Description

Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

References

No references.

Sublime Security
Created Apr 24th, 2026 • Last updated Oct 6th, 2026
Source
// AUTO-GENERATED IOC LIST - DO NOT EDIT MANUALLY
// Managed by automated IOC system
type.inbound
and hash.sha256(sender.email.email) in (
  '00d63ceac2fd6e0420e5b39810077268b95dc4f4596d6185fdd68a634acfa1e0', // Attacker-registered domain - BEC reconnaissance campaigns
  '01ae75e3d4e040a184e7ffdff91eadc3f0c136cd6ec754a10200a67cb529c771', // Compromised account - assigned ticket ID credential phishing hosted on a lovable.app subdomain
  '01eb9fff727d15c5fac229c9db4173d44988389daf483be57e7b8f35e66bb51f', // Observed malicious sender - advance-fee investment fraud campaigns
  '0540b57e20e05cdb2ae89fcebc55b4788ae00b93381f30458544674b3a44ff00', // Compromised account - accounts payable lure with EML attachment containing an HTML credential phishing page
  '0567d195baff61f8eb84184476011ada4e8d57466aa4833841c592996e7f8cd9', // Compromised account - statement lure with fake PDF tile image linking to a fake Adobe Acrobat password prompt that drops a password-protected zip containing a VBS loader
  '05c2551b17530710c9edbfd9bb7aaf8ec145b216edcbab069daae96f4aae908b', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
  '074a551f4b57f71c7f051b4fce84f8e3b50f85e28afc45e3b55384279571a268', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
  '08361fdb828f15abcfaf7e041cdf3c6653157ca99c95fd8bf2ba8fde1fbc8f64', // Attacker-controlled domain - serialized new business inquiry BEC lures targeting real estate brokerage agents
  '08706553fd4f1e3d3c1ea05f9b2520e210cc810d93c3f34036db5a119544178d', // Compromised account - timecard authorization credential phishing with randomized display name suffixes
  '0914d7505e63c31c497bac8cc2001315edee6cbb14d7dd2a125efd06ce0deda9', // Compromised mailbox - BEC enquiry and proposal lures with fake email quarantine notifications
  '09c62e04e73beed174d8470d9d212a0ec0127b5a2972cdfd2ad8a654eee4f458', // Newly registered lookalike domain - fake insurance policy delivery lures with typosquat reply-to
  '0b02e4dd86f69c17a3fb3b579904120bb3be026eb4049a710627c6631b574bb8', // Attacker-controlled domain - fake SecureSign document delivery credential phishing
  '0b9c2c2dd64d54049e0e53507880a250e675ce3d68b51b0ee2165f2ea5ef8903', // Compromised account - IRS and e-signature document credential phishing
  '0ba5a0bc781991396b6f347ad6f9be553affaf88a09515f8c3b51419776f23f6', // Compromised account - QuickBooks profit and loss file share credential phishing delivered through legitimate Intuit notification tracking links
  '0d3de488a096b39ceb2db13ba7f68374049e2de2e0be6c2da9ef0d83c9337d24', // Observed malicious sender - advance-fee investment fraud campaigns
  '0d9d6401c0cffb024be34cedf19034966d01454e802cd2df9206a9eead1823a8', // Compromised account used in BEC/credential phishing campaigns
  '0eb988e9f6aca75714c0aaf827336471dda7294b94b0e6d45617fbddae4c5f60', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
  '0f8669d310832e5e053a7c29e9d08f43c143f13a66e48d7e0e9852659083cf2f', // Attacker-registered domain - supplier quotation request BEC with lookalike reply-to domain
  '0fd0ddb531936d777000be33631274260d81250c833ebf7c06838a896ea3601f', // Compromised domain - SiteGround branded domain expiry phishing hosted on compromised WordPress sites
  '103dbd3c01a1e8ab0701fa982e5e3e4b0f1a93cdd85c5fe6e74d75b837818de1', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
  '123cd0a3912744f55f3a3c8ad7401f44112428ea6fedae38eca48a468bab87d7', // Compromised nonprofit executive account - EFT remittance payment fraud and thread hijacking
  '126ca3d8255f5e75ddae997d747eb0f5d9626c8a88dfa25687f314e640b873ac', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '14e2a6e8c3b0aa75f25cafed155f6bd2c6111adc9bd239c1f48e394b5fe69d9d', // Attacker-controlled lookalike domain - subjectless campaign delivered via SendGrid with Klaviyo click tracker
  '15e7f8cef27a0cad985b0a21496fa70a28897ed56e9d8700ade048bab5307850', // Throwaway freemail account - executive impersonation requesting mobile number for SMS pivot
  '16f9b3c2bb2663806fe91a6c76c0033018b7d090488076cd3fd4c9bc0c3ff799', // Observed malicious sender - advance-fee investment fraud campaigns
  '1872dac4f5e1bf41b98b805dd5cd6b9d49b85a72e52ef5aa1d8432573e133517', // Compromised consumer ISP account - BEC first contact with rotating display names and a padded dot-delimited review subject targeting municipal government recipients
  '1899d688514d0651536482339e377683b86b96a0eb673de2badef384a8f7f3d4', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
  '18adc07eaac029b344fa1b4652c684df704ea88ff468eae0caeedbab0851715d', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
  '1c34e20d013ca77c292b3ed03164bb4e99984323ae42bfd38724fae5dec884d4', // Compromised account - purchase order lure with compromised WordPress credential phishing payload
  '1cd319937d59bfa6aa933172e8f0b63fdb82645372e524c4424cc4b1094e1450', // Compromised domain - scope of work and quote BEC lures; second mailbox on domain already observed in myGov credential phishing
  '1dc7009cf08e4a9891c9e9fa26201263f29826ea71bfd629400ec376a58fda00', // Compromised account - fake financial planning report credential phishing campaigns
  '1ed0614fc9117f62d629d47f93bf2bb7ab0ca5371557818eb8a983f41b2f0f9c', // Compromised account - Zoom meeting and e-signature credential phishing with link shortener redirect
  '1fc806377e831e2a995bcd156644adbe2807db9c2b6c1a8c1fd0df9cb206e101', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '204eba38fc8bee6f69aec26501c467259dc7edf2bf0bab8f90ca9d73e382c38b', // Observed malicious sender - advance-fee investment and project financing fraud campaigns
  '204f687ffc062cec92de70d4ff5e75d78dc017271ceb6e2c02e26f43fe999822', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
  '227595e0898844a4836cd4d986b822f8c30c3b6aa6c46fc5dd83e593e15d2ac1', // Compromised account - high-volume document review lures with randomized reference IDs and Adobe-branded QR code PDF attachments
  '239438cad30f816998539c67804547c18737a486989ce5da2e8e85a28f903f04', // Attacker typosquat domain impersonating STALAM S.p.A. - request for quotation BEC targeting industrial equipment suppliers
  '244e5cf2fff832b4cb24714ad7113bd475d3e0347f1abf97756e825ba0154154', // Compromised account - collaboration and proposal review BEC pretexting under a fabricated sender identity inconsistent with the sending domain
  '245e37a1bf65bb14a41e88c064f2bb0da3416c3fce1571df00095d885b848c8b', // Compromised education account - fake photo share spam with image attachments and a URL shortener redirect
  '25e051ba53581c25f8ce6281b74e56e027c421e090c2d4fa6c16db9da9cf0919', // Compromised account - DocuSign branded document portal credential phishing with recipient address in URL fragment
  '2608a6edfde80841aef1493fa0a515bfee920a971bacf4adf40f6a4e0fe575c7', // Attacker-controlled domain - Purchase order phishing from a recently registered domain
  '26b456acbf4b9e71ab3f94c9c535aa7d280d99b00933dd152be5b7962639e224', // Compromised account - domain renewal payment phishing campaigns
  '2948295e37b555a1b3fd2318a0f4672eeb69a0dfc67283d8f6db19664729f089', // Observed malicious sender - blank subject campaign with unrendered mail merge tags redirecting to an attacker-controlled host
  '2a9b9e226f23ec6375ea7fbc73d2dfe2bfe4d0e09a8ed002226ad2c54659ba50', // Observed malicious sender - Chinese-language enterprise mailbox credential phishing campaigns
  '2c61e0a0f6d48553de52c70d5c84242ee8b550016aa6fdb36abd9c8d7daf624c', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
  '2d08678c9e7efa286265cc1f3786c86f01c9910fad67f98dc9d36dc312808f6e', // Compromised marketing automation account - Adobe branded secure document credential phishing
  '2f8d025a9102603953c1a16e888bed90edc72e9eb34b0a8ef05de2e666ec4292', // Compromised account - ICS calendar invite fake document share
  '2fe6784be1bc4926bf3bc0e3df70ffeb0c21008f74b685c05657989c0ae481d5', // Attacker-controlled Amazon SES infrastructure - mail delivery report quarantine release credential phishing with recipient domain in body
  '3104c37963b8bcbeddbf158f6607384109dc6a9ec24f4610468690fb66f00cf3', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '35023d982780f5605437e9983a3a7e16246440087687647967df0e7ac899f306', // Attacker-controlled domain - account update credential phishing via self-hosted link tracker with freemail reply contact
  '396651544737fd8be74a6eca3624e1cbdc8f6380e700f7d3482287f9ec3eebf2', // Attacker-controlled throwaway account - Meta business page verification credential phishing with Unicode-obfuscated subject and display name and numbered Netlify payload subdomains
  '3a11180346d6de0d66d38dfe9482b0fd998183d30f10d02940d1caf458457d16', // Compromised account - Polish school domain used in BEC campaigns
  '3bc454b83d39fb07a9c9de41111f58acd2f301f7f7b8357d91eca16056a56a44', // Compromised account - advance-fee investment inquiry BEC lures with a typosquat reply contact domain impersonating Nera Capital
  '3bec8e1bc42caa470c611cc5d481a2e0da08c240813a7427b9390f765a4304cc', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
  '3cf5c3a0b8481997224e3397bc52c754d52558e9a3c3ee1faf02c5e58ecc58c9', // Compromised account - ICS calendar invite ACH payment verification lure
  '3d36ba171280784accd5b7bc6f0571664f87ec6954e1c4ac92f1833d67313f44', // Compromised account - EML attachment with a QR code compensation review credential phishing lure
  '3d3f43292b599f983be6822151540437c86fce4dcf9f05e7dad94f3cfd7aff31', // Compromised account - purchase inquiry BEC campaigns with typosquat reply-to domain
  '3f9e2c465ed00925b6904065f599c2a605ee8f15f9fac73626754d28839e370a', // Compromised SendGrid account - credential phishing with randomized document review subjects
  '3fa83cd162a4f95f91d8cd28016dd8b1e557ee3a96e98ec0110ce7f22e387a24', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
  '3fda2f6d720a5a519de4486bb82f0fe089a7f03dc283edcf3d0a1bfc7b12eaed', // Compromised education account - callback phishing fake invoice lure blind copied to Microsoft 365 group addresses, matching an active multi-sender campaign template
  '40742af9c50cbbdd54fda2fedaf88429d78e34f6df5cc0b34fe7851b354472cb', // Attacker registered domain - fake billing review credential phishing
  '41510787bec9cf8433d8a725e9cf8026a27c420e9e2ed20d4fb0218b95813e6d', // Compromised account - advance fee fraud workers compensation fund and inheritance lures with a freemail reply contact pivot
  '416423ad3b195a68f1f8cea67899e4eaf97428c128e2ae30c3fa607f8951c0d6', // Compromised account - Vietnamese university domain used in BEC campaigns
  '4644ba88c2f2fce73f570e2cf5e8d0c6de0d4d8e50bbe62bd14f6364c5748981', // Compromised account - high-volume multi-template credential phishing via Google Workspace SMTP relay, landing pages on compromised sites reached through google.com/url open redirects and reputable click-trackers
  '48736e8d6c36f5232121bc9d9f0a148a09430a3b718695ca296abcb067530284', // Compromised account - Austrian school domain used in BEC campaigns
  '498030e0191b3c9b464b6c92e852a99e6ccd7989d95afd60c7124f45daec7ffd', // Compromised account - quotation request lure BEC campaigns with mismatched display name
  '4992b89b6a829fb3b2df195a325c6c73c4c0706f87ca663e7b92d14700bd4533', // Compromised account - rotating display names in targeted payroll and treasury document credential phishing
  '4bd8d89c85ab0a7ebe69f6a9136f5eea8506e4bc5c8a09108db6bf48e5d8ee97', // Attacker-controlled domain - ICS calendar invite with Google share.google redirect
  '4c254e837ad5e81e0d5316f4a12030b6112577955af3ab7900481835f555bd7f', // Observed malicious sender - advance-fee investment fraud campaigns
  '4c4801bea710a8a5653b1396d139cc4fbf731791dbbf3f21305f2b651cd62d29', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
  '4df47bebfb4e8c9f8b486fad6e3045ce529835572cedfcd6890bad30cebfa8d9', // Attacker-controlled domain - N26 bank credential phishing targeting German speakers
  '4e6e32b31f295cc2fdd1f88bb32c7855ab2e760f21cf834f97abac9e9db68d47', // Compromised account - strategic partnership solicitation BEC with randomized reference IDs
  '50956a216c7edbacd20275707a65dadd1a22cf9e5e00001afaf1c24692124f44', // Attacker-controlled domain behind a privacy registrar - request for quotation reply-chain BEC targeting manufacturing recipients
  '50a5e066da1a7d65d81b3f233272b208c782688634445aeb3f4ae355a6ae6699', // Newly registered burner domain - executive impersonation requesting mobile number for SMS pivot
  '51085bd2a15074f19fd307da1867258dcba93a33ea9a672079a85efd54ed243f', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
  '52460bcbe479bdce1c737d0af3f611143a81d5f12c8457b29c900905834bf0e0', // Attacker-controlled domain behind a privacy registrar - fake Microsoft 365 undelivered message quarantine release credential phishing delivered through Amazon SES
  '53ed891f2c0fb15fcce73a4e6731f1433874dea7d3ba000af1b7e840ed7e329a', // Compromised consumer ISP account - awaiting feedback reply-chain BEC pretexting with a mismatched reply-to
  '548edab40e3bff052d6357c81662ae9d67d1f7fa75bd0491e3e94751fcb1bbcc', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
  '5502acdf89fe972ba391e8aa9355919a1c3f920947169bbd23da5c6383e18433', // Attacker-registered lookalike domain - fake Google review removal scam campaigns
  '57a8b399739a513c38fa4c2f88162f5890f9149b68c34f23e34c60b0fbeab39a', // Compromised education account - fake photo share spam with rotating display names and low reputation redirect link domains
  '598a485295137301401ff1465e9b304a38d6581d7c1e03a3d4de52921bbf38b2', // Lookalike domain impersonating Bapco Energies - export inquiry BEC with mismatched reply-to domain
  '5a03383efec90551b7cd2dca400b07dc9c99479d94d904fc0133dac1814a4d91', // Compromised account - ICS calendar invite fake contract lure
  '5b4a30d023e44f51a487a586db67267773ed53454f4fb7e14fb9782b3bc7ed4e', // Attacker-registered domain - real estate acquisition BEC lures targeting brokerage agents
  '5c04ec6dce7c935c0ef934e88f8757b16aa9b9f400b6433395ea001549bc1f39', // Compromised account - supply enquiry BEC lures with a newly registered reply-to domain
  '5d9e7e39076ea435f8576988c43d553a100d4cae977be38be72c523ea3c083d9', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '5dd6751ee719a5b57e2e739450bbe782a9db7c1efb8768f7bc5e1b1bee59f578', // Compromised account - Costco and Paramount billing deactivation phishing with payloads on free dynamic DNS hosts
  '6042175ee7fade7184f2fea3c5e9008eaa6ee0b2777d6e1d90987bf66d7d1cb1', // Compromised account - payroll update and banking details BEC campaigns
  '6052f572ae56a3ddf1e0c2d9912c80be182312605cbe9d6a4b38041d0811d0a9', // Compromised account - request for quotation BEC with a newly registered lookalike reply-to domain
  '607317145cd319c8e765744a3bc9571743ba8c6d8e2d73c56e3eac33e51c0c09', // Observed malicious sender - blank subject campaign with unrendered mail merge tags redirecting through a relay host
  '6106f4d9431f6f990a68d8de4bf194e5ef5341ac1ba918697c0635b3f93fc77c', // Attacker-registered domain - fraudulent purchase order BEC impersonating equipment manufacturer procurement with typosquat reply-to
  '61fffa77073ca73875d1c738fa8a9628440a07128e50d4b6be57e8a195a4afd5', // Compromised domain - myGov impersonation credential phishing with Australian tax payment lure
  '64fa0322c197928c6d991de6c564eb43a03265cebdd60ce3bf200a0c120daec7', // Compromised account - project inquiry and partnership opportunity BEC lures impersonating CBRE
  '6551838f7e4a651df49fd405ca80fb5832ec26817339dcf2f1f05f0b0f207359', // Compromised account - part-time spokesperson job scam and product inquiry BEC campaigns
  '6784f5d07e939e55fea76d13fa9ac6119ada247536447bb594fb98e4d7ed1717', // Compromised account - mail delivery failure notification credential phishing
  '6977556ab6dade2725e77073483b74294ce491013ff2f1f33a1cc30cb15f8bb3', // Compromised consumer ISP account - BEC first contact with single-word subjects
  '6a9576645d5e70778b6bde0d16285415a2dea7496c54fcfb4885d274dcaabee7', // Compromised account - request for quotation BEC first contact with newly registered lookalike reply-to domain and fictitious contact number
  '6bc270fac6bed884311689fc339a2d5953638d7909359c61348a440de9caf9c1', // Compromised account - purchase order fraud impersonating Manitou Group with typosquat reply-to domain
  '6d2c29e0d973404059aa517e8bacbbbef7fb7644486f1fdce6c4924c32e3d9fd', // Compromised account - ICS calendar invite voicemail lure
  '6ed87d7442a9c67238272ffda2bc11ab7635fdec57fd58cfb289da585eb7314a', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
  '6ee212661325038d04e5652c95726f08d55724429bcc28b7a3637dad745acf5c', // Compromised account - NetSuite accounts receivable aging report share impersonation with VIP invoicing request
  '6fcd011c929ff7d871d21375e5e9468b49397a566524bc9f57ec022dbe047c04', // Observed malicious sender - advance-fee investment fraud campaigns
  '731e54574f28629bfce11244200e89c40b22f24482c6148f883283b45892067e', // Compromised account - project inquiry BEC lures reusing the sender persona from a parallel compromised domain
  '75553065a29e3398457e07de37cfba1ed1c87671a7efac9ec50da431e59b1b79', // Compromised domain mailer - Portuguese language security re-registration credential phishing
  '77629fbddfba6fbb8423b8f3d9e32891424aa5ba11073b6c8e65f04718970982', // Compromised university account - fake photo share and fake forwarded thread campaigns
  '77df91f5bd3c2e212d6a97a37f9096c7066a38ef5df4da445a83a5a8f8f94500', // Compromised account - fake voicemail and remittance notice credential phishing campaigns
  '7c117ed39641278555ae674d9e4d469eae35f1321a45934a31f09cddccabd3a7', // Attacker-controlled domain - fake document share via attacker-provisioned Dynamics 365 marketing tenant redirecting to compromised site with recipient email in URL fragment
  '7c711457c1affc6bdf1a622a22f81f624e034448548e625117d1091f848ddc7c', // Compromised account - ICS calendar invite document review lure
  '7c8569f4156a396673e5509f5c3a4b1aaf30761802631478bd59bec9c2ff0459', // Attacker-registered domain - German language inheritance advance fee fraud campaigns
  '7da8a342aa3d2e085f144bdcc9554df29c4419581c86b09e48ca8f602e645ace', // Compromised university account - advance fee fraud congratulations lure with an attacker-controlled reply contact domain
  '7e7cb86170d9d8c6c183222448955820f67d9cfdd08b95ebd7e163be6077454a', // Compromised education account - booking confirmation reply lure linking to credential phishing HTML hosted on Amazon S3
  '7f82c9f6763c54de2ac9ba07db314f0c99a4828c895aa7a0b139b22206e642c1', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '7f866abd59466f633368c2c658e388794d4a26c8cfc1c4122ea2eef5a87ec0fb', // Compromised account - empty subject reply-chain BEC pretexting with a freemail reply-to pivot
  '7f997ff6ee6e189af585d4291b8944fd22cb02358f4294886cc755518efa60aa', // Compromised account - part-time spokesperson job scam and product inquiry BEC campaigns
  '81c391208275700266de52f05176151b490fc98ac303c69aade60c4dd7733e6e', // Attacker-controlled domain - numeric-hex reference code reconnaissance
  '82f54cefc0ea8ea3344762e170acf0511ec0102e845c2b72c0373de521fa36d8', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
  '858214f8881d63a66b52ab87585f04465a31875e77755fe489b8e2291fe1c593', // Compromised school account - digital invoice lure with PDF attachment
  '87014bc8f121aa71f5319e62375d4574abac28b8c32005a2c85db2b227bc4e06', // Compromised account relay - advance fee fraud, DocuSign contract, email deactivation and billing review credential phishing campaigns with payloads on compromised sites
  '875a5fa3440dc3e03efd0ccdc4b3006ffa6ab23eb8f1287dcd27ac6578c5ee41', // Compromised Amazon SES tenant - Toast payroll notification impersonation with credential phishing payload reached via neogrid open redirect and diverted reply-to
  '87eb1efe1ab4ff5ef8767c19f6ccd837b2dac092b70092b56e3e59302035ad84', // Observed malicious sender - Norton subscription renewal credential phishing campaigns
  '88653d86088efa5cbf02791a9f2480e507abd28c463b288e1220d5cf2a9c19f8', // Compromised account - company proposal lures with Zoho Writer published document payload
  '896ce3441bc7c3d3dfee3f8947965492ed7160596b8f09eff9f625412b5a619d', // Attacker-controlled typosquat domain - ICS calendar invite fake document share
  '8b6199148560383d2fca031052475ca2627637fdf4a883dd475c9f3a51d39887', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
  '8c4ffc408b379a7649bef8b6fe6dedf467960627897eae7742091d98fc79a263', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
  '8c61b30c46de11fd376026587646066325cc31f9749381abe2280b1fc1b58fbc', // Compromised account - invoice notice and ICS calendar invite voicemail credential phishing campaigns
  '8d0a6552bc32f3704106dcbdd393c73ceb29a4bbfd7f0ec207ea438c757b608e', // Compromised Vietnamese bank account - advance fee fraud gift and prize campaigns
  '8d6d35f92d52490cfd8c2153a979604b95aabb430eef256486600075465e80b8', // Compromised Kenyan school account - thread hijacking with credential phishing link
  '8f8ea31184fbfd5633983283a4946d44f74638d521ad3bba9d967f5a128c2ad1', // Compromised education account - fake photo share spam with image attachments and a Google Sites redirect landing page
  '90349b130b8bf9d0a06f809c78b3e1926e0b02d4797bee3fd614eec5f9f9c9d8', // Compromised account - proposal review lures with PDF attachment impersonating the owning business
  '9059acff3ee9f042e49bafad2fa905051fd0b4817e4434c4a44b463ebf422963', // Abused ESP subdomain - parcel delivery notification phishing redirecting to a compromised WordPress host
  '91fe8f768fdef0efacb6325ad65b4d5922789d49dc2b253e7e352367ac8608fc', // Observed malicious sender - advance-fee investment fraud campaigns
  '955ae08074c3cf8fff4143461c371ece9690921a27896d18b3c34f6afa65b48f', // Compromised government account - service solicitation BEC campaigns with mismatched display name
  '9565c234e0c50c63f3a05123e98e324988744230ef3b14dcabafaa45e162bc25', // Compromised account - payroll and compensation statement lures with credential phishing PDF attachments relayed through SES
  '97956c1c9b21e5499a9363040b419b349b91bf5d594cd343303c98f2ff7f59d2', // Compromised account - Brazilian invoice (NFe) lure with HTML payload hosted on Azure blob storage
  '98efda257ce741da148c18cdf32a60bb37952c322a9df9d9f996591b0670f52d', // Attacker-registered domain - title order and wire fraud lures spoofing a Chase title team address
  '9a431f19cd293db92b46516921b57a145933fb84bcd74b61d030a563acba7080', // Compromised account - company proposal lures with Zoho Writer published document payload
  '9ac3bc28005ac615607c878c119118698b368217633d616082bd6b619bca8224', // Compromised university student account - advance fee fraud to undisclosed recipients with freemail reply-to
  '9ad52736e4eb32a906e646cb4c16f38c318e44922666f59d1652b85d2a7a7680', // Compromised nonprofit account - ICS calendar invite credential phishing
  '9af400fa39126d7ad6a34adbd1bc681fdeec84e9542def79e3e49bd170bfe328', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  '9c49f7240d126b9769580d403a5e5cd759edaaa1c32ec92b0a076c2ac96a8235', // Compromised account - sales inquiry BEC with attacker-controlled reply-to domain
  '9ce5faf38597804a6513b30ec3929fd4beacb240ed304cd4f07be163afe149df', // Compromised account - German language tyre system invoice lure delivering a compressed archive payload hosted on Dropbox
  '9d20cf849102d8c4bfec9c15c2d79fa408502657a4455cacaa2bc725fec078ae', // Compromised account - tool giveaway lure with Google Cloud Storage redirect
  '9d5c11b2b6dc2f8c0e7962302796a9862512530b938025c44e114a2a66586902', // Compromised account - company proposal lures with Zoho Writer published document payload
  '9fda882aad59efabf9e2c45a9f1490e87deb323de5aedcf80b4bfbbf1c21f8b0', // Compromised account - fake eDocument task and Teams share credential phishing campaigns
  'a15404dc1be5940267fbd4fb7f673f4b0715eb0eb19bbfabfc8394f28a96b243', // Compromised account - fake HR policy violation notice harvesting credentials via SendGrid click-tracked link, personalized with recipient name and job title
  'a206e5b140de73c7ef373197d929c99a26ec416c7fdeef66ef7b4593a11c9595', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
  'a2bbaa6824197630b7b9fb12296405481f6d2224194559c1ee39a635f8603cfc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
  'a3473438fe21318a0e950cf1c01309d84a8fb0bd287276e0dc90e33501d3e233', // Attacker-controlled domain - BuildingConnected impersonation credential phishing with visit tracking
  'a4312827c4ed4900fa06d6f3058edc203fe85683b6de585d1fae5becd4700a6b', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
  'a4f740abf0fa1c0a6c26a9acdff1248e6cd147b392b5806028515ae3da389785', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
  'a5e72048f261715f3e7ce6d2cc8916bd2a3e230e5dba3f6bfa3fbf8756ac7381', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
  'a7fc25e74dec71054e0d8da967f612612fe926aa2fd29618d1ad4e9316e93988', // Attacker-controlled domain behind a privacy registrar - empty-subject fax transmission log lures using an Xfinity tracking open redirect to an Engagis OpenID credential prompt
  'a9f1555662a63f40e3e1260a33ef1f119aec0c79a052d58094732dbe82e56f7b', // Compromised account relaying through an attacker-controlled Google Group - hidden Google Sites credential harvester behind a decoy Acrobat link
  'aa679ede4b58f308084c907834ee382b80f6d74aa0161c06ad873a5605e08241', // Compromised consumer ISP account - executive impersonation requesting mobile number for SMS pivot
  'ab89b7242f2e0ebf76e8af17516aa8273c9002480e94a10dd29cb94252a2d5e6', // Compromised account - lender branded secure message credential phishing distributed via SendGrid
  'add7445fa0b8209b0da2e500b8c50231fc4c0f8c029a38659dd2e5ee58ff85c7', // Compromised account - empty-subject fax transmission log lures using an Xfinity tracking open redirect to an Engagis OpenID credential prompt
  'ae42584dfd37653be7e42203ca5b6ad5508a639726ab5cbb65ba58085e54c6b4', // Attacker-controlled typosquat domain - numeric-hex reference code reconnaissance
  'b044f948af172622b44fec0affad51861ff32c5f6ba5bcda261293e35a6b5d3b', // Observed malicious sender - advance-fee investment fraud campaigns
  'b1636bd79df0c1cecfb3213ffc0f921d23c73435cabcc2ff03c759c14c896170', // Attacker-registered domain - completed document notification credential phishing via marketing automation tracking links
  'b1a62e7738fae564eb985703a8b73efa43e50dd6f9d97e32c5ea38332f1496cd', // Compromised account - project and proposal inquiry BEC lures sent without payload links
  'b3a315352bd909eee0c773071df508ef0487f0180df22017c6e5e5eb40d77301', // Compromised Japanese company account - parcel delivery credential phishing
  'b4751533eefe4d0cc630fd5dce52e043a1ff6617238b2ebe3b7290899bbe241f', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
  'b4a1ad4e015be4e6dac4e9ebedb23615e2db8287afe0198f3a1ecde7ed5722ec', // Compromised account - SF Express shipment notice lures with recipient address in the subject and payload staged on a CDN asset host
  'b6878960db617a69fed9fe072dce897e8f76c2bf9cf2f93171e442f74ccc8f25', // Compromised account - repeated BEC first contact with single-character subject
  'b7415f1380d0a89b124bce7de8b1eee96dc452f9c95252192176cd427020b060', // Observed malicious sender - contract agreement BEC campaigns using freemail reply-to mismatch
  'b77161f16370afbd32afd8e613be5ffb1a9d9e99e1b8d3e547cf6379ab55c6ca', // Observed malicious sender - spoofed sender in fake forwarded thread membership invoice fraud campaigns
  'bb87499a229e0f70ebd20d8d3be83d426c898c01ee3a4b8706abc5d78d9146df', // Compromised account - ICS calendar invite credential phishing
  'bb8e9bf6bd2e4c3749b5b778222c6c52097de3a98f0a56ea358b6e31081d2b17', // Compromised Amazon SES tenant - credential phishing sent from click-tracking subdomain with decoy Alignable and Intuit links
  'bd39e620e9fd143d50ee834ba38bff60d80bf4dc36681c5d3e02757dedecfdcf', // Compromised account - product pricing and event space inquiry BEC lures
  'be44430a667b7776e351cf54a66f85716de0731dcb1245b7c5bca081e4cd80a5', // Observed malicious sender
  'be6f44a266193db11f641f64f34eb011a636fde8696dc95f82d4d3c3090a1b75', // Compromised account - mail delivery failure notification credential phishing
  'be75194b73d1bb258beb4ab257211d4ba6be240a485d60b2f4346b4d3171d5e4', // Attacker-controlled domain registered days before use - BEC first contact with an alphanumeric reference code subject
  'beca37c439dbac64c07a144e36c1c057cb9b2a0d105b464f88e0a023298599cf', // Compromised account - brand impersonation with reply pivot to a lookalike domain
  'bf5d4be8d2cee2476e9a226bd955f41819e4b01976f9bbd91b58bc82f057d4f6', // Observed malicious sender
  'c178b0a38ad2fdbdb40b7851d0fa4ed962b1252b1b7e7d6c04c4f2d6260f560f', // Compromised government account - Microsoft 365 subscription expiry credential phishing
  'c35764206e9ae5372498a5c7562e52632a0ddadecd1973d71b9d448624ae3b16', // Compromised account - urgent notification lure via cloud-protect.net redirect
  'c36ea820ad081f649f670a3d98b079c6897554749fe85af4afc11f6a5badd2d7', // Compromised government mailbox - price inquiry and project proposal reply-chain BEC pretexting with no sender signature
  'c5dfb0030991c22aad632fb5d57e7eac57f6379ff3165fcf5d170a6d730c4538', // Compromised account - ICS calendar invite fake document share
  'c75f2d07928e315171113031a6a1a54bed3a6a6cd53b293a8e9015222de1fb32', // Compromised account - supplier purchase inquiry fraud with typosquat reply-to domain
  'caed0ffc5a2f2858ef33956eeaf3f1309467e352506dbc200bed299a3ce71420', // Observed malicious sender - advance-fee investment fraud campaigns
  'cafb217669aba8cea858f44e7c4672644015a9d76e4c8de4a53fcc98e3f66881', // Compromised account - company proposal lures with Zoho Writer published document payload
  'cbb683f2108bf5c91e5da136b20d94e299bd8a027311afd10f17575f0a166f19', // Attacker-controlled domain - homoglyph brand impersonation with open redirect chain
  'cc154336dc3d3f9af8226bb0e5fe764a822d5d8063601d0572ae0368395c71c2', // Compromised account - Cyrillic homoglyph voicemail notification credential phishing with a punycode obfuscated redirect chain
  'ccbb818f79e89f26de61674b90618330fcaca8d6630fc44b3c51a161ed06bdfb', // Compromised account - quote request vendor fraud BEC lures with a TLD swap typosquat reply-to domain targeting construction county government and healthcare recipients
  'cd020f36af6c65e3953816094eee6b2e57f888d01cf00de9017ff4d3c63f8e07', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
  'ce3ba673d30f2a4aa04809e8e709c1ec04e21b2d3474e5c57b61653c2646b9be', // Compromised account - fake document share and edit invitation credential phishing with HTML whitespace stuffing
  'd0c976c4f72edb8094a4258e4c1bbb3b21ba17c30e0e95f7e32e5e8457c43335', // Observed malicious sender - Robinhood and Interactive Brokers lookalike domain credential phishing via account security alerts
  'd16ec6c5e981e96ac5d3de0089ed6419eef9ad23a712fe3fd9e8bec97e62b063', // Compromised account - Banco do Brasil pending procedure notification credential phishing
  'd42970a5e7e999074b5f3055823dcb66840d3a8787fb38958a7e1d650eb093c8', // Compromised university account - advance fee fraud first contact lure with an external consultancy reply contact pivot
  'd8aab2b15d8bbfd7e2fac6310ad0369eec56540cd67ed90313045cacda7f3c80', // Compromised account - mail delivery failure notification credential phishing
  'd931f0c6ddded184ac8e0a6dcdb356fc0d4f64fe2c852f587db149d942c2e5e3', // Compromised account - Dropbox Paper credential phishing to undisclosed recipients
  'da53b2817a57c3914b74d12c9bfd9a88299a52b595401bc495c3ac85cfbb5521', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
  'db92038c5432edd7ce1df22ae4ffc173eff2ab6f6dc9f77e435b6437d6a788db', // Observed malicious sender - advance-fee project funding fraud from newly registered domain
  'dc01b1e4b74adb29a9e2ff4f29a34076f61c87cf04f620cef525d5070818687c', // Observed malicious sender - advance-fee investment fraud campaigns
  'dcf926c300e21c985ff97951bb747662f4d89b68ebd2ec2346792ea69534cafc', // Attacker-registered domain - realtor-targeted program eligibility confirmation lures
  'de7deda77de750c100c517564cbf2ffbec72001d31203ed7eb5c45635945ea5f', // Attacker-controlled Amazon SES infrastructure - mail delivery report quarantine release credential phishing with per-recipient display name spoofing
  'dff78965cc2c55b284990806f57a9ac6c4da7e50271a5a1473fb7b6bd557ff4e', // Attacker-registered domain - purchase order and RFQ review BEC lures behind an unscannable Cloudflare link
  'e06aa193933815324af2fee9d3c250dab080a681b9658253ce2b0af0466cbbd1', // Observed malicious sender - advance-fee investment fraud campaigns
  'e0b7349e426e4ad21dc9512fdd04e821c66f92a00fa81a79536f2ef36adbc562', // Compromised government account - technical support lure with Constant Contact landing page
  'e0da1bd70a04552d8104ae6d11b2eeb477b6dc8ecbd257d5dcde3bec0127044e', // Observed malicious sender - bid solicitation and RFQ vendor impersonation campaigns using typosquatted reply-to domain
  'e2ac59798b67d702ccb16fb33a126c17fa5b437d43eedce5e5574d9961609085', // Compromised government mailbox - null subject BEC pretexting under a fabricated display name with a freemail reply-to pivot
  'e39218d8dd92ed4eabe4417733d40cfafe7de1fcce268bef9f33f624c9a90152', // Compromised account - recruiter corporate bill invoice fraud with generated PDF attachments
  'e496f21a9a64bb06d1c3c9f3ce6df5a4fec04e513e51c9d05d6637e48036e9e8', // Observed malicious sender - advance-fee investment fraud campaigns
  'e52716b8b92a14d06f4cd11f94237660a087229eb19ef96e76ee312334ba2210', // Compromised account - fake email quarantine and pending message approval credential phishing with compromised WordPress payload
  'e58acee1778ebb1f0a3fd8aecaf8707976b7cf6edd44dddcc8638a772864084d', // Compromised account - QuickBooks payment confirmation impersonation with typosquat payload reached via open redirect
  'e829d4a1070b56abae6b5c0e81f76dc41feacd256c9e97f719e8478872ca5d55', // Compromised account - invoice fraud with ACH payment urgency and recipient company display name spoofing
  'eaef6d29428f22885109b201072d03826b5579b4b84658ab69e637659feabcc6', // Newly registered burner domain - executive impersonation requesting mobile number for SMS pivot
  'eaf8cfe2d96cdb4f17819f77aad91fd9555fb82be5124b112a70d252f92219c6', // Compromised Japanese company account - vendor invoice BEC with fabricated internal exec forward in .msg attachment and lookalike vendor domain
  'ec3d8dc44fa1143a7b438cf06cfb39d57ab26947f089bb03d723e11a515dddf7', // Compromised consumer account - executive impersonation BEC first contact requesting phone number
  'ec9c01b0c4fbe5de2fb5065ab31cfb80304179a889a513f8bae112cc5d544331', // Compromised account - remittance notification document share credential phishing campaigns
  'eceeea014ecc4f86431c8e49e16d74fcb1bdb2003f05a0e4166da37512f11847', // Compromised consumer ISP account - BEC first contact probe with display name impersonating a vendor executive
  'eda233116ef0046c1ab0b64ce9e8654b808efafb0cb602de669a0722cc012de7', // Compromised account - per-recipient templated RFP solicitation BEC
  'ee4873fd02b2832cc47f937d09368e26b08589967552c22551efc3d45856384d', // Attacker-controlled throwaway account - Meta business page verification credential phishing with Unicode-obfuscated subject and display name and numbered Netlify payload subdomains
  'ef25dfa33c53628cf72f4902874212da1bd60bf38224a1781a059ccd168ad664', // Compromised student account - BEC first contact with mismatched reply-to
  'f206926f3b476970e4132e3d9dd32170a5e991d5fba5883389f1d4a18c39aa40', // Attacker-controlled domain - request for quotation lure with excessive URL rewrite encoder chain
  'f2231cb4a71ce384c1dd949af538dd25761776366a0f0b76ed4c889aa6488c4d', // Compromised SendGrid subdomain - fake eDocx pending task credential phishing
  'f23450c74fbd8e5379835a6961f3cb92f0222573f6839469384717b4f1ed46f2', // Attacker-controlled lookalike domain - procurement sourcing BEC lures impersonating an unrelated metals supplier
  'f33c82ad311018d7a88bf14b94be5cfa42afdbe529edc8086b0c11e1159648df', // Privacy mail burner account - executive impersonation requesting mobile number for SMS pivot
  'f5ee438bbfbde02b493f726c06351325bfc31085e3056aaba768db9211893bc0', // Compromised account - fake webmail password security notice with recipient email in URL fragment
  'f7134c981f996cacd56e1e541ba5179cd35292078496e981aec26fea016a3e14', // Compromised account - USAA claim adjuster impersonation with PDF attachment
  'f88ea669b8f785c1afc0c04e15b412a1e7199c542b69fae9fc83a3260b9181f2', // Attacker-controlled domain behind a privacy registrar - fake EE rewards points expiry credential phishing delivered through SendGrid
  'f92b12adb9911b249d6b774bbea0fe7e2481192e2ed99583c8a391be59802e1a', // Compromised marketing automation account - Adobe branded secure document credential phishing
  'fa85690cd62ab68ed9168a43567f2868fa120aa73565a082a87443877d0c25e6', // Attacker-controlled domain - multi-lure credential phishing and BEC with homoglyph brand and university display name spoofing
  'fcf380341ec080be2082bbf4c3a21fcd5dc2d79f5b50d7bc868c83f96ca6631d', // Attacker-registered domain - executive impersonation BEC reply lures
  'fde63093f069fd00d5d5b0a8aff58e2e55646f0de7dadcd5b78c0511c16bf6cd' // Compromised account - credential phishing with recipient address in subject line and URL fragment
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started