A Real Intuit Notification Link, Then a 7-Day-Old Domain
ID: 46ec23b5-6c6e-5ee2-9e56-434c449d6f51
STIX ID: report--46ec23b5-6c6e-5ee2-9e56-434c449d6f51
Feed Name: IRONSCALES
Threat Score
A targeted credential-harvest phishing email used a single-button document-share template that resolved through a legitimate Intuit notification/click-tracking host and then forwarded to an attacker-controlled domain (account-maildocuments-xsaas.icu) registered seven days earlier; authentication passed but behavioral signals (single-action template, mismatched content, young terminal domain) triggered detection and four mailboxes were quarantined.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
