sync: auto-sync from HOWARD-HOME at 2026-07-15 11:39:11

Author: Howard Enos
Machine: HOWARD-HOME
Timestamp: 2026-07-15 11:39:11
This commit is contained in:
2026-07-15 11:39:45 -07:00
parent aae897abfe
commit 71aa0da646
13 changed files with 3175 additions and 7 deletions

View File

@@ -0,0 +1,70 @@
# Phishing Investigation — "Past Due - AMU54618 - AMYSH Solutions"
- **Date (UTC):** 2026-07-15
- **Tenant:** cascadestucson.com (`207fa277-e9d8-4eb7-ada1-1064d2221498`)
- **Reported by:** Chris Knight (via Mike/Howard)
- **Investigated with:** ComputerGuru Security Investigator (Graph read + EXO read), read-only
## The message
| Field | Value |
|---|---|
| From | Dax Howard `<info@syufway.com>` |
| Reply-To | `dax.howard@steqm.com` (mismatch — classic BEC indicator) |
| To | `accounting@cascadestucson.com` (only recipient in tenant) |
| Subject | Past Due - AMU54618 - AMYSH Solutions |
| Delivered | 2026-07-14 17:32 UTC (10:32 AM AZ) |
| Internet-Message-Id | `<NSCCVAyTgUFD3cMIwaf4nl5G1cSc5xC4W4Cr1Rrk0c@localhost>` |
| Attachment | `W9_AMYSH_Solutions54618.pdf` (84 KB) |
Two delivery attempts ~10s apart:
1. **17:30:23 UTC — Quarantined** as **High Confidence Phish** (never released).
2. **17:30:34 UTC — Delivered** to the Inbox (second copy evaded the filter).
## Attachment analysis
The PDF is a filled **IRS W-9** for "AMYSH Solutions", EIN 92-4058031, 75 E Santa
Clara St, San Jose CA 95113, signed 04/11/2026. **No URLs, no QR code, no active
content.** This is a vendor-impersonation / BEC setup: get the target to onboard
a fake vendor and pay a fraudulent invoice. The email body claims to forward an
invoice from "Skylar Green, Billing Coordinator, AMYSH Solutions".
## Who opened it (MailItemsAccessed audit, delivered copy)
Mailbox delegates with FullAccess: ashley.jensen, lauren.hasselman,
zachary.nelson, Chris.Knight.
| Time (UTC) | User | Client |
|---|---|---|
| 2026-07-14 17:32:06 | ashley.jensen@cascadestucson.com | Outlook Android |
| 2026-07-14 17:33:30 | Chris.Knight@cascadestucson.com | Outlook desktop |
| 2026-07-14 18:16:43 | ashley.jensen@cascadestucson.com | Outlook Android |
| 2026-07-14 18:54:59 | Chris.Knight@cascadestucson.com | Outlook desktop |
## Did anyone respond / act on it?
- **No outbound mail** from the tenant to `info@syufway.com` or the reply-to
`dax.howard@steqm.com` (message trace 07-13 → 07-15). Nobody replied.
- No link/click risk — the PDF contains no links.
- Risk is limited to *future action*: paying the fake invoice or emailing the
reply-to address.
## Verdict
Confirmed phishing (vendor-fraud/BEC lure). Defender already classified the
first copy as High Confidence Phish. Opened by Ashley Jensen and Chris Knight;
no reply, no click, no payment action observed. **No compromise indicated.**
## Remediation performed (2026-07-15, approved by Howard)
1. [OK] Delivered copy moved to Deleted Items in the accounting mailbox
(recoverable if ever needed for evidence).
2. [OK] `syufway.com` and `steqm.com` added to the Tenant Allow/Block List
(Sender block, no expiration) — future mail from either domain is blocked.
3. Quarantined copy left in quarantine (High Confidence Phish, not released).
## Remaining advice for client
- Do not pay invoice AMU54618 or contact the sender.
- Any real vendor banking/W-9 changes get phone verification on a known-good
number.