RDP Phishing Challenge

Hi,

Can anyone help me about task 2, second question “Which service was abused by the attackers?”. I couldn’t figured it out. I think this question’s answer is mistyped by editors.

Hi, for that question, look at the RDP file’s connection domain. It mimics that cloud provider’s naming pattern to trick the victim. Think of “abused” here as “impersonated.”

1 Like