Observed IOC: Malicious sender email addresses

Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

Sublime rule (View on GitHub)

  1name: "Observed IOC: Malicious sender email addresses"
  2description: "Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed."
  3type: "rule"
  4severity: "high"
  5source: |
  6  // AUTO-GENERATED IOC LIST - DO NOT EDIT MANUALLY
  7  // Managed by automated IOC system
  8  type.inbound
  9  and hash.sha256(sender.email.email) in (
 10    '0004f01dc9ee385b299b774fbd0010c6da8164833d2ca0816ba648085e49051a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 11    '0025925158ebaf2924dc24ff2d2c31c8613e2023b5bae2101cb1e752ff187eba', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 12    '00d63ceac2fd6e0420e5b39810077268b95dc4f4596d6185fdd68a634acfa1e0', // Attacker-registered domain - BEC reconnaissance campaigns
 13    '01eb9fff727d15c5fac229c9db4173d44988389daf483be57e7b8f35e66bb51f', // Observed malicious sender - advance-fee investment fraud campaigns
 14    '03587843559b1c4aa44369aae3cbb618080e1949b9a316af0de465d7a60a0e5c', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
 15    '03f4447e4e825556bd7f47093b610e80f7962b0dfa62027b8e5f4315d7856d62', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 16    '054a555253046cedcbcec7ef343b0b7e3ad923a016c08c45e9346dba1bd30726', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 17    '057761a14911145dd930fac2ae3362ee5478bda82cfe87ea89aacd86a95cd6af', // Observed malicious sender - compromised SendGrid tenant, fake Teams invite credphish
 18    '062a0829f242e71ffaa3943294a6f4e9f504510813a5ee83c457bce0c6c74e11', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 19    '0637dfcfc63fda766fc8010d3916bb18d245077d519e3bb053145213a6aa4e7b', // Compromised account - multi-lure campaigns spanning DocuSign brand impersonation, mailbox suspension credential phishing, and shipping notification lures
 20    '072ad26b13508033eebde6e5070cf6d8aa09d7414d64da7b69bd82f6e8f683bb', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 21    '07447603538582dab2e8ee62920a7435cc9b756bcbc7f94054d373b6232460d7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 22    '074a551f4b57f71c7f051b4fce84f8e3b50f85e28afc45e3b55384279571a268', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
 23    '08706553fd4f1e3d3c1ea05f9b2520e210cc810d93c3f34036db5a119544178d', // Compromised account - timecard authorization credential phishing with randomized display name suffixes
 24    '0914d7505e63c31c497bac8cc2001315edee6cbb14d7dd2a125efd06ce0deda9', // Compromised mailbox - BEC enquiry and proposal lures with fake email quarantine notifications
 25    '09c62e04e73beed174d8470d9d212a0ec0127b5a2972cdfd2ad8a654eee4f458', // Newly registered lookalike domain - fake insurance policy delivery lures with typosquat reply-to
 26    '0b02e4dd86f69c17a3fb3b579904120bb3be026eb4049a710627c6631b574bb8', // Attacker-controlled domain - fake SecureSign document delivery credential phishing
 27    '0b9c2c2dd64d54049e0e53507880a250e675ce3d68b51b0ee2165f2ea5ef8903', // Compromised account - IRS and e-signature document credential phishing
 28    '0d3de488a096b39ceb2db13ba7f68374049e2de2e0be6c2da9ef0d83c9337d24', // Observed malicious sender - advance-fee investment fraud campaigns
 29    '0d708fdcc014db960b64ce93255c64a60884612cc2dc9c830b5638b950b4fedf', // Observed malicious sender - BEC/credential phishing campaigns
 30    '0d7906e61f89af2bfbe63d749ec7681950410a81819baf307ed26a2a4ceb5605', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 31    '0d9d6401c0cffb024be34cedf19034966d01454e802cd2df9206a9eead1823a8', // Compromised account used in BEC/credential phishing campaigns
 32    '0f1d80cdfbcd7b28945e0aa96ca1adbf3e69bc9b3c80b62bb240254df8bf6d24', // Compromised account - advance-fee grant program notification fraud campaigns
 33    '0f8669d310832e5e053a7c29e9d08f43c143f13a66e48d7e0e9852659083cf2f', // Attacker-registered domain - supplier quotation request BEC with lookalike reply-to domain
 34    '0fd0ddb531936d777000be33631274260d81250c833ebf7c06838a896ea3601f', // Compromised domain - SiteGround branded domain expiry phishing hosted on compromised WordPress sites
 35    '0fe6070072580c44577931b8b61febab507e1721439481777a3c8ef218950189', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 36    '1127c5e25e2155b4e9a1aa7ebfd0269373697032eb6d037b2b1773636620777f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 37    '12170cccd307602216eac235d3176f547ce89fb492eccbdbed19a2748f7264fb', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 38    '123cd0a3912744f55f3a3c8ad7401f44112428ea6fedae38eca48a468bab87d7', // Compromised nonprofit executive account - EFT remittance payment fraud and thread hijacking
 39    '12e43526e75cf27e10b97b0c1d7f673028450020031ada7e21525a12ad174724', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 40    '131f2f1f4d53adf813008ef0442f741800589f6c80d2ed75022de3cbfb19699d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 41    '14f25726353bf0377a6f0dd943e3fea2ee8dae88995dcb9997560fd00d17b155', // Compromised account - Air Canada brand impersonation credential phishing campaigns
 42    '16527a63209b668a15eb474b91b7bbb7a5c8282e4dcd8ce68044772677855c2b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 43    '16599313a98b7432e9756a1c4ab7693b454850ba025a23a656d15ed643fe2014', // Throwaway/lookalike sender address used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 44    '16944bb3724b4ecb0ffcfd5634fdc373b76891e6689e754154032777ebe12c6a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 45    '16f9b3c2bb2663806fe91a6c76c0033018b7d090488076cd3fd4c9bc0c3ff799', // Observed malicious sender - advance-fee investment fraud campaigns
 46    '185d468c1a67af5f7943dfe4142e6557f027bce99c3fae3bb5c532358806df7c', // Observed malicious sender
 47    '1899d688514d0651536482339e377683b86b96a0eb673de2badef384a8f7f3d4', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
 48    '18ac731a9858023e2b59114b6a861e10858c8d577ddf7ca7f7dd13984166a83e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 49    '18adc07eaac029b344fa1b4652c684df704ea88ff468eae0caeedbab0851715d', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
 50    '19c288bd2baa150a12078d1310c3094b2ddd7fda8ba42d283be861a50615a924', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 51    '1a01ef4c29dcd924f903c6d2af54335acecf5e2289a41d69f1799005d07a8a0f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 52    '1a80fa436062f7deeea549b7f4d2b9db44c4ffef9d153fa8566a478de2876118', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 53    '1acbc86f2347911378c5803f3fff4b2db5e8355ebd1a656e7da89cea3b4479e0', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 54    '1b3f7a9f96d368268612f38aa535178ba2905ded7773a7dc15a93628bfc854e4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 55    '1daa2ca8844ce276e570e75eaf1562b79086ad846dad24108646c066b97961bf', // Compromised account - mortgage payoff and title request BEC campaigns impersonating Shellpoint and Wells Fargo
 56    '1dc7009cf08e4a9891c9e9fa26201263f29826ea71bfd629400ec376a58fda00', // Compromised account - fake financial planning report credential phishing campaigns
 57    '1ed0614fc9117f62d629d47f93bf2bb7ab0ca5371557818eb8a983f41b2f0f9c', // Compromised account - Zoom meeting and e-signature credential phishing with link shortener redirect
 58    '1f9f044f5f4f108480264b5df8b623215c9d2e425331a22d67e6709fce0bef0a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 59    '1ff9e668661c28c3abda5d497fe4966037a01e10063bcd1d644b8ea21bca92c5', // Compromised account - Google Calendar invite document share credential phishing campaigns
 60    '2040a34f81cfa9b83e25fd49aa853ea55e2af03c2f6bb521d02babc94c25359d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 61    '204eba38fc8bee6f69aec26501c467259dc7edf2bf0bab8f90ca9d73e382c38b', // Observed malicious sender - advance-fee investment and project financing fraud campaigns
 62    '204f687ffc062cec92de70d4ff5e75d78dc017271ceb6e2c02e26f43fe999822', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
 63    '2383fd0534e334243246377850eda12c5a29edff93259caa91e543acef30fcf4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 64    '23c62826bbcf57ba73b802de9ff676e7c470ef20d3b6651a81b371fa3e00bbf1', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 65    '23d30b83c60509d03e79c2673ab0c1b9a9fe5dda07a2198df43038cb153d7ae7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 66    '2428a08e180812cb74fb0930df94d299f444403a4cedc2fdb958e4de0ca72517', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 67    '249fdecf8c13707087a66615e8777af844873136dca22dce66955a9fa0c62f54', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 68    '251a75c039f8a8084b1946923a671bbd3370283fc824fe0f9ec2faccb6f0fd4e', // Compromised account - Google Calendar invite proposal review credential phishing campaigns
 69    '25e051ba53581c25f8ce6281b74e56e027c421e090c2d4fa6c16db9da9cf0919', // Compromised account - DocuSign branded document portal credential phishing with recipient address in URL fragment
 70    '269e21e213e3e7db224f86a0fa4fdd5c17040abaf42eeed5b862ccb14965af78', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
 71    '26b456acbf4b9e71ab3f94c9c535aa7d280d99b00933dd152be5b7962639e224', // Compromised account - domain renewal payment phishing campaigns
 72    '287a3feb51527264b034738d5f654c9c3f6d4d85ab8ea0f9e04defcd42c85f95', // Observed malicious sender - BEC/credential phishing campaigns
 73    '298e3bbd5441f58bf33082da80ae0229cd0fa17054e3432199414a4706d05bc8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 74    '2a9b9e226f23ec6375ea7fbc73d2dfe2bfe4d0e09a8ed002226ad2c54659ba50', // Observed malicious sender - Chinese-language enterprise mailbox credential phishing campaigns
 75    '2c61e0a0f6d48553de52c70d5c84242ee8b550016aa6fdb36abd9c8d7daf624c', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
 76    '2ded1c3fefd56268abc47bba7573bc15cd7439037faa2b99044e205402f5ade3', // Observed malicious sender - BEC/credential phishing campaigns
 77    '2f8d025a9102603953c1a16e888bed90edc72e9eb34b0a8ef05de2e666ec4292', // Compromised account - ICS calendar invite fake document share
 78    '30497db58c2865530f352d8605072c6cdcb553d496ab237fc3196f3133795c25', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 79    '306bddcc8efbeed15553380ede95273d10438f4e4d8190963bd1cc58178560d1', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 80    '3190d9232f76f2636a06b1e39d934ddd23774e978ff5a5239eb4aa9eafd5e806', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 81    '36387b3610f581c3ff95f77130dc8faa8cf2046b0e610f4138bbe89651f4afff', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 82    '36eb7b8532befd5335eab6ec7bcd54d35428be2357d6caaa6421c20f1c6077cf', // Compromised account - Google Calendar invite bidding process solicitation credential phishing campaigns
 83    '38a8e112af8d9252b3f51a8ba94003631bc4c9bf6ef60941521169382c8f546e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 84    '3a11180346d6de0d66d38dfe9482b0fd998183d30f10d02940d1caf458457d16', // Compromised account - Polish school domain used in BEC campaigns
 85    '3a61963d39790456dae1ebe93b0a61c045fb58eea268a91bb92c4a622b01504c', // Compromised ESP account on active business domain - credential phishing file share and past due statement lures, short TTL due to legitimate traffic
 86    '3c6d0480a53df3b3c3e2c27a210d99d9704e02814e1d11507e02490695eb8806', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 87    '3cf5c3a0b8481997224e3397bc52c754d52558e9a3c3ee1faf02c5e58ecc58c9', // Compromised account - ICS calendar invite ACH payment verification lure
 88    '3d3f43292b599f983be6822151540437c86fce4dcf9f05e7dad94f3cfd7aff31', // Compromised account - purchase inquiry BEC campaigns with typosquat reply-to domain
 89    '3f9e2c465ed00925b6904065f599c2a605ee8f15f9fac73626754d28839e370a', // Compromised SendGrid account - credential phishing with randomized document review subjects
 90    '3fa83cd162a4f95f91d8cd28016dd8b1e557ee3a96e98ec0110ce7f22e387a24', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
 91    '403949574d735ce2301d06f5dec9d6eec3f532fbf44c01c85608ac5ca4548e91', // Compromised account - Trafigura impersonation supplier quotation BEC with lookalike reply-to domain
 92    '40742af9c50cbbdd54fda2fedaf88429d78e34f6df5cc0b34fe7851b354472cb', // Attacker registered domain - fake billing review credential phishing
 93    '416423ad3b195a68f1f8cea67899e4eaf97428c128e2ae30c3fa607f8951c0d6', // Compromised account - Vietnamese university domain used in BEC campaigns
 94    '4329b35c2cbed4d8f479f1b8d0bae5f255d292714d3c80e3366d7710fe91a238', // Compromised account - Google Calendar invite investment agreement credential phishing campaigns
 95    '43e610255bac2342a7f16f0a442962e8f9a13b90a37425d31ddbd88b058d0d9d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 96    '48736e8d6c36f5232121bc9d9f0a148a09430a3b718695ca296abcb067530284', // Compromised account - Austrian school domain used in BEC campaigns
 97    '48f87ee437793b1d2f8faf51dd2a5748f7a67f67fc0b168e861beeb28f371b59', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
 98    '491e0d4561fbe866b20d6aab02fc7946b1483e4dea0e4c1493aae7ccac292317', // Compromised account - Google Calendar invite Google Voice notification credential phishing campaigns
 99    '498030e0191b3c9b464b6c92e852a99e6ccd7989d95afd60c7124f45daec7ffd', // Compromised account - quotation request lure BEC campaigns with mismatched display name
100    '4992b89b6a829fb3b2df195a325c6c73c4c0706f87ca663e7b92d14700bd4533', // Compromised account - rotating display names in targeted payroll and treasury document credential phishing
101    '4bd612d0513e4be9d62a13fff090a163b7fe55534ee8cd6a95b4f925d558210a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
102    '4bd8d89c85ab0a7ebe69f6a9136f5eea8506e4bc5c8a09108db6bf48e5d8ee97', // Attacker-controlled domain - ICS calendar invite with Google share.google redirect
103    '4c254e837ad5e81e0d5316f4a12030b6112577955af3ab7900481835f555bd7f', // Observed malicious sender - advance-fee investment fraud campaigns
104    '4c4801bea710a8a5653b1396d139cc4fbf731791dbbf3f21305f2b651cd62d29', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
105    '4df47bebfb4e8c9f8b486fad6e3045ce529835572cedfcd6890bad30cebfa8d9', // Attacker-controlled domain - N26 bank credential phishing targeting German speakers
106    '4e369c5bcd4380ff2da76b495727f0faf53a73dd3c5da8f8bb941ddd416b7b3b', // Compromised account - domain renewal payment phishing campaigns
107    '4e6e32b31f295cc2fdd1f88bb32c7855ab2e760f21cf834f97abac9e9db68d47', // Compromised account - strategic partnership solicitation BEC with randomized reference IDs
108    '4fc1f40c3dce21cdc1416a0932cdacd9b8cf20c6cd8993c3f5784bf4d6b9fc4c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
109    '5088966877d8065394ac600df092d315bbb7e8a3ba18f1bc1e46bf12118bbc35', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
110    '50ae47f0a347fc4f9403361b5626f2397657d768196afe7378fe613e9077102f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
111    '50b954f90cdce83f741dacb8ab75ebb329e446302657e85d0ad5e538c6059f8d', // Compromised account - domain renewal payment phishing campaigns
112    '50d289addef8c2b6b33f72f069f979042f0878135ed471d00c3a3d1070a0f3d2', // Compromised account - device code phishing via fake legal case notification hosted on UiPath cloud app
113    '51085bd2a15074f19fd307da1867258dcba93a33ea9a672079a85efd54ed243f', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
114    '54e9c00529e925b43d578e8b1cb5efa2c634992ff871b98715b10d96b49c97c3', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
115    '5502acdf89fe972ba391e8aa9355919a1c3f920947169bbd23da5c6383e18433', // Attacker-registered lookalike domain - fake Google review removal scam campaigns
116    '563d4aedcf31889fc01fc1c240622d35285a988856bad72f11c5f85ff7372ea6', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
117    '57bbac04d703d41541706ec03ff4d8fee40b52b3343224a9e85baff3ff7de90a', // Compromised student account - fake forwarded thread and fake photo share link phishing campaigns
118    '59f89167e3c871f5ffb2555333b868a28af9fded8b99d5718b4c760ed98bccb3', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
119    '5a03383efec90551b7cd2dca400b07dc9c99479d94d904fc0133dac1814a4d91', // Compromised account - ICS calendar invite fake contract lure
120    '5a3e0172e9f47403a5211107fa7bf4f9e4c123db10bce71a56dd24dab210472b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
121    '5b30df912ea94e42843ba0a7233004b7ad7d4cfe36ca29110a89dc60fc69e9f9', // Compromised account - Google Calendar invite credential phishing abusing Intuit notification link redirects
122    '5b508f66848ab601fd3544c927b095362b884ff7c96a863e5c4ca898b25ba290', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
123    '5c0ee499a0e284381b435296d99e3483cde8f8f1da31a89fe4b9b4e7ffa9410c', // Compromised account - domain renewal payment phishing campaigns
124    '5c5ad5fda56f9659a2c1710d37f94eb2da19e941e75d9b59ccbd85b44a7b99ed', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
125    '5c693feb863201cf47f7845815eda91bb3f5cb80d0cca995f18c939fefecf21a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
126    '5ec704a8f5f01a6fa672656573abf9c70154a1a2af0a3123406afb3091ef0537', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
127    '5f3852d1709c1599749a64668e89f8aa7c842a85ca646f9980c0a1fa58d61818', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
128    '6006d47a8d739e6f5231b49f0d61767227529f6405e6b502d7dee958db22939f', // Compromised account - Google Calendar invite RFQ solicitation credential phishing campaigns
129    '6057ccf37d8286e1ae7d8dfd1789fe60791f2bc39600631f0551712cc8661e5e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
130    '6106f4d9431f6f990a68d8de4bf194e5ef5341ac1ba918697c0635b3f93fc77c', // Attacker-registered domain - fraudulent purchase order BEC impersonating equipment manufacturer procurement with typosquat reply-to
131    '61fffa77073ca73875d1c738fa8a9628440a07128e50d4b6be57e8a195a4afd5', // Compromised domain - myGov impersonation credential phishing with Australian tax payment lure
132    '637bfb85dc1f4f13ca89f1ecae0ea67745800e25d2ffe8a7ac89ac3fd961c944', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
133    '66771511747b19c3015adbbadd4e1d54d0db51c646f3c28b34b1fa09ee772afe', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
134    '6777231b6c945ebef989e3c0cfd506bd36f312e4e72759c20240f975efba3b00', // Compromised student account - fake photo share and fake forwarded thread campaigns
135    '682690942d17fcfdab558aeb4dc2731f51666adabfad813e1f4b6e3843a2c605', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
136    '68cf1bca691f867a75e175d94086e2c3d5b65fea6ea5849b8dc3c2f2b469ba7e', // Compromised account - ICS calendar invite Google Voice voicemail lures with Unicode-obfuscated subjects
137    '68e096fe2d9e586026cbe19d4b718ab64b0f4aae0aca3021c0f77e6f5e7512ec', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
138    '69bb39e7e9fc344ed53bf59bf46ab39601ff098e1fe28730f5dbdb6dd5cc2e92', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
139    '6a89cfa7f865f8dd85b314cadb52092fd42beab427e1ff8a5d9059dd7e606d87', // Compromised account - ICS calendar invite RFQ quote proposal credential phishing campaigns
140    '6abb620f683ee3a848295b4343b27d99c8269f1b1e99061d04f292730f1c15ad', // Observed malicious sender - fake voicemail notifications via Google Calendar invites for credential phishing
141    '6ba83ae804722e49e6e3b876b5830dfe6044b5b8767aed9d5b2e2b168b835cde', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
142    '6bc270fac6bed884311689fc339a2d5953638d7909359c61348a440de9caf9c1', // Compromised account - purchase order fraud impersonating Manitou Group with typosquat reply-to domain
143    '6bcb6d890034877d208a211b2b2fc4e34e477a4a588c610f7ddd6d4fcad30821', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
144    '6d2c29e0d973404059aa517e8bacbbbef7fb7644486f1fdce6c4924c32e3d9fd', // Compromised account - ICS calendar invite voicemail lure
145    '6dd1daf7fab34d399a3307b0ab85a2c7d4ae4f9e42e0a226811f6d4d362b9d4c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
146    '6ed87d7442a9c67238272ffda2bc11ab7635fdec57fd58cfb289da585eb7314a', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
147    '6f9a75a9a30c46798d67cf29265c8fb9255d05f9929156470c87e85a19f83254', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
148    '6fcd011c929ff7d871d21375e5e9468b49397a566524bc9f57ec022dbe047c04', // Observed malicious sender - advance-fee investment fraud campaigns
149    '7044b353baffec52f9de4bb653e76485c6829328443d7fbd6f38fdd160c16055', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
150    '70e1030db9d32f156df07d445ee2bdc71fa37d3e9cde4418c5db6e2560f711cc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
151    '73267f82cfef50641282935512e3d291d2c681aebd58c8ba7950af8236626912', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
152    '7516a9a2ed9016192434dd81db055d23dccba29731343f12be7f7dcb324a439e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
153    '762c9ce5b716f3b385559fb09e7510661267797ea556eb866cbd1727424fdaca', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
154    '766d628cd39125d9a6bce62dff3203cdc47d1a74e83f05157ad4fd28771974cd', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
155    '77dbd254b71aedc57d3247f9273b23a0ff191ebeafd4fe231048959f0191d524', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
156    '77df91f5bd3c2e212d6a97a37f9096c7066a38ef5df4da445a83a5a8f8f94500', // Compromised account - fake voicemail and remittance notice credential phishing campaigns
157    '7c711457c1affc6bdf1a622a22f81f624e034448548e625117d1091f848ddc7c', // Compromised account - ICS calendar invite document review lure
158    '7c8569f4156a396673e5509f5c3a4b1aaf30761802631478bd59bec9c2ff0459', // Attacker-registered domain - German language inheritance advance fee fraud campaigns
159    '7d3ecab1afc389186703af31545b4b7485ff20ad130167d641a178bf88850f1f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
160    '7f6a1cadfd6cbdc412e25021725006324d84aeb4ba3e366d772e92887937bf15', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
161    '81c391208275700266de52f05176151b490fc98ac303c69aade60c4dd7733e6e', // Attacker-controlled domain - numeric-hex reference code reconnaissance
162    '82f54cefc0ea8ea3344762e170acf0511ec0102e845c2b72c0373de521fa36d8', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
163    '83c22c9f165fa33fe708cc4d7dac54fb8daa30cfb9bb38e603af1b18d413faf4', // Compromised account - recipient-personalized report notification lures abusing freee.co.jp marketing link redirects
164    '8492466cf682afff67250cb3918967951f97bc3945a6443ecdf1ad0e63873f69', // Compromised account - domain renewal payment phishing campaigns
165    '8797ebd0fe0fd6e370fbdece9bb10a2ad341557ead0533e488bc6fffc9e5ea3f', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
166    '87eb1efe1ab4ff5ef8767c19f6ccd837b2dac092b70092b56e3e59302035ad84', // Observed malicious sender - Norton subscription renewal credential phishing campaigns
167    '894310051f1fe1fde08f6254d7909481b182338dca784c0dfc4c8b71134cf776', // Attacker domain impersonating Indian bank - BEC lien waiver fraud targeting construction companies
168    '896ce3441bc7c3d3dfee3f8947965492ed7160596b8f09eff9f625412b5a619d', // Attacker-controlled typosquat domain - ICS calendar invite fake document share
169    '8a47d2234827f5ded1d6bc235b16bf78b6f993c5799b4145888de15ba9a5e741', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
170    '8b6199148560383d2fca031052475ca2627637fdf4a883dd475c9f3a51d39887', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
171    '8bd7bb8d8e31c7dae087785d89ea17f199041105cd97bdc7cebd47ddbf9b4cae', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
172    '8c4ffc408b379a7649bef8b6fe6dedf467960627897eae7742091d98fc79a263', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
173    '8c61b30c46de11fd376026587646066325cc31f9749381abe2280b1fc1b58fbc', // Compromised account - invoice notice and ICS calendar invite voicemail credential phishing campaigns
174    '8ccd1976165c5acf2be6d44e89c95808574b584a2289354059554ba92f3ee355', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
175    '8d0a6552bc32f3704106dcbdd393c73ceb29a4bbfd7f0ec207ea438c757b608e', // Compromised Vietnamese bank account - advance fee fraud gift and prize campaigns
176    '8d14a081e8cf17d9101839290dca690a996b910d175e9ce2f2595cb395d6cc94', // Compromised account - domain renewal payment phishing campaigns
177    '8d6d35f92d52490cfd8c2153a979604b95aabb430eef256486600075465e80b8', // Compromised Kenyan school account - thread hijacking with credential phishing link
178    '8f70301abb6faa9b1b0463bda1a42a153a49c849dae45c24ca087b49cbd6f16f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
179    '91fe8f768fdef0efacb6325ad65b4d5922789d49dc2b253e7e352367ac8608fc', // Observed malicious sender - advance-fee investment fraud campaigns
180    '92b022313ffa3406da6cb095c2f8aa3404b401fea6ff9786f748663b9da6539f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
181    '9472ab67914ca4eb86fb7c4b726bef67c194bbbd430871570e53ba148099c502', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
182    '949999f91a3feac5a7b82ce881d1a32f8aea674ff928f5a7f8950076033272d7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
183    '94a586de7ec274964f27506d5f27a6d717a1d472306017737ea067830889fb98', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
184    '955ae08074c3cf8fff4143461c371ece9690921a27896d18b3c34f6afa65b48f', // Compromised government account - service solicitation BEC campaigns with mismatched display name
185    '95f01da32fea6a5c28b5453568b7d3977a76e3ae42e7375534f22cd5c43c089a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
186    '970950880f23d7bc62e6e9622fabb162f846ca06134163b426951c4d62db026d', // Compromised account - fake eDocument task and Microsoft Teams document share credential phishing campaigns
187    '99673797051adaeb68dc8b07624ba300472cf9cff1a995fa1f95d8b6685374dc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
188    '9ac3bc28005ac615607c878c119118698b368217633d616082bd6b619bca8224', // Compromised university student account - advance fee fraud to undisclosed recipients with freemail reply-to
189    '9ad52736e4eb32a906e646cb4c16f38c318e44922666f59d1652b85d2a7a7680', // Compromised nonprofit account - ICS calendar invite credential phishing
190    '9b3afc720c7975523f572be5e2b8e75a2567257a834e73ba3c11eeae4c53467b', // Attacker domain - fake eForm/spreadsheet sharing via SendGrid abuse
191    '9b4bc1752d36bb4718a2a30342761e8ccecb5d64dc9164c3127dab30614811d8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
192    '9d20cf849102d8c4bfec9c15c2d79fa408502657a4455cacaa2bc725fec078ae', // Compromised account - tool giveaway lure with Google Cloud Storage redirect
193    '9ee9228bc6dcb8628d144d63c21d436f427719672dc1ff01e9f5845059424ea6', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
194    '9fda882aad59efabf9e2c45a9f1490e87deb323de5aedcf80b4bfbbf1c21f8b0', // Compromised account - fake eDocument task and Teams share credential phishing campaigns
195    'a18ddb2b10a3a42bbbbc6300dce305703607cf9a12ed737da9f5576b879b1113', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
196    'a2bbaa6824197630b7b9fb12296405481f6d2224194559c1ee39a635f8603cfc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
197    'a3b5cc5244de712715f1ff645eef860ee5e0f2e9e86f1eee79930224f642d9c1', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
198    'a3e2ac92f5de8d20c54480ab3a61f33be788de8e9467bc18fc5e0b6a0d6da2ed', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
199    'a4312827c4ed4900fa06d6f3058edc203fe85683b6de585d1fae5becd4700a6b', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
200    'a484fa16fb013b579b1f4006cc42d20da09541271c5f93312b4d02dbeba8385f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
201    'a4f740abf0fa1c0a6c26a9acdff1248e6cd147b392b5806028515ae3da389785', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
202    'a5e72048f261715f3e7ce6d2cc8916bd2a3e230e5dba3f6bfa3fbf8756ac7381', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
203    'a74606dc787d5e75866029b343dd8c08f083d8f9b086362b9fb20f071e79a12b', // Observed malicious sender - BEC/credential phishing campaigns
204    'a867247b8ccfc2299abe14585264d8a09bc1786f8ca4e2340ebf7c276b0b9af7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
205    'a86a143662cf3c933ae792e1fd48819a41142c97453fe675d6efb4a29eca927c', // Compromised account - Google Calendar invite bid invitation and partnership inquiry BEC campaigns
206    'abd5ceb9b3abbd53544b99ded01b9a993c38b3133b0905d62006f8d378e5f8d8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
207    'ac3af7bc7aa52ad34365f7659070dc858ad4eb09aaa9f9177ba37adbdbf60a48', // Observed malicious sender - abused aged domain (SPF none), HR/payroll credphish via encrypted-PDF password lure
208    'adea82cef2ef6c53647457513d1f0972dcafd4e5ea093a977bbcc8a4ab385d1e', // Compromised account - venture capital partnership request impersonation campaigns
209    'ae42584dfd37653be7e42203ca5b6ad5508a639726ab5cbb65ba58085e54c6b4', // Attacker-controlled typosquat domain - numeric-hex reference code reconnaissance
210    'aee561d4926ae4535a732b4649ea27a5ccef7a18b28775b162d095e11820a52c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
211    'b044f948af172622b44fec0affad51861ff32c5f6ba5bcda261293e35a6b5d3b', // Observed malicious sender - advance-fee investment fraud campaigns
212    'b1636bd79df0c1cecfb3213ffc0f921d23c73435cabcc2ff03c759c14c896170', // Attacker-registered domain - completed document notification credential phishing via marketing automation tracking links
213    'b282f3e253bf6a2aa02d484f2edacc2f20338ce37fe157d8817ba96321af6766', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
214    'b2dfca515de73047279efe855337aa3c7d6179f7b0d7dc35921fb0377b618baf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
215    'b325f09c58d698fcde5274662e2c9ee4e49fb8030825e23450b53cec5d546c5d', // Compromised account - ICS calendar invite voice recording notification credential phishing campaigns
216    'b3413ce41fc413b11ba8fd0b58c71e3a811169cc2ac783154eaaf37e84fe7bbe', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
217    'b3a315352bd909eee0c773071df508ef0487f0180df22017c6e5e5eb40d77301', // Compromised Japanese company account - parcel delivery credential phishing
218    'b3e89ebfcc45a1fd5f254b8d04c5275d968af4618a7a8c5f6cc75b8d941bd448', // Compromised real account used in VIP-impersonation invoice/payment BEC with fabricated reply threads
219    'b3ed5ef14f1be181d2e375ad4d3d29a3b0777ec5fd162c9c36422962d2dcfd7c', // Observed malicious sender - BEC/credential phishing campaigns
220    'b45eb5412cc803dec77d6c7abea7ce0e6e3abc72ec75ac19a4f16c9cee65b91b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
221    'b4751533eefe4d0cc630fd5dce52e043a1ff6617238b2ebe3b7290899bbe241f', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
222    'b53cf0459ca41ca4c51c15d4be23113aeee4d77a77f7f01761e416b6896011b9', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
223    'b6df58873af5b6edde8f19e46bd7ed10bd0c7b61d4adda29506b05c5f0ef057a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
224    'b707848bcdcf5a385ccd43e428c5c1f09ab1b5b0076e95fbf5ee98780fdad8a3', // Compromised account - business proposal advance fee fraud campaigns
225    'b7415f1380d0a89b124bce7de8b1eee96dc452f9c95252192176cd427020b060', // Observed malicious sender - contract agreement BEC campaigns using freemail reply-to mismatch
226    'b77161f16370afbd32afd8e613be5ffb1a9d9e99e1b8d3e547cf6379ab55c6ca', // Observed malicious sender - spoofed sender in fake forwarded thread membership invoice fraud campaigns
227    'bb24567ae519d6391aba7c28597fbf84a1c9b283bcd9e8d9383e4345c7ee0dcf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
228    'bb87499a229e0f70ebd20d8d3be83d426c898c01ee3a4b8706abc5d78d9146df', // Compromised account - ICS calendar invite credential phishing
229    'bc7822660da2eddd2af07cf2180e50c7a56b303390cf1144614f5143d24fbf31', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
230    'be44430a667b7776e351cf54a66f85716de0731dcb1245b7c5bca081e4cd80a5', // Observed malicious sender
231    'bf5d4be8d2cee2476e9a226bd955f41819e4b01976f9bbd91b58bc82f057d4f6', // Observed malicious sender
232    'c319fed85def0d337780b2f93c18fce8aee32421b822a7b1554ff7307a142012', // Compromised account - sales invoice PDF attachment fraud campaigns
233    'c35764206e9ae5372498a5c7562e52632a0ddadecd1973d71b9d448624ae3b16', // Compromised account - urgent notification lure via cloud-protect.net redirect
234    'c36ab707c4867b70407bfc0d9a4b069350080fdc820626f9a54f88ca905a3c97', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
235    'c5dfb0030991c22aad632fb5d57e7eac57f6379ff3165fcf5d170a6d730c4538', // Compromised account - ICS calendar invite fake document share
236    'c75f2d07928e315171113031a6a1a54bed3a6a6cd53b293a8e9015222de1fb32', // Compromised account - supplier purchase inquiry fraud with typosquat reply-to domain
237    'ca2e7c13010d96bf2286342dc7ea87ec67232e29b5e659820210e01cef273081', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
238    'caed0ffc5a2f2858ef33956eeaf3f1309467e352506dbc200bed299a3ce71420', // Observed malicious sender - advance-fee investment fraud campaigns
239    'cbb683f2108bf5c91e5da136b20d94e299bd8a027311afd10f17575f0a166f19', // Attacker-controlled domain - homoglyph brand impersonation with open redirect chain
240    'ce2be5b5f5f2e6d1d9d8619c832e94cfa804ce4839d834d1af510a769e7a7d16', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
241    'ce2e6f79ab6c8ea45992953e454d96c0ee2a5efe2e92d6ed571f13bf82c99108', // Compromised account - RFP invitation and business project solicitation BEC campaigns
242    'ce374e281361708cdb4f456b44a0e95528a7a428d602d9f132aac5b5aa9826af', // Compromised account - Google Calendar invite credential phishing abusing Intuit link redirects
243    'cf073a4affff5131a6f53c8d3f62548e6a453f6ceff16d6f784e115f5fae6038', // Compromised account - domain renewal payment phishing campaigns
244    'cf75ac0cb2baeaa1bf657101ca7ae0c300398509298f615e3d05fea7216da05c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
245    'cfa974b119ad8212b484a0229914ff1405ca9b8c7489166420986b3576b7da7d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
246    'd0c976c4f72edb8094a4258e4c1bbb3b21ba17c30e0e95f7e32e5e8457c43335', // Observed malicious sender - Robinhood and Interactive Brokers lookalike domain credential phishing via account security alerts
247    'd74e6eddf9abd425d77adced3fb56eb96a164b2a56a28e0d75d08ede43d51cd4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
248    'd7a310ef6cb3f4e842b17d268a52391675477f71475b63a4cf1cee6f9bd94ff5', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
249    'd86903bff85599facfd0e178670e77f500fb5fa84ca2aafa20f245c0a6e0aa05', // Observed malicious sender - BEC/credential phishing campaigns
250    'd931f0c6ddded184ac8e0a6dcdb356fc0d4f64fe2c852f587db149d942c2e5e3', // Compromised account - Dropbox Paper credential phishing to undisclosed recipients
251    'd9a945c87143ad54d536e4363cac491dc31b2f75891063a0d1fa776381358ddb', // Compromised account - credential phishing with recipient address embedded in subject targeting education recipients
252    'd9b1a194be864f755ad19767c53bfc54dd27fb69464fc9d6b0729f4f82267f42', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
253    'db92038c5432edd7ce1df22ae4ffc173eff2ab6f6dc9f77e435b6437d6a788db', // Observed malicious sender - advance-fee project funding fraud from newly registered domain
254    'dc01b1e4b74adb29a9e2ff4f29a34076f61c87cf04f620cef525d5070818687c', // Observed malicious sender - advance-fee investment fraud campaigns
255    'dcf926c300e21c985ff97951bb747662f4d89b68ebd2ec2346792ea69534cafc', // Attacker-registered domain - realtor-targeted program eligibility confirmation lures
256    'e02c4ad389225617a5fe12c012348a928f6c2159b378afb28d4d1f5f1e541376', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
257    'e06aa193933815324af2fee9d3c250dab080a681b9658253ce2b0af0466cbbd1', // Observed malicious sender - advance-fee investment fraud campaigns
258    'e0da1bd70a04552d8104ae6d11b2eeb477b6dc8ecbd257d5dcde3bec0127044e', // Observed malicious sender - bid solicitation and RFQ vendor impersonation campaigns using typosquatted reply-to domain
259    'e2dd8628371377d56c761817ed6676c5ccd2e9870f1b8cb7b63467f0d387d8fd', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
260    'e430fdb030ceb6fe3886338084b9bc210bde348930cd9e94ff2e978d47dca0a5', // Compromised account - Sedgwick and State Farm insurance claim adjuster lures with Office attachments linking to credential phishing pages
261    'e496f21a9a64bb06d1c3c9f3ce6df5a4fec04e513e51c9d05d6637e48036e9e8', // Observed malicious sender - advance-fee investment fraud campaigns
262    'e7c699fb15764decb4193d06537fd56d2ebb7e6af19919dd9b489815c200ea2c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
263    'e9c2bed0462383568a1ac0fa73058693c34f06f35293388bc742a6f055d07701', // Compromised account - Google Calendar invite voice message credential phishing campaigns
264    'eaf8cfe2d96cdb4f17819f77aad91fd9555fb82be5124b112a70d252f92219c6', // Compromised Japanese company account - vendor invoice BEC with fabricated internal exec forward in .msg attachment and lookalike vendor domain
265    'eb6fdf648b34efa0d7eed5ac971d12d2fbc5d8f8fa3c5d3abe7d307b3f1367f2', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
266    'ec9c01b0c4fbe5de2fb5065ab31cfb80304179a889a513f8bae112cc5d544331', // Compromised account - remittance notification document share credential phishing campaigns
267    'f0d099bfdabc2c0ac8f8561a64d66e9e6ee1207fc560db8fe07771fbfa4bdd52', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
268    'f12e13befd897b6b9ea41f1b299200fd71fb5137d6c0866f5af0984ac91a30cf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
269    'f2231cb4a71ce384c1dd949af538dd25761776366a0f0b76ed4c889aa6488c4d', // Compromised SendGrid subdomain - fake eDocx pending task credential phishing
270    'f23450c74fbd8e5379835a6961f3cb92f0222573f6839469384717b4f1ed46f2', // Attacker-controlled lookalike domain - procurement sourcing BEC lures impersonating an unrelated metals supplier
271    'f4116dde162ca98aeabba276d40e2d7306b4a63332b67dc994bf9278452a2c60', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
272    'f47441d1d8080fd855a7ebc8ba3549958929f7d2acc70417438319bab03531bf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
273    'f5ee438bbfbde02b493f726c06351325bfc31085e3056aaba768db9211893bc0', // Compromised account - fake webmail password security notice with recipient email in URL fragment
274    'f7134c981f996cacd56e1e541ba5179cd35292078496e981aec26fea016a3e14', // Compromised account - USAA claim adjuster impersonation with PDF attachment
275    'fa0038a882392e5496003d074ba4f627b377efe20e2cbe8aad9b8547b9222771', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
276    'fa8ac775c0747999f0733c1197e1540b5db9e456a36014347c880b03a3b2aada', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
277    'fcbac7976a502038193be95362557c9808746ff4830a570376056340a4087857', // Spoofed legitimate Harvard domain via Amazon SES for BEC/credential phishing campaigns
278    'fcdab3c46b7b5fb33820642cb465c86d9cc71a4a9792c2d0f92ad160e92e2f32', // Compromised account - domain renewal payment phishing campaigns
279    'fde63093f069fd00d5d5b0a8aff58e2e55646f0de7dadcd5b78c0511c16bf6cd', // Compromised account - credential phishing with recipient address in subject line and URL fragment
280    'fe0327623c71abe970f70c79062ccf66021adcc266fab760ed7d79d65df2221c', // Observed malicious sender - BEC/credential phishing campaigns
281    'fe08399f0400a0dab9349c6e3ad82bf1a6b70c3578fc519ea330964c918ec210', // Attacker typosquat domain impersonating Fidelity Investments - fake security alerts
282    'fe766eccc0c02f9ecfb6a9a326a1d77a91a3cee2151680befda2630eb8e128a9', // Observed malicious sender - lookalike law firm domain used in fake insurance policy document campaigns
283    'fff3c2530f6cc63385b2de940cc3e2c471561a3e5c28f77c650f203f1e86d6f0' // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
284  )  
285
286attack_types:
287  - "BEC/Fraud"
288  - "Credential Phishing"
289  - "Malware/Ransomware"
290tactics_and_techniques:
291  - "Impersonation: Email address"
292  - "Social engineering"
293detection_methods:
294  - "Sender analysis"
295  - "Header analysis"
296id: "b1c2d3e4-f5a6-4b8c-9d0e-f1a2b3c4d5e6"
to-top