Table of Contents
The email was not a convincing forgery. It was not a forgery at all.
It arrived from no-reply@dochub[.]com, the genuine notification address of a document-sharing and e-signature platform that has been operating for well over two decades. SPF passed. DKIM passed twice, once for the platform's own domain and once for the Amazon SES infrastructure that carried the message. DMARC passed. Microsoft's composite authentication returned a perfect score of 100. Both links in the body pointed at the platform's own domain, arrived wrapped in Safe Links, and came back rated Clean.
There was nothing in the sending infrastructure to block, because the infrastructure was not the attacker's.
Two fields in that message belonged to the attacker. The display name announced QuickBooks ProAdvisor Support via DocHub. The Reply-To pointed at a personal webmail account. That was the entire attack.
A Genuine Platform, Borrowed for an Afternoon
A document share request carries fields the submitter fills in: who the document appears to be from, and where replies should go. The platform then does exactly what it promises, generating a branded notification and sending it from its own authenticated infrastructure.
The attacker uploaded a document, typed a borrowed vendor identity into the sender field, aimed the Reply-To at a webmail mailbox, and let the platform handle delivery. The subject read Account Status Alert: Verification Pending. The recipient was a sales manager at a small to mid-size company, one mailbox, no wider blast.
The mismatch is the whole tell, and it is visible without a single technical control. Intuit does not send QuickBooks ProAdvisor notices through an unrelated document platform, and the platform's own footer said as much, attributing the submission to an IP address, 20[.]168[.]12[.]145, with no relationship to the brand being invoked.
Every Authentication Check Passed, and That Was the Point
The header trail is boringly clean. SPF passed with 54[.]240[.]123[.]85 listed as a permitted sender for the platform's mail domain. DKIM produced two valid signatures, d=dochub[.]com and d=amazonses[.]com. DMARC passed with the header From aligned to the signing domain. Composite authentication reported compauth=pass reason=100, and Outlook assigned a spam confidence level of 1. The relay path ran from an Amazon SES egress host into Exchange Online frontend hops and on to the mailbox, with no gateway anomalies and no broken alignment.
That is not a misconfiguration to fix. It is authentication working correctly. As RFC 7489 defines it, DMARC answers one question: is the domain in the visible From address aligned with a domain that authorized this message? The platform authorized it, so the answer was yes. No standard asks what the submitter typed into the form, because no standard can.
The 2024 Verizon Data Breach Investigations Report found phishing present in 15 percent of breaches and the human element a component of 68 percent, with pretexting the leading social-engineering type. The technical layer here had no objection to raise.
The Links Were Real, Too
There were two links, and they were duplicates: the same document, once as a direct view path and once through the platform's shared-document route. Both resolved to the platform's own viewer, and both scanned Clean. No credential form was observed anywhere in the flow, and no attacker-controlled host appeared at any hop. This was not a redirect chain, and calling it one would misread the case.
The document carried a machine-generated filename of the kind the platform mints automatically, which tells a URL reputation engine nothing. The links were not the harvest. Their job was to establish that the message was real, which it was.
The Payload Was a Reply-To and a Phone Number
Everything hostile in this message lived in the two channels that lead off the platform.
The Reply-To resolved to m.ari.o.s.g.lad.e@googlemail[.]com, presented under the borrowed support identity. The scattered dots are a familiar operator trick: major webmail providers ignore dots when routing, so one inbox can be addressed by dozens of visually distinct strings. Alongside it, the body carried a toll-free number, +1 800-839-9360, as an alternate way to reach support.
Both routes end in a conversation no email control can inspect. Reply, and the thread continues in a mailbox outside the tenant. Call, and the pretext moves to vishing, where a live operator walks the target through whatever verification they need. The 2023 FBI Internet Crime Report put reported business email compromise losses near $2.9 billion, and most of that damage happens in follow-on conversations rather than in the first message.
See Your Risk: Calculate how many threats your SEG is missing
Scoring Intent When the Infrastructure Says Nothing
Themis scored the incident at 54 percent, and that modest number is the honest one. There was no hostile domain to weigh, no failed authentication, no malicious payload. What remained was context: a first-time sender to this mailbox, a display name asserting a brand that did not match the sending domain, a Reply-To on free webmail attached to a transactional template, and a phone number offered as an alternate channel. The incident was tagged for both suspicious sender and suspicious message behavior, and the mailbox was quarantined in the same minute the mail landed.
The other half of the verdict came from people. The report originated from the IRONSCALES community, and federated reputation matched the pattern against resolutions of similar incidents elsewhere. That is what a network of 35,000+ security professionals across 17,000+ organizations buys when the wire evidence is empty. Pairing Adaptive AI scoring with a fast human reporting loop is not redundancy here. It is the only detection surface left.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Sender | no-reply@dochub[.]com | Genuine platform notification address, fully authenticated |
| Display Name | QuickBooks ProAdvisor Support via DocHub | Attacker-supplied field, borrowed vendor brand |
| Subject | Account Status Alert: Verification Pending | Generic account-verification pretext |
m.ari.o.s.g.lad.e@googlemail[.]com | Attacker Reply-To, dot-scattered webmail alias | |
| Phone | +1 800-839-9360 | In-body call-in number, off-platform channel |
| IP | 20[.]168[.]12[.]145 | Submitter IP in the platform footer, not the delivery path |
| URL | hxxps://dochub[.]com/m-ari-o-s-g-lad-e/eOLPG9YKjYxAv87RZpXz6y/document-[redacted]-pdf?t=xMRaqFgCLVZT-WyEG8PJ | Primary document-view link, verdict Clean |
| URL | hxxps://dochub[.]com/m/shared-document/m-ari-o-s-g-lad-e/eOLPG9YKjYxAv87RZpXz6y/document-[redacted]-pdf?t=xMRaqFgCLVZT-WyEG8PJ | Duplicate route to the same file, same verdict |
| Sending IP | 54[.]240[.]123[.]85 | Amazon SES egress, SPF-authorized |
MITRE ATT&CK Mapping
- T1566.002 Phishing: Spearphishing Link: the message delivered platform-hosted document links as its visible lure.
- T1566.004 Phishing: Spearphishing Voice: the in-body toll-free number invited the target to continue the pretext by phone.
- T1656 Impersonation: a borrowed accounting-software support identity was overlaid on a genuine platform notification.
What This Case Should Change
Infrastructure-based defense had no purchase on this message, and no amount of tuning would have given it any. The CISA phishing guidance and the NIST definition of phishing both frame the threat around deception of the recipient rather than properties of the transport. This case is the clean expression of that distinction.
Three moves follow. Score brand-to-domain mismatch as a first-class signal, because a display name claiming one vendor while the envelope belongs to another is an assertion the infrastructure cannot support. Treat a free-webmail Reply-To on transactional platform mail as high-signal by default, and flag in-body phone numbers on any message that also claims an account problem. And invest in the reporting path, because some messages will only ever be caught by behavior and by people. The 2024 Microsoft Digital Defense Report shows attackers migrating toward exactly this kind of low-signal delivery through trusted services, and the IBM Cost of a Data Breach Report for the same year put the global average breach cost at $4.88 million.
When the platform is real, the authentication is real, and the links are real, the only thing left to inspect is the intent of whoever filled in the form.
Related attacks
| Attack | What happened |
|---|---|
| AT&T Brand, Third-Party Infrastructure, and a $25 Visa Card That Goes Nowhere Good | An email claiming to be from AT&T Business arrived from a third-party campaign platform that passed SPF, DKIM, and DMARC for its own domain, not AT&T's. |
| Three Brand Names, One Payment Email, and a PDF That Lied About What It Was | A payment notification email carried three different brand identities: Ottimate in the visible sender name, Qubiqle Inc. |
| The SendGrid Email That Came From a Window Company | A pixel-perfect SendGrid notification arrived from a compromised window manufacturer's domain. |
| Every Link Said U.S. Bank. Every Link Went Through Brevo. | A U.S. |
| The Procore Footer Was Real. The Document Was Not. | Every link scanner called the Procore and ExxonMobil URLs clean. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.