Suspicious Invoice Email - Triage #000 (Fake template)

Investigation of a phishing-style invoice email targeting finance users with a malicious redirect link.

16/04/2026

#phishing #email-analysis #template

Context

At 09:14, a high-priority alert was triggered for a suspicious inbound email sent to two members of the finance team.
The message impersonated a known supplier and requested urgent payment confirmation through a link labeled “View Invoice”.

Investigation steps

  1. Validated sender reputation and checked SPF, DKIM, and DMARC alignment.
  2. Extracted URLs from the email body and analyzed redirection behavior in a sandbox.
  3. Reviewed mailbox activity and endpoint telemetry for both recipients.
  4. Correlated indicators with threat intel feeds and internal historical detections.

Findings

The sender domain was newly registered and failed DMARC alignment.
The embedded link redirected through two short-lived domains before landing on a fake Microsoft 365 login page.
One user clicked the link but did not submit credentials. No endpoint malware execution was detected.

MITRE ATT&CK

IOCs (Indicators of Compromise)

TypeIndicatorNotes
Domaininvoice-secure-check.comNewly registered domain used in initial redirect
Domainm365-auth-verify.netHosted fake login page
IP185.244.25.91Server observed during sandbox resolution
HashN/ANo file attachment in this case
URLhxxps://invoice-secure-check[.]com/open?id=8472Defanged malicious URL

Timeline

TimeEvent
09:14Alert received (suspicious sender + URL pattern)
09:18Investigation started in email security console
09:27Malicious redirect chain confirmed in sandbox
09:34Message quarantined and sender/domain blocked
09:42User contacted for validation (no credential submission)
09:50Case documented and closed with monitoring actions

Outcome

Containment and blocking were completed the same morning; the case was closed after L2 review with ongoing monitoring on the new detection logic.

Lessons learned