Observed IOC: Malicious sender email addresses
Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.
Sublime rule (View on GitHub)
1name: "Observed IOC: Malicious sender email addresses"
2description: "Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed."
3type: "rule"
4severity: "high"
5source: |
6 // AUTO-GENERATED IOC LIST - DO NOT EDIT MANUALLY
7 // Managed by automated IOC system
8 type.inbound
9 and hash.sha256(sender.email.email) in (
10 '0004f01dc9ee385b299b774fbd0010c6da8164833d2ca0816ba648085e49051a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
11 '0025925158ebaf2924dc24ff2d2c31c8613e2023b5bae2101cb1e752ff187eba', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
12 '00d63ceac2fd6e0420e5b39810077268b95dc4f4596d6185fdd68a634acfa1e0', // Attacker-registered domain - BEC reconnaissance campaigns
13 '01eb9fff727d15c5fac229c9db4173d44988389daf483be57e7b8f35e66bb51f', // Observed malicious sender - advance-fee investment fraud campaigns
14 '03587843559b1c4aa44369aae3cbb618080e1949b9a316af0de465d7a60a0e5c', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
15 '03f4447e4e825556bd7f47093b610e80f7962b0dfa62027b8e5f4315d7856d62', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
16 '054a555253046cedcbcec7ef343b0b7e3ad923a016c08c45e9346dba1bd30726', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
17 '057761a14911145dd930fac2ae3362ee5478bda82cfe87ea89aacd86a95cd6af', // Observed malicious sender - compromised SendGrid tenant, fake Teams invite credphish
18 '062a0829f242e71ffaa3943294a6f4e9f504510813a5ee83c457bce0c6c74e11', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
19 '0637dfcfc63fda766fc8010d3916bb18d245077d519e3bb053145213a6aa4e7b', // Compromised account - multi-lure campaigns spanning DocuSign brand impersonation, mailbox suspension credential phishing, and shipping notification lures
20 '072ad26b13508033eebde6e5070cf6d8aa09d7414d64da7b69bd82f6e8f683bb', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
21 '07447603538582dab2e8ee62920a7435cc9b756bcbc7f94054d373b6232460d7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
22 '074a551f4b57f71c7f051b4fce84f8e3b50f85e28afc45e3b55384279571a268', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
23 '08706553fd4f1e3d3c1ea05f9b2520e210cc810d93c3f34036db5a119544178d', // Compromised account - timecard authorization credential phishing with randomized display name suffixes
24 '0914d7505e63c31c497bac8cc2001315edee6cbb14d7dd2a125efd06ce0deda9', // Compromised mailbox - BEC enquiry and proposal lures with fake email quarantine notifications
25 '09c62e04e73beed174d8470d9d212a0ec0127b5a2972cdfd2ad8a654eee4f458', // Newly registered lookalike domain - fake insurance policy delivery lures with typosquat reply-to
26 '0b02e4dd86f69c17a3fb3b579904120bb3be026eb4049a710627c6631b574bb8', // Attacker-controlled domain - fake SecureSign document delivery credential phishing
27 '0b9c2c2dd64d54049e0e53507880a250e675ce3d68b51b0ee2165f2ea5ef8903', // Compromised account - IRS and e-signature document credential phishing
28 '0d3de488a096b39ceb2db13ba7f68374049e2de2e0be6c2da9ef0d83c9337d24', // Observed malicious sender - advance-fee investment fraud campaigns
29 '0d708fdcc014db960b64ce93255c64a60884612cc2dc9c830b5638b950b4fedf', // Observed malicious sender - BEC/credential phishing campaigns
30 '0d7906e61f89af2bfbe63d749ec7681950410a81819baf307ed26a2a4ceb5605', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
31 '0d9d6401c0cffb024be34cedf19034966d01454e802cd2df9206a9eead1823a8', // Compromised account used in BEC/credential phishing campaigns
32 '0f1d80cdfbcd7b28945e0aa96ca1adbf3e69bc9b3c80b62bb240254df8bf6d24', // Compromised account - advance-fee grant program notification fraud campaigns
33 '0f8669d310832e5e053a7c29e9d08f43c143f13a66e48d7e0e9852659083cf2f', // Attacker-registered domain - supplier quotation request BEC with lookalike reply-to domain
34 '0fd0ddb531936d777000be33631274260d81250c833ebf7c06838a896ea3601f', // Compromised domain - SiteGround branded domain expiry phishing hosted on compromised WordPress sites
35 '0fe6070072580c44577931b8b61febab507e1721439481777a3c8ef218950189', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
36 '1127c5e25e2155b4e9a1aa7ebfd0269373697032eb6d037b2b1773636620777f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
37 '12170cccd307602216eac235d3176f547ce89fb492eccbdbed19a2748f7264fb', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
38 '123cd0a3912744f55f3a3c8ad7401f44112428ea6fedae38eca48a468bab87d7', // Compromised nonprofit executive account - EFT remittance payment fraud and thread hijacking
39 '12e43526e75cf27e10b97b0c1d7f673028450020031ada7e21525a12ad174724', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
40 '131f2f1f4d53adf813008ef0442f741800589f6c80d2ed75022de3cbfb19699d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
41 '14f25726353bf0377a6f0dd943e3fea2ee8dae88995dcb9997560fd00d17b155', // Compromised account - Air Canada brand impersonation credential phishing campaigns
42 '16527a63209b668a15eb474b91b7bbb7a5c8282e4dcd8ce68044772677855c2b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
43 '16599313a98b7432e9756a1c4ab7693b454850ba025a23a656d15ed643fe2014', // Throwaway/lookalike sender address used in VIP-impersonation invoice/payment BEC with fabricated reply threads
44 '16944bb3724b4ecb0ffcfd5634fdc373b76891e6689e754154032777ebe12c6a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
45 '16f9b3c2bb2663806fe91a6c76c0033018b7d090488076cd3fd4c9bc0c3ff799', // Observed malicious sender - advance-fee investment fraud campaigns
46 '185d468c1a67af5f7943dfe4142e6557f027bce99c3fae3bb5c532358806df7c', // Observed malicious sender
47 '1899d688514d0651536482339e377683b86b96a0eb673de2badef384a8f7f3d4', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
48 '18ac731a9858023e2b59114b6a861e10858c8d577ddf7ca7f7dd13984166a83e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
49 '18adc07eaac029b344fa1b4652c684df704ea88ff468eae0caeedbab0851715d', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
50 '19c288bd2baa150a12078d1310c3094b2ddd7fda8ba42d283be861a50615a924', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
51 '1a01ef4c29dcd924f903c6d2af54335acecf5e2289a41d69f1799005d07a8a0f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
52 '1a80fa436062f7deeea549b7f4d2b9db44c4ffef9d153fa8566a478de2876118', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
53 '1acbc86f2347911378c5803f3fff4b2db5e8355ebd1a656e7da89cea3b4479e0', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
54 '1b3f7a9f96d368268612f38aa535178ba2905ded7773a7dc15a93628bfc854e4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
55 '1daa2ca8844ce276e570e75eaf1562b79086ad846dad24108646c066b97961bf', // Compromised account - mortgage payoff and title request BEC campaigns impersonating Shellpoint and Wells Fargo
56 '1dc7009cf08e4a9891c9e9fa26201263f29826ea71bfd629400ec376a58fda00', // Compromised account - fake financial planning report credential phishing campaigns
57 '1ed0614fc9117f62d629d47f93bf2bb7ab0ca5371557818eb8a983f41b2f0f9c', // Compromised account - Zoom meeting and e-signature credential phishing with link shortener redirect
58 '1f9f044f5f4f108480264b5df8b623215c9d2e425331a22d67e6709fce0bef0a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
59 '1ff9e668661c28c3abda5d497fe4966037a01e10063bcd1d644b8ea21bca92c5', // Compromised account - Google Calendar invite document share credential phishing campaigns
60 '2040a34f81cfa9b83e25fd49aa853ea55e2af03c2f6bb521d02babc94c25359d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
61 '204eba38fc8bee6f69aec26501c467259dc7edf2bf0bab8f90ca9d73e382c38b', // Observed malicious sender - advance-fee investment and project financing fraud campaigns
62 '204f687ffc062cec92de70d4ff5e75d78dc017271ceb6e2c02e26f43fe999822', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
63 '2383fd0534e334243246377850eda12c5a29edff93259caa91e543acef30fcf4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
64 '23c62826bbcf57ba73b802de9ff676e7c470ef20d3b6651a81b371fa3e00bbf1', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
65 '23d30b83c60509d03e79c2673ab0c1b9a9fe5dda07a2198df43038cb153d7ae7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
66 '2428a08e180812cb74fb0930df94d299f444403a4cedc2fdb958e4de0ca72517', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
67 '249fdecf8c13707087a66615e8777af844873136dca22dce66955a9fa0c62f54', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
68 '251a75c039f8a8084b1946923a671bbd3370283fc824fe0f9ec2faccb6f0fd4e', // Compromised account - Google Calendar invite proposal review credential phishing campaigns
69 '25e051ba53581c25f8ce6281b74e56e027c421e090c2d4fa6c16db9da9cf0919', // Compromised account - DocuSign branded document portal credential phishing with recipient address in URL fragment
70 '269e21e213e3e7db224f86a0fa4fdd5c17040abaf42eeed5b862ccb14965af78', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
71 '26b456acbf4b9e71ab3f94c9c535aa7d280d99b00933dd152be5b7962639e224', // Compromised account - domain renewal payment phishing campaigns
72 '287a3feb51527264b034738d5f654c9c3f6d4d85ab8ea0f9e04defcd42c85f95', // Observed malicious sender - BEC/credential phishing campaigns
73 '298e3bbd5441f58bf33082da80ae0229cd0fa17054e3432199414a4706d05bc8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
74 '2a9b9e226f23ec6375ea7fbc73d2dfe2bfe4d0e09a8ed002226ad2c54659ba50', // Observed malicious sender - Chinese-language enterprise mailbox credential phishing campaigns
75 '2c61e0a0f6d48553de52c70d5c84242ee8b550016aa6fdb36abd9c8d7daf624c', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
76 '2ded1c3fefd56268abc47bba7573bc15cd7439037faa2b99044e205402f5ade3', // Observed malicious sender - BEC/credential phishing campaigns
77 '2f8d025a9102603953c1a16e888bed90edc72e9eb34b0a8ef05de2e666ec4292', // Compromised account - ICS calendar invite fake document share
78 '30497db58c2865530f352d8605072c6cdcb553d496ab237fc3196f3133795c25', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
79 '306bddcc8efbeed15553380ede95273d10438f4e4d8190963bd1cc58178560d1', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
80 '3190d9232f76f2636a06b1e39d934ddd23774e978ff5a5239eb4aa9eafd5e806', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
81 '36387b3610f581c3ff95f77130dc8faa8cf2046b0e610f4138bbe89651f4afff', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
82 '36eb7b8532befd5335eab6ec7bcd54d35428be2357d6caaa6421c20f1c6077cf', // Compromised account - Google Calendar invite bidding process solicitation credential phishing campaigns
83 '38a8e112af8d9252b3f51a8ba94003631bc4c9bf6ef60941521169382c8f546e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
84 '3a11180346d6de0d66d38dfe9482b0fd998183d30f10d02940d1caf458457d16', // Compromised account - Polish school domain used in BEC campaigns
85 '3a61963d39790456dae1ebe93b0a61c045fb58eea268a91bb92c4a622b01504c', // Compromised ESP account on active business domain - credential phishing file share and past due statement lures, short TTL due to legitimate traffic
86 '3c6d0480a53df3b3c3e2c27a210d99d9704e02814e1d11507e02490695eb8806', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
87 '3cf5c3a0b8481997224e3397bc52c754d52558e9a3c3ee1faf02c5e58ecc58c9', // Compromised account - ICS calendar invite ACH payment verification lure
88 '3d3f43292b599f983be6822151540437c86fce4dcf9f05e7dad94f3cfd7aff31', // Compromised account - purchase inquiry BEC campaigns with typosquat reply-to domain
89 '3f9e2c465ed00925b6904065f599c2a605ee8f15f9fac73626754d28839e370a', // Compromised SendGrid account - credential phishing with randomized document review subjects
90 '3fa83cd162a4f95f91d8cd28016dd8b1e557ee3a96e98ec0110ce7f22e387a24', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
91 '403949574d735ce2301d06f5dec9d6eec3f532fbf44c01c85608ac5ca4548e91', // Compromised account - Trafigura impersonation supplier quotation BEC with lookalike reply-to domain
92 '40742af9c50cbbdd54fda2fedaf88429d78e34f6df5cc0b34fe7851b354472cb', // Attacker registered domain - fake billing review credential phishing
93 '416423ad3b195a68f1f8cea67899e4eaf97428c128e2ae30c3fa607f8951c0d6', // Compromised account - Vietnamese university domain used in BEC campaigns
94 '4329b35c2cbed4d8f479f1b8d0bae5f255d292714d3c80e3366d7710fe91a238', // Compromised account - Google Calendar invite investment agreement credential phishing campaigns
95 '43e610255bac2342a7f16f0a442962e8f9a13b90a37425d31ddbd88b058d0d9d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
96 '48736e8d6c36f5232121bc9d9f0a148a09430a3b718695ca296abcb067530284', // Compromised account - Austrian school domain used in BEC campaigns
97 '48f87ee437793b1d2f8faf51dd2a5748f7a67f67fc0b168e861beeb28f371b59', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
98 '491e0d4561fbe866b20d6aab02fc7946b1483e4dea0e4c1493aae7ccac292317', // Compromised account - Google Calendar invite Google Voice notification credential phishing campaigns
99 '498030e0191b3c9b464b6c92e852a99e6ccd7989d95afd60c7124f45daec7ffd', // Compromised account - quotation request lure BEC campaigns with mismatched display name
100 '4992b89b6a829fb3b2df195a325c6c73c4c0706f87ca663e7b92d14700bd4533', // Compromised account - rotating display names in targeted payroll and treasury document credential phishing
101 '4bd612d0513e4be9d62a13fff090a163b7fe55534ee8cd6a95b4f925d558210a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
102 '4bd8d89c85ab0a7ebe69f6a9136f5eea8506e4bc5c8a09108db6bf48e5d8ee97', // Attacker-controlled domain - ICS calendar invite with Google share.google redirect
103 '4c254e837ad5e81e0d5316f4a12030b6112577955af3ab7900481835f555bd7f', // Observed malicious sender - advance-fee investment fraud campaigns
104 '4c4801bea710a8a5653b1396d139cc4fbf731791dbbf3f21305f2b651cd62d29', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
105 '4df47bebfb4e8c9f8b486fad6e3045ce529835572cedfcd6890bad30cebfa8d9', // Attacker-controlled domain - N26 bank credential phishing targeting German speakers
106 '4e369c5bcd4380ff2da76b495727f0faf53a73dd3c5da8f8bb941ddd416b7b3b', // Compromised account - domain renewal payment phishing campaigns
107 '4e6e32b31f295cc2fdd1f88bb32c7855ab2e760f21cf834f97abac9e9db68d47', // Compromised account - strategic partnership solicitation BEC with randomized reference IDs
108 '4fc1f40c3dce21cdc1416a0932cdacd9b8cf20c6cd8993c3f5784bf4d6b9fc4c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
109 '5088966877d8065394ac600df092d315bbb7e8a3ba18f1bc1e46bf12118bbc35', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
110 '50ae47f0a347fc4f9403361b5626f2397657d768196afe7378fe613e9077102f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
111 '50b954f90cdce83f741dacb8ab75ebb329e446302657e85d0ad5e538c6059f8d', // Compromised account - domain renewal payment phishing campaigns
112 '50d289addef8c2b6b33f72f069f979042f0878135ed471d00c3a3d1070a0f3d2', // Compromised account - device code phishing via fake legal case notification hosted on UiPath cloud app
113 '51085bd2a15074f19fd307da1867258dcba93a33ea9a672079a85efd54ed243f', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
114 '54e9c00529e925b43d578e8b1cb5efa2c634992ff871b98715b10d96b49c97c3', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
115 '5502acdf89fe972ba391e8aa9355919a1c3f920947169bbd23da5c6383e18433', // Attacker-registered lookalike domain - fake Google review removal scam campaigns
116 '563d4aedcf31889fc01fc1c240622d35285a988856bad72f11c5f85ff7372ea6', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
117 '57bbac04d703d41541706ec03ff4d8fee40b52b3343224a9e85baff3ff7de90a', // Compromised student account - fake forwarded thread and fake photo share link phishing campaigns
118 '59f89167e3c871f5ffb2555333b868a28af9fded8b99d5718b4c760ed98bccb3', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
119 '5a03383efec90551b7cd2dca400b07dc9c99479d94d904fc0133dac1814a4d91', // Compromised account - ICS calendar invite fake contract lure
120 '5a3e0172e9f47403a5211107fa7bf4f9e4c123db10bce71a56dd24dab210472b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
121 '5b30df912ea94e42843ba0a7233004b7ad7d4cfe36ca29110a89dc60fc69e9f9', // Compromised account - Google Calendar invite credential phishing abusing Intuit notification link redirects
122 '5b508f66848ab601fd3544c927b095362b884ff7c96a863e5c4ca898b25ba290', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
123 '5c0ee499a0e284381b435296d99e3483cde8f8f1da31a89fe4b9b4e7ffa9410c', // Compromised account - domain renewal payment phishing campaigns
124 '5c5ad5fda56f9659a2c1710d37f94eb2da19e941e75d9b59ccbd85b44a7b99ed', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
125 '5c693feb863201cf47f7845815eda91bb3f5cb80d0cca995f18c939fefecf21a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
126 '5ec704a8f5f01a6fa672656573abf9c70154a1a2af0a3123406afb3091ef0537', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
127 '5f3852d1709c1599749a64668e89f8aa7c842a85ca646f9980c0a1fa58d61818', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
128 '6006d47a8d739e6f5231b49f0d61767227529f6405e6b502d7dee958db22939f', // Compromised account - Google Calendar invite RFQ solicitation credential phishing campaigns
129 '6057ccf37d8286e1ae7d8dfd1789fe60791f2bc39600631f0551712cc8661e5e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
130 '6106f4d9431f6f990a68d8de4bf194e5ef5341ac1ba918697c0635b3f93fc77c', // Attacker-registered domain - fraudulent purchase order BEC impersonating equipment manufacturer procurement with typosquat reply-to
131 '61fffa77073ca73875d1c738fa8a9628440a07128e50d4b6be57e8a195a4afd5', // Compromised domain - myGov impersonation credential phishing with Australian tax payment lure
132 '637bfb85dc1f4f13ca89f1ecae0ea67745800e25d2ffe8a7ac89ac3fd961c944', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
133 '66771511747b19c3015adbbadd4e1d54d0db51c646f3c28b34b1fa09ee772afe', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
134 '6777231b6c945ebef989e3c0cfd506bd36f312e4e72759c20240f975efba3b00', // Compromised student account - fake photo share and fake forwarded thread campaigns
135 '682690942d17fcfdab558aeb4dc2731f51666adabfad813e1f4b6e3843a2c605', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
136 '68cf1bca691f867a75e175d94086e2c3d5b65fea6ea5849b8dc3c2f2b469ba7e', // Compromised account - ICS calendar invite Google Voice voicemail lures with Unicode-obfuscated subjects
137 '68e096fe2d9e586026cbe19d4b718ab64b0f4aae0aca3021c0f77e6f5e7512ec', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
138 '69bb39e7e9fc344ed53bf59bf46ab39601ff098e1fe28730f5dbdb6dd5cc2e92', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
139 '6a89cfa7f865f8dd85b314cadb52092fd42beab427e1ff8a5d9059dd7e606d87', // Compromised account - ICS calendar invite RFQ quote proposal credential phishing campaigns
140 '6abb620f683ee3a848295b4343b27d99c8269f1b1e99061d04f292730f1c15ad', // Observed malicious sender - fake voicemail notifications via Google Calendar invites for credential phishing
141 '6ba83ae804722e49e6e3b876b5830dfe6044b5b8767aed9d5b2e2b168b835cde', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
142 '6bc270fac6bed884311689fc339a2d5953638d7909359c61348a440de9caf9c1', // Compromised account - purchase order fraud impersonating Manitou Group with typosquat reply-to domain
143 '6bcb6d890034877d208a211b2b2fc4e34e477a4a588c610f7ddd6d4fcad30821', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
144 '6d2c29e0d973404059aa517e8bacbbbef7fb7644486f1fdce6c4924c32e3d9fd', // Compromised account - ICS calendar invite voicemail lure
145 '6dd1daf7fab34d399a3307b0ab85a2c7d4ae4f9e42e0a226811f6d4d362b9d4c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
146 '6ed87d7442a9c67238272ffda2bc11ab7635fdec57fd58cfb289da585eb7314a', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
147 '6f9a75a9a30c46798d67cf29265c8fb9255d05f9929156470c87e85a19f83254', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
148 '6fcd011c929ff7d871d21375e5e9468b49397a566524bc9f57ec022dbe047c04', // Observed malicious sender - advance-fee investment fraud campaigns
149 '7044b353baffec52f9de4bb653e76485c6829328443d7fbd6f38fdd160c16055', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
150 '70e1030db9d32f156df07d445ee2bdc71fa37d3e9cde4418c5db6e2560f711cc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
151 '73267f82cfef50641282935512e3d291d2c681aebd58c8ba7950af8236626912', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
152 '7516a9a2ed9016192434dd81db055d23dccba29731343f12be7f7dcb324a439e', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
153 '762c9ce5b716f3b385559fb09e7510661267797ea556eb866cbd1727424fdaca', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
154 '766d628cd39125d9a6bce62dff3203cdc47d1a74e83f05157ad4fd28771974cd', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
155 '77dbd254b71aedc57d3247f9273b23a0ff191ebeafd4fe231048959f0191d524', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
156 '77df91f5bd3c2e212d6a97a37f9096c7066a38ef5df4da445a83a5a8f8f94500', // Compromised account - fake voicemail and remittance notice credential phishing campaigns
157 '7c711457c1affc6bdf1a622a22f81f624e034448548e625117d1091f848ddc7c', // Compromised account - ICS calendar invite document review lure
158 '7c8569f4156a396673e5509f5c3a4b1aaf30761802631478bd59bec9c2ff0459', // Attacker-registered domain - German language inheritance advance fee fraud campaigns
159 '7d3ecab1afc389186703af31545b4b7485ff20ad130167d641a178bf88850f1f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
160 '7f6a1cadfd6cbdc412e25021725006324d84aeb4ba3e366d772e92887937bf15', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
161 '81c391208275700266de52f05176151b490fc98ac303c69aade60c4dd7733e6e', // Attacker-controlled domain - numeric-hex reference code reconnaissance
162 '82f54cefc0ea8ea3344762e170acf0511ec0102e845c2b72c0373de521fa36d8', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
163 '83c22c9f165fa33fe708cc4d7dac54fb8daa30cfb9bb38e603af1b18d413faf4', // Compromised account - recipient-personalized report notification lures abusing freee.co.jp marketing link redirects
164 '8492466cf682afff67250cb3918967951f97bc3945a6443ecdf1ad0e63873f69', // Compromised account - domain renewal payment phishing campaigns
165 '8797ebd0fe0fd6e370fbdece9bb10a2ad341557ead0533e488bc6fffc9e5ea3f', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
166 '87eb1efe1ab4ff5ef8767c19f6ccd837b2dac092b70092b56e3e59302035ad84', // Observed malicious sender - Norton subscription renewal credential phishing campaigns
167 '894310051f1fe1fde08f6254d7909481b182338dca784c0dfc4c8b71134cf776', // Attacker domain impersonating Indian bank - BEC lien waiver fraud targeting construction companies
168 '896ce3441bc7c3d3dfee3f8947965492ed7160596b8f09eff9f625412b5a619d', // Attacker-controlled typosquat domain - ICS calendar invite fake document share
169 '8a47d2234827f5ded1d6bc235b16bf78b6f993c5799b4145888de15ba9a5e741', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
170 '8b6199148560383d2fca031052475ca2627637fdf4a883dd475c9f3a51d39887', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
171 '8bd7bb8d8e31c7dae087785d89ea17f199041105cd97bdc7cebd47ddbf9b4cae', // Compromised account - Google Calendar invite voice message notification credential phishing campaigns
172 '8c4ffc408b379a7649bef8b6fe6dedf467960627897eae7742091d98fc79a263', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
173 '8c61b30c46de11fd376026587646066325cc31f9749381abe2280b1fc1b58fbc', // Compromised account - invoice notice and ICS calendar invite voicemail credential phishing campaigns
174 '8ccd1976165c5acf2be6d44e89c95808574b584a2289354059554ba92f3ee355', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
175 '8d0a6552bc32f3704106dcbdd393c73ceb29a4bbfd7f0ec207ea438c757b608e', // Compromised Vietnamese bank account - advance fee fraud gift and prize campaigns
176 '8d14a081e8cf17d9101839290dca690a996b910d175e9ce2f2595cb395d6cc94', // Compromised account - domain renewal payment phishing campaigns
177 '8d6d35f92d52490cfd8c2153a979604b95aabb430eef256486600075465e80b8', // Compromised Kenyan school account - thread hijacking with credential phishing link
178 '8f70301abb6faa9b1b0463bda1a42a153a49c849dae45c24ca087b49cbd6f16f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
179 '91fe8f768fdef0efacb6325ad65b4d5922789d49dc2b253e7e352367ac8608fc', // Observed malicious sender - advance-fee investment fraud campaigns
180 '92b022313ffa3406da6cb095c2f8aa3404b401fea6ff9786f748663b9da6539f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
181 '9472ab67914ca4eb86fb7c4b726bef67c194bbbd430871570e53ba148099c502', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
182 '949999f91a3feac5a7b82ce881d1a32f8aea674ff928f5a7f8950076033272d7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
183 '94a586de7ec274964f27506d5f27a6d717a1d472306017737ea067830889fb98', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
184 '955ae08074c3cf8fff4143461c371ece9690921a27896d18b3c34f6afa65b48f', // Compromised government account - service solicitation BEC campaigns with mismatched display name
185 '95f01da32fea6a5c28b5453568b7d3977a76e3ae42e7375534f22cd5c43c089a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
186 '970950880f23d7bc62e6e9622fabb162f846ca06134163b426951c4d62db026d', // Compromised account - fake eDocument task and Microsoft Teams document share credential phishing campaigns
187 '99673797051adaeb68dc8b07624ba300472cf9cff1a995fa1f95d8b6685374dc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
188 '9ac3bc28005ac615607c878c119118698b368217633d616082bd6b619bca8224', // Compromised university student account - advance fee fraud to undisclosed recipients with freemail reply-to
189 '9ad52736e4eb32a906e646cb4c16f38c318e44922666f59d1652b85d2a7a7680', // Compromised nonprofit account - ICS calendar invite credential phishing
190 '9b3afc720c7975523f572be5e2b8e75a2567257a834e73ba3c11eeae4c53467b', // Attacker domain - fake eForm/spreadsheet sharing via SendGrid abuse
191 '9b4bc1752d36bb4718a2a30342761e8ccecb5d64dc9164c3127dab30614811d8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
192 '9d20cf849102d8c4bfec9c15c2d79fa408502657a4455cacaa2bc725fec078ae', // Compromised account - tool giveaway lure with Google Cloud Storage redirect
193 '9ee9228bc6dcb8628d144d63c21d436f427719672dc1ff01e9f5845059424ea6', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
194 '9fda882aad59efabf9e2c45a9f1490e87deb323de5aedcf80b4bfbbf1c21f8b0', // Compromised account - fake eDocument task and Teams share credential phishing campaigns
195 'a18ddb2b10a3a42bbbbc6300dce305703607cf9a12ed737da9f5576b879b1113', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
196 'a2bbaa6824197630b7b9fb12296405481f6d2224194559c1ee39a635f8603cfc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
197 'a3b5cc5244de712715f1ff645eef860ee5e0f2e9e86f1eee79930224f642d9c1', // Compromised account - Google Calendar invite voicemail notification credential phishing campaigns
198 'a3e2ac92f5de8d20c54480ab3a61f33be788de8e9467bc18fc5e0b6a0d6da2ed', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
199 'a4312827c4ed4900fa06d6f3058edc203fe85683b6de585d1fae5becd4700a6b', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
200 'a484fa16fb013b579b1f4006cc42d20da09541271c5f93312b4d02dbeba8385f', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
201 'a4f740abf0fa1c0a6c26a9acdff1248e6cd147b392b5806028515ae3da389785', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
202 'a5e72048f261715f3e7ce6d2cc8916bd2a3e230e5dba3f6bfa3fbf8756ac7381', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
203 'a74606dc787d5e75866029b343dd8c08f083d8f9b086362b9fb20f071e79a12b', // Observed malicious sender - BEC/credential phishing campaigns
204 'a867247b8ccfc2299abe14585264d8a09bc1786f8ca4e2340ebf7c276b0b9af7', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
205 'a86a143662cf3c933ae792e1fd48819a41142c97453fe675d6efb4a29eca927c', // Compromised account - Google Calendar invite bid invitation and partnership inquiry BEC campaigns
206 'abd5ceb9b3abbd53544b99ded01b9a993c38b3133b0905d62006f8d378e5f8d8', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
207 'ac3af7bc7aa52ad34365f7659070dc858ad4eb09aaa9f9177ba37adbdbf60a48', // Observed malicious sender - abused aged domain (SPF none), HR/payroll credphish via encrypted-PDF password lure
208 'adea82cef2ef6c53647457513d1f0972dcafd4e5ea093a977bbcc8a4ab385d1e', // Compromised account - venture capital partnership request impersonation campaigns
209 'ae42584dfd37653be7e42203ca5b6ad5508a639726ab5cbb65ba58085e54c6b4', // Attacker-controlled typosquat domain - numeric-hex reference code reconnaissance
210 'aee561d4926ae4535a732b4649ea27a5ccef7a18b28775b162d095e11820a52c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
211 'b044f948af172622b44fec0affad51861ff32c5f6ba5bcda261293e35a6b5d3b', // Observed malicious sender - advance-fee investment fraud campaigns
212 'b1636bd79df0c1cecfb3213ffc0f921d23c73435cabcc2ff03c759c14c896170', // Attacker-registered domain - completed document notification credential phishing via marketing automation tracking links
213 'b282f3e253bf6a2aa02d484f2edacc2f20338ce37fe157d8817ba96321af6766', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
214 'b2dfca515de73047279efe855337aa3c7d6179f7b0d7dc35921fb0377b618baf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
215 'b325f09c58d698fcde5274662e2c9ee4e49fb8030825e23450b53cec5d546c5d', // Compromised account - ICS calendar invite voice recording notification credential phishing campaigns
216 'b3413ce41fc413b11ba8fd0b58c71e3a811169cc2ac783154eaaf37e84fe7bbe', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
217 'b3a315352bd909eee0c773071df508ef0487f0180df22017c6e5e5eb40d77301', // Compromised Japanese company account - parcel delivery credential phishing
218 'b3e89ebfcc45a1fd5f254b8d04c5275d968af4618a7a8c5f6cc75b8d941bd448', // Compromised real account used in VIP-impersonation invoice/payment BEC with fabricated reply threads
219 'b3ed5ef14f1be181d2e375ad4d3d29a3b0777ec5fd162c9c36422962d2dcfd7c', // Observed malicious sender - BEC/credential phishing campaigns
220 'b45eb5412cc803dec77d6c7abea7ce0e6e3abc72ec75ac19a4f16c9cee65b91b', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
221 'b4751533eefe4d0cc630fd5dce52e043a1ff6617238b2ebe3b7290899bbe241f', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
222 'b53cf0459ca41ca4c51c15d4be23113aeee4d77a77f7f01761e416b6896011b9', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
223 'b6df58873af5b6edde8f19e46bd7ed10bd0c7b61d4adda29506b05c5f0ef057a', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
224 'b707848bcdcf5a385ccd43e428c5c1f09ab1b5b0076e95fbf5ee98780fdad8a3', // Compromised account - business proposal advance fee fraud campaigns
225 'b7415f1380d0a89b124bce7de8b1eee96dc452f9c95252192176cd427020b060', // Observed malicious sender - contract agreement BEC campaigns using freemail reply-to mismatch
226 'b77161f16370afbd32afd8e613be5ffb1a9d9e99e1b8d3e547cf6379ab55c6ca', // Observed malicious sender - spoofed sender in fake forwarded thread membership invoice fraud campaigns
227 'bb24567ae519d6391aba7c28597fbf84a1c9b283bcd9e8d9383e4345c7ee0dcf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
228 'bb87499a229e0f70ebd20d8d3be83d426c898c01ee3a4b8706abc5d78d9146df', // Compromised account - ICS calendar invite credential phishing
229 'bc7822660da2eddd2af07cf2180e50c7a56b303390cf1144614f5143d24fbf31', // Compromised account - ICS calendar invite voice message notification credential phishing campaigns
230 'be44430a667b7776e351cf54a66f85716de0731dcb1245b7c5bca081e4cd80a5', // Observed malicious sender
231 'bf5d4be8d2cee2476e9a226bd955f41819e4b01976f9bbd91b58bc82f057d4f6', // Observed malicious sender
232 'c319fed85def0d337780b2f93c18fce8aee32421b822a7b1554ff7307a142012', // Compromised account - sales invoice PDF attachment fraud campaigns
233 'c35764206e9ae5372498a5c7562e52632a0ddadecd1973d71b9d448624ae3b16', // Compromised account - urgent notification lure via cloud-protect.net redirect
234 'c36ab707c4867b70407bfc0d9a4b069350080fdc820626f9a54f88ca905a3c97', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
235 'c5dfb0030991c22aad632fb5d57e7eac57f6379ff3165fcf5d170a6d730c4538', // Compromised account - ICS calendar invite fake document share
236 'c75f2d07928e315171113031a6a1a54bed3a6a6cd53b293a8e9015222de1fb32', // Compromised account - supplier purchase inquiry fraud with typosquat reply-to domain
237 'ca2e7c13010d96bf2286342dc7ea87ec67232e29b5e659820210e01cef273081', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
238 'caed0ffc5a2f2858ef33956eeaf3f1309467e352506dbc200bed299a3ce71420', // Observed malicious sender - advance-fee investment fraud campaigns
239 'cbb683f2108bf5c91e5da136b20d94e299bd8a027311afd10f17575f0a166f19', // Attacker-controlled domain - homoglyph brand impersonation with open redirect chain
240 'ce2be5b5f5f2e6d1d9d8619c832e94cfa804ce4839d834d1af510a769e7a7d16', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
241 'ce2e6f79ab6c8ea45992953e454d96c0ee2a5efe2e92d6ed571f13bf82c99108', // Compromised account - RFP invitation and business project solicitation BEC campaigns
242 'ce374e281361708cdb4f456b44a0e95528a7a428d602d9f132aac5b5aa9826af', // Compromised account - Google Calendar invite credential phishing abusing Intuit link redirects
243 'cf073a4affff5131a6f53c8d3f62548e6a453f6ceff16d6f784e115f5fae6038', // Compromised account - domain renewal payment phishing campaigns
244 'cf75ac0cb2baeaa1bf657101ca7ae0c300398509298f615e3d05fea7216da05c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
245 'cfa974b119ad8212b484a0229914ff1405ca9b8c7489166420986b3576b7da7d', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
246 'd0c976c4f72edb8094a4258e4c1bbb3b21ba17c30e0e95f7e32e5e8457c43335', // Observed malicious sender - Robinhood and Interactive Brokers lookalike domain credential phishing via account security alerts
247 'd74e6eddf9abd425d77adced3fb56eb96a164b2a56a28e0d75d08ede43d51cd4', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
248 'd7a310ef6cb3f4e842b17d268a52391675477f71475b63a4cf1cee6f9bd94ff5', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
249 'd86903bff85599facfd0e178670e77f500fb5fa84ca2aafa20f245c0a6e0aa05', // Observed malicious sender - BEC/credential phishing campaigns
250 'd931f0c6ddded184ac8e0a6dcdb356fc0d4f64fe2c852f587db149d942c2e5e3', // Compromised account - Dropbox Paper credential phishing to undisclosed recipients
251 'd9a945c87143ad54d536e4363cac491dc31b2f75891063a0d1fa776381358ddb', // Compromised account - credential phishing with recipient address embedded in subject targeting education recipients
252 'd9b1a194be864f755ad19767c53bfc54dd27fb69464fc9d6b0729f4f82267f42', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
253 'db92038c5432edd7ce1df22ae4ffc173eff2ab6f6dc9f77e435b6437d6a788db', // Observed malicious sender - advance-fee project funding fraud from newly registered domain
254 'dc01b1e4b74adb29a9e2ff4f29a34076f61c87cf04f620cef525d5070818687c', // Observed malicious sender - advance-fee investment fraud campaigns
255 'dcf926c300e21c985ff97951bb747662f4d89b68ebd2ec2346792ea69534cafc', // Attacker-registered domain - realtor-targeted program eligibility confirmation lures
256 'e02c4ad389225617a5fe12c012348a928f6c2159b378afb28d4d1f5f1e541376', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
257 'e06aa193933815324af2fee9d3c250dab080a681b9658253ce2b0af0466cbbd1', // Observed malicious sender - advance-fee investment fraud campaigns
258 'e0da1bd70a04552d8104ae6d11b2eeb477b6dc8ecbd257d5dcde3bec0127044e', // Observed malicious sender - bid solicitation and RFQ vendor impersonation campaigns using typosquatted reply-to domain
259 'e2dd8628371377d56c761817ed6676c5ccd2e9870f1b8cb7b63467f0d387d8fd', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
260 'e430fdb030ceb6fe3886338084b9bc210bde348930cd9e94ff2e978d47dca0a5', // Compromised account - Sedgwick and State Farm insurance claim adjuster lures with Office attachments linking to credential phishing pages
261 'e496f21a9a64bb06d1c3c9f3ce6df5a4fec04e513e51c9d05d6637e48036e9e8', // Observed malicious sender - advance-fee investment fraud campaigns
262 'e7c699fb15764decb4193d06537fd56d2ebb7e6af19919dd9b489815c200ea2c', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
263 'e9c2bed0462383568a1ac0fa73058693c34f06f35293388bc742a6f055d07701', // Compromised account - Google Calendar invite voice message credential phishing campaigns
264 'eaf8cfe2d96cdb4f17819f77aad91fd9555fb82be5124b112a70d252f92219c6', // Compromised Japanese company account - vendor invoice BEC with fabricated internal exec forward in .msg attachment and lookalike vendor domain
265 'eb6fdf648b34efa0d7eed5ac971d12d2fbc5d8f8fa3c5d3abe7d307b3f1367f2', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
266 'ec9c01b0c4fbe5de2fb5065ab31cfb80304179a889a513f8bae112cc5d544331', // Compromised account - remittance notification document share credential phishing campaigns
267 'f0d099bfdabc2c0ac8f8561a64d66e9e6ee1207fc560db8fe07771fbfa4bdd52', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
268 'f12e13befd897b6b9ea41f1b299200fd71fb5137d6c0866f5af0984ac91a30cf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
269 'f2231cb4a71ce384c1dd949af538dd25761776366a0f0b76ed4c889aa6488c4d', // Compromised SendGrid subdomain - fake eDocx pending task credential phishing
270 'f23450c74fbd8e5379835a6961f3cb92f0222573f6839469384717b4f1ed46f2', // Attacker-controlled lookalike domain - procurement sourcing BEC lures impersonating an unrelated metals supplier
271 'f4116dde162ca98aeabba276d40e2d7306b4a63332b67dc994bf9278452a2c60', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
272 'f47441d1d8080fd855a7ebc8ba3549958929f7d2acc70417438319bab03531bf', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
273 'f5ee438bbfbde02b493f726c06351325bfc31085e3056aaba768db9211893bc0', // Compromised account - fake webmail password security notice with recipient email in URL fragment
274 'f7134c981f996cacd56e1e541ba5179cd35292078496e981aec26fea016a3e14', // Compromised account - USAA claim adjuster impersonation with PDF attachment
275 'fa0038a882392e5496003d074ba4f627b377efe20e2cbe8aad9b8547b9222771', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
276 'fa8ac775c0747999f0733c1197e1540b5db9e456a36014347c880b03a3b2aada', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
277 'fcbac7976a502038193be95362557c9808746ff4830a570376056340a4087857', // Spoofed legitimate Harvard domain via Amazon SES for BEC/credential phishing campaigns
278 'fcdab3c46b7b5fb33820642cb465c86d9cc71a4a9792c2d0f92ad160e92e2f32', // Compromised account - domain renewal payment phishing campaigns
279 'fde63093f069fd00d5d5b0a8aff58e2e55646f0de7dadcd5b78c0511c16bf6cd', // Compromised account - credential phishing with recipient address in subject line and URL fragment
280 'fe0327623c71abe970f70c79062ccf66021adcc266fab760ed7d79d65df2221c', // Observed malicious sender - BEC/credential phishing campaigns
281 'fe08399f0400a0dab9349c6e3ad82bf1a6b70c3578fc519ea330964c918ec210', // Attacker typosquat domain impersonating Fidelity Investments - fake security alerts
282 'fe766eccc0c02f9ecfb6a9a326a1d77a91a3cee2151680befda2630eb8e128a9', // Observed malicious sender - lookalike law firm domain used in fake insurance policy document campaigns
283 'fff3c2530f6cc63385b2de940cc3e2c471561a3e5c28f77c650f203f1e86d6f0' // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
284 )
285
286attack_types:
287 - "BEC/Fraud"
288 - "Credential Phishing"
289 - "Malware/Ransomware"
290tactics_and_techniques:
291 - "Impersonation: Email address"
292 - "Social engineering"
293detection_methods:
294 - "Sender analysis"
295 - "Header analysis"
296id: "b1c2d3e4-f5a6-4b8c-9d0e-f1a2b3c4d5e6"