 http://secure-cloud-storage.ru/download/invoice
Visible Anchor: "View Q4 Vendor Invoices"
NO HTTPS / SUSPECT TLD Code Token: L
LINK 5 https://netflix.customer-billing-reactivate.co/update
Visible Anchor: "Update Expired Payment Method"
FAKE BRAND HYPHENATION Code Token: T
LOCK 02 DECODER LOGIC
4-LETTER KEYWORD
Decoder Rule: Gather the Code Tokens belonging only to the four malicious links in numerical order (Links 1, 2, 4, 5). Discard the token from the one legitimate link. The resulting letters spell the emergency firewall command word.
STATION 2 OVERRIDE WORD:
(Transfer to Page 1 Lock Tracker)
OPERATION PHISH TRAP // CIRU INVESTIGATION PAGE 3 OF 5
STATION 03
THE DANGEROUS ATTACHMENT VAULT // MALWARE TRIAGE
TARGET: LOCK 03 (HASH)
Mission Objective: Five suspicious attachments were quarantined in the sandbox. Inspect their file extensions, double-extension deceptions, macro warnings, and file container behavior to identify threats and extract the 4-digit security hash.
1. DOUBLE EXTENSIONS Windows often hides known extensions. Attackers name files Invoice.pdf.exe so users only see Invoice.pdf.
2. WEAPONIZED MACROS Office files ending in .docm or .xlsm can execute embedded automated visual basic scripts that download trojans.
3. ARCHIVES & SHORTCUTS .zip or .iso files disguise executable shortcuts (.lnk) or script runners (.vbs, .js).
SANDBOX QUARANTINE LOG // ANALYZE & SCORE
FILE A
Quarterly_Payroll_Summary.pdf.exe
Reported Icon: Adobe PDF | True MIME: application/x-msdownload
MALICIOUS EXECUTABLE Threat Weight: 2,000
FILE B
Safety_Protocols_Handbook.pdf
Reported Icon: Adobe PDF | True MIME: application/pdf (Clean scan)
BENIGN / SAFE Threat Weight: 0
FILE C
Vendor_Billing_Audit.docm
Prompt: "Yellow Bar: Enable Macros to view protected financial tables"
MACRO LOADER Threat Weight: 400
FILE D
Unclaimed_FedEx_Parcel.zip
Container contains hidden script: tracking_manifest.vbs
SCRIPT DROPPER Threat Weight: 80
FILE E
Urgent_Subpoena_Notice.scr
Extension .scr is a Windows ScreenSaver executable disguised as text
EXECUTABLE SCREENSAVER Threat Weight: 9
LOCK 03 SUMMATION ALGORITHM
4-DIGIT NUMBER
Calculation Rule: Add the Threat Weights of all four verified malicious files (File A + File C + File D + File E). Safe files contribute 0. The total sum equals the 4-digit Vault Passkey.
SUM [2000 + 400 + 80 + 9] =
(Transfer to Page 1 Lock Tracker)
OPERATION PHISH TRAP // CIRU INVESTIGATION PAGE 4 OF 5
STATION 04
SOCIAL ENGINEERING WIRETAP & FINAL OVERRIDE
LOCK 04 & FINAL SHUTDOWN
Phishing isn't just email. Attackers use SMS (smishing), phone calls (vishing), and psychological triggers like urgency, authority, and fear. Match each intercepted wiretap to its psychological trigger vector code.
SMS #401 (SMISHING) 08:41 AM
"ALERT: Bank card frozen due to fraud. Reply with your 6-digit PIN within 5 minutes to restore access."
Weapon: Fear & Panic Vector Digit: 7
VOICEMAIL #402 (VISHING) 08:43 AM
"This is Regional Director Stone. I am ordering you to bypass protocols and reset the master switch now!"
Weapon: Fake Authority Vector Digit: 1
SMS #403 (SMISHING) 08:45 AM
"Free $500 gift card! Only 3 cards left in stock. Tap bit.ly/prize99 before midnight to claim."
Weapon: Scarcity & Greed Vector Digit: 5
CHAT #404 (PRETEXTING) 08:47 AM
"Hey buddy, I'm new in dept 4 and forgot my login badge. Can you send me your login and password?"
Weapon: Fake Sympathy/Help Vector Digit: 2
LOCK 04 CODE (COMBINE VECTOR DIGITS 1 TO 4):
[ 7 - 1 - 5 - 2 ]
CENTRAL SYSTEM OVERRIDE TERMINAL
BREACH THREAT: LEVEL 5
To disarm the ransomware clock, combine the evidence from all four stations into the Master Checksum Formula:
[POS 1] First letter of Lock 02 word (Word: H A L T) → Letter 1
[POS 2] First digit of Lock 01 PIN (PIN: 3 8 4 3) → Digit 1
[POS 3] Convert 2nd letter of Lock 02 (A) to number using Matrix on Page 1 → Number
[POS 4] Second digit of Lock 03 Hash (Hash: 2 4 8 9) → Digit 2
[POS 5] First digit of Lock 04 Vector (Vector: 7 1 5 2) → Digit 1
[POS 6] Last letter of Lock 02 word (Word: H A L T) → Letter 4
FINAL 6-CHARACTER OVERRIDE KEY:
Enter characters in order [Pos 1 to 6]
MISSION CONTROLLER SIGNOFF:
Escape Time: _______ Min Breach Thwarted: [ ] SUCCESS [ ] FAILED
OPERATION PHISH TRAP // CIRU INVESTIGATION PAGE 5 OF 5
Phish Trap Teacher Guide
INSTRUCTOR FACILITATION GUIDE CYBER INCIDENT SIMULATION
TARGET TIME: 45 MINUTES
PHISH TRAP FACILITATOR MANUAL
Classroom Setup, Pacing Mechanics, Mission Script & Pedagogical Notes
AUDIENCE: GRADES 6-12+ GROUP SIZE: 3-4 AGENTS
LEARNING OBJECTIVES & CYBER DEFENSE PILLARS
• Header Inspection: Detect spoofed display names, lookalike domains, and mismatched Reply-To headers.
• URL Deconstruction: Dissect protocols, subdomains, registered domains, and typosquatting traps.
• Attachment Triage: Unmask disguised binaries (.exe, .scr), weaponized macros (.docm), and LNK droppers.
• Social Engineering: Recognize pretexting, urgent deadlines, scarcity, and counterfeit authority.
RECOMMENDED CLASSROOM IMPLEMENTATION MODELS
MODEL A: SQUAD PACKETS
Print complete 5-page packets for each team of 3-4 students. Teams work cooperatively at their table pods at their own pace.
MODEL B: PHYSICAL STATIONS
Mount Pages 2, 3, 4, 5 around the classroom walls. Teams carry Page 1 (Dossier Console) and rotate between physical investigation stations.
MODEL C: TIMED SPRINT
Project a 45:00 countdown timer with dramatic ambient cyber synth audio. Give teams two "Hint Tokens" they can trade for clues.
MISSION LAUNCH // INSTRUCTOR READ-ALOUD HOOK (1 MINUTE) READ DRAMATICALLY
"Agents, listen closely. At 0842 hours, an advanced cyber syndicate known as 'Shadow Phish' breached our municipal infrastructure firewalls through spear-phishing emails and deceptive credentials. Four security nodes are compromised. Data exfiltration initiates in exactly 45 minutes unless we override the lockdown sequence. You have been selected for CIRU Rapid Response. Inspect every message, trace every URL, isolate malicious files, and crack all four security locks. The timer starts now!"
RECOMMENDED PACING GUIDE (45-50 MINUTE CLASS)
00-05m Briefing & Setup
05-15m Station 1 Inbox
15-25m Station 2 Links
25-35m Station 3 Vault
35-45m Lock 4 & Debrief
PHISH TRAP TEACHER MANUAL // FACILITATION PAGE 1 OF 3
TACTICAL CLUE SYSTEM
PRINTABLE HINT CARDS & CLASSROOM DEBRIEF
CUT OR DISTRIBUTE AS NEEDED
Cut these cards along dashed lines. Give each squad 2 Hint Tokens at the start of the mission. When stuck, teams can redeem a token for a tier 1 or tier 2 hint card from the instructor.
STATION 1 // HINT LEVEL 1 NUDGE
Look closely at the address in Email Gamma. Even if the sender name looks familiar, where will your email actually go if you hit reply?