The Redirect Was Real HubSpot. The Hiding Was Broken.
ID: 3f96174b-99e6-511d-a7d1-88519d50fd1e
STIX ID: report--3f96174b-99e6-511d-a7d1-88519d50fd1e
Feed Name: IRONSCALES
A controls engineer received an authenticated-looking document-share phishing email that used Amazon SES relays and a dormant third-party domain to pass SPF/DKIM/DMARC; the single CTA resolved via HubSpot's hs-sales-engage.com tracking redirect (abused for reputation), the attached PDF did not match the claimed filename, and a malformed in-body CSS rule exposed unrelated third-party content. Adaptive AI mitigated the message about five seconds after delivery; indicators include the HubSpot tracking domain, an Amazon SES IP (54.240.7.21), a 122,100-byte PDF (MD5 79b0cd99aadac25aec75b18b367828a4), and observable structural phishing patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
