A Valid DKIM Signature Over an Unauthorized Message
ID: a98534d5-8c32-5859-b4eb-8dea532c9481
STIX ID: report--a98534d5-8c32-5859-b4eb-8dea532c9481
Feed Name: IRONSCALES
A senior executive received a spearphishing email that passed SPF/DKIM/DMARC because an unauthenticated submission was accepted and relayed by a legitimate Microsoft 365 tenant, which applied a valid DKIM signature and outbound SPF. The message carried a nested .eml attachment containing a QR code that decoded to a pre-filled credential-harvesting landing page; detection relied on behavioral signals and a human analyst. Indicators provided include the originating IP (96.9.214.101), HELO string (speedy-negotiation), malicious domain (gambiit.net), URL from the QR code, the attachment name (Earnings_Adjustment.eml) and its MD5 hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
