INC-1042 · owner D. Kusuma
Password spray followed by mailbox rule abuse
A spray campaign from hosting infrastructure compromised one account without MFA. The actor created a hiding inbox rule consistent with business email compromise preparation.
highContainedSLA 8h response · metcollaborators: You
Evidence panel
Pivotable entities
MITRE ATT&CK
T1110.003T1114.003T1078
Attack timeline
Build the sequence of the intrusion
- 02:41
Spray begins
61 accounts, 4 source IPs
- 02:50
Successful sign-in
r.wijaya from 45.133.1.87
- 03:06
Inbox rule created
Rule '..' moves security mail to RSS Feeds
- 05:12
Containment
Sessions revoked, password reset
Linked alerts
Containment actions
- Account password reset and sessions revoked
- Inbox rule removed
- Source IP ranges blocked
Recommendations
- Enforce MFA for all users
- Block legacy authentication
- Alert on inbox rule creation by default
Case tasks
- Confirm no mail forwarding externallyD. Kusuma
- Notify the account ownerD. Kusuma
- Tenant-wide MFA gap reportYou
Investigation notes
Audit trail
- System · Incident created from ALT-24011970-01-01 01:50:00Z
- D. Kusuma · Status changed to Contained1970-01-01 04:00:00Z