The GrabThePhisherLAb requires the examination of a phishing kit to find the flags.
Scenario
An attacker compromised a server and impersonated https://pancakeswap.finance/, a decentralized exchange native to BNB Chain, to host a phishing kit at https://apankewk.soup.xyz/mainpage.php. The attacker set it as an open directory with the file name "pankewk.zip".
Provided the phishing kit, you as a soc analyst are requested to analyze it and do your threat intel homework.
-------------------------------------------------------------------------
Tools Used
This Lab did not require any Tools and other than a regular text editor, Browser and or terminal
Writeup
Question 1: Which wallet is used for asking the seed phrase?
-> We examinate the Files in the download folder (pass: cyberdefenders.org) and open the index.html. now we can try all the buttons on the left and only one opens a new window -> metamask
Answer: Metamask