The Reply-To Address Told The Real Story
The email had no subject.
It promised a MoneyGram donation gift and a cash prize of €520,000. The sender appeared to be one person, but the message told the recipient to reply to a completely different Gmail account.
Agent Foskett did not reply. He opened the evidence instead.

Briefing summary
A crude prize scam still teaches a serious investigation lesson. The visible sender was not the reply destination. The attacker did not need the victim to click a link. They only needed the victim to answer the wrong mailbox.
The email was bad, but the tactic was real
The evidence in plain sight
Why Reply-To matters
The first Defender XDR question
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
EmailEvents
| where Timestamp > ago(30d)
| where Subject == "" or isempty(Subject)
| where SenderFromAddress has "sanbernardo.cl"
or SenderMailFromAddress has "sanbernardo.cl"
or AuthenticationDetails has "sanbernardo.cl"
| project
Timestamp,
NetworkMessageId,
SenderFromAddress,
SenderMailFromAddress,
RecipientEmailAddress,
Subject,
ThreatTypes,
DeliveryAction,
DeliveryLocation,
AuthenticationDetails
What Defender can tell you quickly
Search for the scam language
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
EmailEvents
| where Timestamp > ago(30d)
| where Subject == "" or Subject has_any ("gift", "donation", "cash", "prize", "MoneyGram")
| where AdditionalFields has_any ("Moneygram", "520,000", "donation gift", "cash prize")
or AuthenticationDetails has_any ("Moneygram", "520,000", "donation gift", "cash prize")
| project
Timestamp,
NetworkMessageId,
SenderFromAddress,
SenderMailFromAddress,
RecipientEmailAddress,
Subject,
ThreatTypes,
DeliveryAction,
DeliveryLocation
Important analyst note
Compare sender domains at scale
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
EmailEvents
| where Timestamp > ago(30d)
| extend SenderFromDomain = tostring(split(SenderFromAddress, "@")[1])
| extend SenderMailFromDomain = tostring(split(SenderMailFromAddress, "@")[1])
| where isnotempty(SenderFromDomain)
| where isnotempty(SenderMailFromDomain)
| where SenderFromDomain != SenderMailFromDomain
| summarize
Messages = count(),
Recipients = dcount(RecipientEmailAddress),
FirstSeen = min(Timestamp),
LastSeen = max(Timestamp)
by SenderFromDomain, SenderMailFromDomain, DeliveryAction, DeliveryLocation, ThreatTypes
| order by Messages desc
The fraud path if the user replies
Check whether anyone clicked anyway
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
let SuspiciousMessages =
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromAddress has "sanbernardo.cl"
or Subject has_any ("gift", "donation", "cash", "prize", "MoneyGram")
| project NetworkMessageId, SenderFromAddress, RecipientEmailAddress, Subject;
EmailUrlInfo
| join kind=inner SuspiciousMessages on NetworkMessageId
| project
Timestamp,
SenderFromAddress,
RecipientEmailAddress,
Subject,
Url,
UrlDomain
Hunt for user interaction
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
let SuspiciousMessages =
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromAddress has "sanbernardo.cl"
or Subject has_any ("gift", "donation", "cash", "prize", "MoneyGram")
| project NetworkMessageId, SenderFromAddress, RecipientEmailAddress, Subject;
UrlClickEvents
| join kind=inner SuspiciousMessages on NetworkMessageId
| project
Timestamp,
AccountUpn,
RecipientEmailAddress,
SenderFromAddress,
Subject,
Url,
ActionType,
Workload
| order by Timestamp desc
Agent Foskett moment
Questions every analyst should ask
Related investigations
Final thought
The Reply-To Address Told The Real Story
This Agent Foskett investigation explains how a suspicious cash prize email used a mismatched Reply-To address to move the victim into a fraudulent conversation.
Microsoft Defender XDR Reply-To Email Investigation
EmailEvents, AuthenticationDetails, SenderFromAddress, SenderMailFromAddress, DeliveryAction, DeliveryLocation, EmailUrlInfo and UrlClickEvents can help defenders reconstruct suspicious email investigations.
Reply-To Fraud, SPF, DKIM, DMARC And Composite Authentication
Reply-To mismatches can reveal social engineering, impersonation, suspicious sender identity, fake prize scams, advance fee fraud and business email compromise patterns.
