Email Investigation

Email Investigations

Message-level forensics with headers, auth results, attachments, URLs, and detonation.

Suspicious messages

  • MSG-312108:03
    Adobe subscription — action required
    billing@adobe-secure-invoice.com
    high
  • MSG-312007:41
    Open enrollment: verify your details
    hr-benefits@contoso-portal.net
    critical
  • MSG-311907:12
    Your recent sign-in — Zürich, CH
    no-reply@microsoft.com
    low
  • MSG-311806:58
    Wire release confirmation #4429
    wire-transfers@bank-of-westhaven.com
    medium
MSG-3121·Delivered to Inbox → auto-quarantined 08:04

Adobe subscription — action required

From billing@adobe-secure-invoice.com
To sarah.chen@contoso.com
Return-Path bounce@mailer-31.rr-out.com
IP 185.220.101.44 · TOR exit
high
SPF
fail
DKIM
none
DMARC
fail (p=reject)

Embedded URLs

  • hxxps://adobe-secure-invoice.com/renew?u=...high
  • hxxps://cdn.adobestatic.com/img/lockup.pnglow
  • hxxps://tracker.mkt-out.net/o/49x/medium

Attachments & sandbox

  • Invoice-4429.htmcritical
  • Detonation verdict: malicious · credential harvester (Adobe brand impersonation).
  • Campaign correlation: Storm-1811-C · 87 similar messages tenant-wide.

Raw headers

Received: from mailer-31.rr-out.com (185.220.101.44) by contoso-mx.contoso.com
Authentication-Results: contoso.com; spf=fail (sender IP is 185.220.101.44)
  smtp.mailfrom=bounce@mailer-31.rr-out.com; dkim=none; dmarc=fail action=reject
Message-ID: <5d1c0a1c-4e7b-adobe-secure@mailer-31.rr-out.com>
From: "Adobe Billing" <billing@adobe-secure-invoice.com>
Subject: Adobe subscription — action required
X-ThreatLens-Verdict: PHISH/BRAND-IMPERSONATION