The Award I Didn't Enter Somehow Won Me First Prize
The email began with one of the most dangerous words in the inbox.
Congratulations.
Apparently, GEMXIT had been selected and approved for a business award. There would be recognition, a certificate, a badge and a directory listing.
This was excellent news.
There was only one small problem.
I couldn't remember entering anything.

The Congratulations Test
An unexpected compliment can lower the guard before the real request appears.
The email arrived carrying its own applause
First question: have we seen this sender before?
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ "wcbrb.com"
or Subject has_any ("Congratulations", "Best Businesses", "Award")
| project Timestamp,
SenderFromAddress,
SenderFromDomain,
RecipientEmailAddress,
Subject,
DeliveryAction,
DeliveryLocation,
ThreatTypes,
AuthenticationDetails,
NetworkMessageId
| order by Timestamp descAuthentication answers one question — not all of them
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ "wcbrb.com"
| extend Auth = parse_json(AuthenticationDetails)
| project Timestamp,
SenderFromAddress,
SenderFromDomain,
Subject,
AuthenticationDetails,
ThreatTypes,
DetectionMethods,
DeliveryAction,
DeliveryLocation,
NetworkMessageId
| order by Timestamp descNow inspect what the email wants you to click
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ "wcbrb.com"
| project Timestamp, NetworkMessageId, SenderFromAddress,
RecipientEmailAddress, Subject
| join kind=inner (
EmailUrlInfo
| project NetworkMessageId, Url, UrlDomain, UrlLocation
) on NetworkMessageId
| project Timestamp,
SenderFromAddress,
RecipientEmailAddress,
Subject,
UrlDomain,
Url,
UrlLocation
| order by Timestamp descHunt for the pattern, not just this organisation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
EmailEvents
| where Timestamp > ago(30d)
| where EmailDirection == "Inbound"
| where Subject has_any (
"congratulations",
"selected and approved",
"business award",
"best businesses",
"recognition",
"verification certificate"
)
| summarize Messages = count(),
Recipients = dcount(RecipientEmailAddress),
FirstSeen = min(Timestamp),
LastSeen = max(Timestamp)
by SenderFromDomain, SenderFromAddress, Subject
| order by Messages desc
