JELAJAH SOC
YO

INC-1042 · owner D. Kusuma

Password spray followed by mailbox rule abuse

A spray campaign from hosting infrastructure compromised one account without MFA. The actor created a hiding inbox rule consistent with business email compromise preparation.

All incidents
highContainedSLA 8h response · metcollaborators: You

Evidence panel

Pivotable entities

MITRE ATT&CK

T1110.003T1114.003T1078

Attack timeline

Build the sequence of the intrusion

  1. 02:41

    Spray begins

    61 accounts, 4 source IPs

  2. 02:50

    Successful sign-in

    r.wijaya from 45.133.1.87

  3. 03:06

    Inbox rule created

    Rule '..' moves security mail to RSS Feeds

  4. 05:12

    Containment

    Sessions revoked, password reset

Linked alerts

Containment actions

  • Account password reset and sessions revoked
  • Inbox rule removed
  • Source IP ranges blocked

Recommendations

  • Enforce MFA for all users
  • Block legacy authentication
  • Alert on inbox rule creation by default

Case tasks

  • Confirm no mail forwarding externallyD. Kusuma
  • Notify the account ownerD. Kusuma
  • Tenant-wide MFA gap reportYou

Investigation notes

    Audit trail

    • System · Incident created from ALT-24011970-01-01 01:50:00Z
    • D. Kusuma · Status changed to Contained1970-01-01 04:00:00Z