SPF Pass, DKIM Pass, DMARC Pass. Still Phishing.
ID: 7a6a44b4-924f-523e-aa4a-3f210f41b9c8
STIX ID: report--7a6a44b4-924f-523e-aa4a-3f210f41b9c8
Feed Name: IRONSCALES
Threat Score
An attacker registered a cousin domain of a legitimate Mexican supplier, configured SPF/DKIM/DMARC, and sent a well-crafted Spanish ERP invoice PDF to multiple procurement staff; the PDF and links were clean but a behavioral sender-fingerprint mismatch (display name vs historical sender address) flagged impersonation and quarantined the messages. IOCs provided include the malicious sender address, originating IP, PDF MD5, and an anomalous X-Mailer string.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
