| International Journal of Computer Applications |
| Foundation of Computer Science (FCS), NY, USA |
| Volume 187 - Number 122 |
| Year of Publication: 2026 |
| Authors: Dio Andrean, Imam Riadi |
10.5120/ijcaf00270018320
|
Dio Andrean, Imam Riadi . Analysis of Phishing Attacks on Ecommerce Services using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 122 ( Jul 2026), 63-70. DOI=10.5120/ijcaf00270018320
The rapid growth of e-commerce has increased the risk of phishing attacks targeting users' sensitive information. This study aims to analyze phishing attacks on e-commerce services using the National Institute of Standards and Technology (NIST) digital forensic methodology. The investigation was conducted through the collection, examination, analysis, and reporting phases. A phishing attack scenario was simulated by sending phishing emails containing links to a fake login website. Network traffic was captured using Wireshark and analyzed using .pcapng files and sslkeylog.log to identify digital evidence from encrypted HTTPS communications. The investigation successfully identified the phishing domain (soppieeeee.free.nf), server IP address (185.27.134.228), TCP and TLS handshake activities, HTTP POST requests, and the victim's transmitted login credentials. The integrity of the collected evidence was verified using MD5 hash values. The results demonstrate that the NIST methodology, combined with Wireshark, provides a systematic and effective approach for collecting, examining, analyzing, and reporting digital evidence related to phishing attacks on e-commerce services.