logo

The Redirect Was Real HubSpot. The Hiding Was Broken.

ID: 3f96174b-99e6-511d-a7d1-88519d50fd1e

STIX ID: report--3f96174b-99e6-511d-a7d1-88519d50fd1e

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (Audian Paxson)

...
...

A controls engineer received an authenticated-looking document-share phishing email that used Amazon SES relays and a dormant third-party domain to pass SPF/DKIM/DMARC; the single CTA resolved via HubSpot's hs-sales-engage.com tracking redirect (abused for reputation), the attached PDF did not match the claimed filename, and a malformed in-body CSS rule exposed unrelated third-party content. Adaptive AI mitigated the message about five seconds after delivery; indicators include the HubSpot tracking domain, an Amazon SES IP (54.240.7.21), a 122,100-byte PDF (MD5 79b0cd99aadac25aec75b18b367828a4), and observable structural phishing patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.