Cybercriminals are leveraging phishing emails to infiltrate Microsoft 365 accounts and search for payroll-related files.
Ref id: [random string] Voicemail-lure subject format used in inbound messages URL https[:]//meet.google[.]com/linkredirect?dest=https[:]//www.google[.]com/url?q=amp/adservice[.]google.com.ph/ddm/clk/424929466;226923624;r;u=ds&sv1=64195420186&sv2=3261659123742877&sv3=6702577448695742699&gclid=EAIaIQobChMIurHiwbHn8gIVBZ53Ch2TZAIsEAQYASABEgKAL_D_BwE;?//s3[. ]us-east-1.amazonaws.com/amzn-5646353653563view/url Example multi-stage phishing redirect Domain ogads-pa[.]clients6[.]google[. ]com Google Ads-related domain resolved in redirect sequence Domain ep1[.]adtrafficquality[.
]google Google Ads-related domain resolved before phishing infrastructure Domain ep2[.]adtrafficquality[. ]google Google Ads-related domain resolved before phishing infrastructure Redirector domain idp[.]keyreniao[. ]com AiTM redirector observed in campaign activity Redirector domain idp[.]korminel[. ]com AiTM redirector observed in campaign activity Redirector domain idp[.]kualabemo[.
]com AiTM redirector observed in campaign activity Proxy domain mslogin[.]milocaroline[. ]com AiTM authentication proxy Proxy domain msonline[.]logicalineonline[. ]com AiTM authentication proxy Proxy domain msauth[.]monlinelogicaline[. ]com AiTM authentication proxy Lookalike domain office[.]ofrecie[.
]com Misspelled Office-themed domain pattern URL path /st_58200519/class_identifier.php Browser-fingerprinting endpoint on phishing infrastructure Domain api[.]country[. ]is Geolocation API queried by phishing-kit JavaScript HTTP header server: openresty/1.31.1.1 Response header associated with AiTM proxy and fingerprinting endpoint HTTP header x-powered-by: Express Response header associated with AiTM proxy root HTTP header x-powered-by: PHP/8.2.32 Response header associated with fingerprinting endpoint User-Agent Firefox/131.0 Anomalous Outlook sign-in user agent User-Agent Firefox/151.0 Additional anomalous Outlook sign-in user agent User-Agent Python Requests User agent observed in recurring session-maintenance activity User-Agent axios/1.18.1 User agent linked to Microsoft Graph reconnaissance Mail access pairing ClientAppId: 5d661950-3475-41cd-a2c3-d671a3162bc1; APIId: c999ed3e-27ae-4cb3-b3a2-46b056af63d3 High-confidence MailItemsAccessed indicator Mail access user agent Client=REST;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0 User agent associated with suspicious mailbox collection Entra sign-in signal errorCode: 90014; appDisplayName: OfficeHome Rare authentication error pattern associated with campaign activity Graph endpoint https[:]//graph.microsoft[. ]com/v1.0/users?$top=999 Tenant-wide user-enumeration query Graph endpoint https[:]//graph.microsoft[. ]com/v1.0/me Microsoft Graph endpoint queried during reconnaissance ASN AS27176, Datawagon LLC Hosting provider observed during interactive inbox-rule activity Integrate real-time threat intelligence from MISP, VirusTotal, or your SIEM to prevent potential cyber threats like phishing and malware attacks.












