Email Investigations
Message-level forensics with headers, auth results, attachments, URLs, and detonation.
Suspicious messages
- MSG-312108:03Adobe subscription — action requiredbilling@adobe-secure-invoice.comhigh
- MSG-312007:41Open enrollment: verify your detailshr-benefits@contoso-portal.netcritical
- MSG-311907:12Your recent sign-in — Zürich, CHno-reply@microsoft.comlow
- MSG-311806:58Wire release confirmation #4429wire-transfers@bank-of-westhaven.commedium
MSG-3121·Delivered to Inbox → auto-quarantined 08:04
Adobe subscription — action required
From billing@adobe-secure-invoice.com
To sarah.chen@contoso.com
Return-Path bounce@mailer-31.rr-out.com
IP 185.220.101.44 · TOR exit
SPF
fail
DKIM
none
DMARC
fail (p=reject)
Embedded URLs
- hxxps://adobe-secure-invoice.com/renew?u=...high
- hxxps://cdn.adobestatic.com/img/lockup.pnglow
- hxxps://tracker.mkt-out.net/o/49x/medium
Attachments & sandbox
- Invoice-4429.htmcritical
- Detonation verdict: malicious · credential harvester (Adobe brand impersonation).
- Campaign correlation: Storm-1811-C · 87 similar messages tenant-wide.
Raw headers
Received: from mailer-31.rr-out.com (185.220.101.44) by contoso-mx.contoso.com Authentication-Results: contoso.com; spf=fail (sender IP is 185.220.101.44) smtp.mailfrom=bounce@mailer-31.rr-out.com; dkim=none; dmarc=fail action=reject Message-ID: <5d1c0a1c-4e7b-adobe-secure@mailer-31.rr-out.com> From: "Adobe Billing" <billing@adobe-secure-invoice.com> Subject: Adobe subscription — action required X-ThreatLens-Verdict: PHISH/BRAND-IMPERSONATION