Taking a break from your usual ASN and netblock blocklist updates for a moment, here is a review of a interesting phishing email campaign facilitated by cybersecurity vendor Trend Micro and web services behemoth AWS. Upon contacting the AWS abuse team, they have denied all culpability in facilitating this attack, despite relaying the message to hundreds if not thousands of potential victims.
Here’s the full headers and body of the phishing email in question:
Received: by 2002:a59:ab06:0:b0:478:9d64:fab9 with SMTP id m6csp66065vqo;Tue, 11 Jun 2024 16:01:05 -0700 (PDT)X-Forwarded-Encrypted: i=2; AJvYcCWDrAGGtC2m1onb7LFYCjv1BC9XJ+WlrxA2orXQHC8zjGWFBP75UZQtxZA/oJ8WMfFpMnrkLn1vJASrPaL9xi1bag==X-Google-Smtp-Source: AGHT+IHQ3dEhDwhP6x1X9adkT7TkCdY1tLusMpXcKc8aCxMSPU5ckH1+6Cdne2rQPWgimdJUtl/PX-Received: by 2002:a05:6102:58ca:b0:48c:4343:bdd1 with SMTP id ada2fe7eead31-48d91dd7fb8mr438978137.3.1718146865049;Tue, 11 Jun 2024 16:01:05 -0700 (PDT)ARC-Seal: i=1; a=rsa-sha256; t=1718146865; cv=none;d=google.com; s=arc-20160816;b=e+9vHhHnmu2ID1hz6ITpRsTHCoJ9c+AfougdCYoLFnESlvl0hsfmWtthhyD6sKwUwpPt6b0uOxMFNrGAn9CumizRXFIHF6KATD/P3Y5L37N7kMT0A6aDHbCgVeu1K+XHfve6xZZ8kPaIUZyppyyGTSj4gzmaNaNTD2gHQF8Z0aVLg8fz/jCb2sxxDS/RHuQPrflyO7xM55hYumu0FpSUGr3unr2kqkMdaETtD+LSzNlVnKCWqarbfPo+Sqz0igncv397lvtETPsAkeNfpDvKoAEkE/Kv1s7U9JozVHncDNuQOJ6hZc9EmYS4qa7iIHCW86vFanGRoLpxJdqpN+5ffw==ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;h=to:message-id:content-transfer-encoding:mime-version:date:subject:from:reply-to;bh=9gfaAQNWzewfSWarEWPKe2oOmPeo0qhBp+Lp4QXtIYs=;fh=zEMK+f3w3jEJ+rVETDLljm1MjZ16EIk9osNt+OMcE4w=;b=GRTXm0xHsFMd6DmkImo463++WkMeQX9nbYh9vxVKv/zQ8doP57T4pFJHdZAYq9PYoBd0m74mTJds+rDmJficAWS0dapZlaqI+qIPWDevv52wmVDpo5w7IpuFj7qVSnYIcmf2P3t06I0zlh3aOit/IeMyTs+7M+ynrg2mxrV/iqY052FAMCneMK6Ex+U9LWQvSAoxP4df8wwXZoEiFfq8zLz6vLubeSkr9Ksd8y2wGkNQ1LLjtI72JF+CevSNND3UttsrqgrV0m6sao9OEMojj0uwoZ+FZAZl0y7iGaOgsfHsygizLHNLojtQ1cJCWw4EOGhXv/jjbmZ1OEUVmVWfmA==;dara=google.comARC-Authentication-Results: i=1; mx.google.com;spf=pass (google.com: domain of postmaster@repostorp01.tmes.trendmicro.com designates 18.208.22.164 as permitted sender) smtp.helo=repostorp01.tmes.trendmicro.comReturn-Path: <>Received: from repostorp01.tmes.trendmicro.com (repostorp01.tmes.trendmicro.com. [18.208.22.164])by mx.google.com with ESMTPS id ada2fe7eead31-48c1a11cf00si3123299137.205.2024.06.11.16.00.59(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);Tue, 11 Jun 2024 16:01:04 -0700 (PDT)Received-SPF: pass (google.com: domain of postmaster@repostorp01.tmes.trendmicro.com designates 18.208.22.164 as permitted sender) client-ip=18.208.22.164;Authentication-Results: mx.google.com;spf=pass (google.com: domain of postmaster@repostorp01.tmes.trendmicro.com designates 18.208.22.164 as permitted sender) smtp.helo=repostorp01.tmes.trendmicro.comReceived: from 187.73.238.226_.trendmicro.com (unknown [192.168.172.45])by repostorp01.tmes.trendmicro.com (Postfix) with SMTP id 241C31000535C;Tue, 11 Jun 2024 23:00:58 +0000 (UTC)X-TM-MAIL-RECEIVED-TIME: 1718146838.436000X-TM-MAIL-UUID: aefb7c85-f6e4-4352-9684-4cf18a77b496Received: from mail.dmeletrico.com.br (unknown [187.73.238.226])by repre01.tmes.trendmicro.com (Trend Micro Email Security) with ESMTPS id 6AB99100017D4;Tue, 11 Jun 2024 23:00:38 +0000 (UTC)Received: from User (200.243.120.130) by SRVEX01.DMELETRICO.COM.BR(172.16.1.204) with Microsoft SMTP Server id 14.1.438.0; Tue, 11 Jun 202419:57:29 -0300Reply-To: <edwincastro7891@gmail.com>From: LEGACYSubject: RE:DONATIONDate: Tue, 11 Jun 2024 15:57:29 -0700MIME-Version: 1.0Content-Type: text/html; charset=”Windows-1251″Content-Transfer-Encoding: 7bitX-Priority: 3X-MSMail-Priority: NormalX-Mailer: Microsoft Outlook Express 6.00.2600.0000X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000Message-ID: <b92775e3-c2e7-4d64-81d3-bc81935c3f29@SRVEX01.DMELETRICO.COM.BR>To: Undisclosed recipients:;X-Originating-IP: [200.243.120.130]X-TM-AS-Product-Ver: SMEX-11.7.0.1055-9.100.1008-28448.000X-TM-AS-Result: Yes-71.954900-5.000000-31X-TM-AS-User-Approved-Sender: NoX-TM-AS-User-Blocked-Sender: NoX-TM-Deliver-Signature: 1BCA224F8385781ADA83DFF9AE32AA80X-TM-Addin-Auth: tK4fOJQkEqeSww5PPJKPyDA0k85spN7uzJacjE9oIfE5zzCWz3xQdsSP6bfnCQG6uasYN7JVEVGAYVr8M/4fVHtCcASWLcsBOyp5Or2POhfdMKeISfXqLV4dq5llvaXRp9XejHmvypD04xWhjOeX6fP3q7px4yGcEX6J/0+/2HH+QOek6mJPIBABgQt3XxhMva90I8ve/ifWLNxrTMZ60PpcYrDexOAUgF5/A8HOa8huD2tjNTLIsMT+jog/0LemL/u5eNoVS69SqIdM392Chg==.Mfezytm9VCSt01leBHjZg5AwtNeQSREmAoS2GW9cdv9QVDURR6xcqpOdvHH290LV2bqtiB4kKHrBqtooU0UPi08pwjbGLCJkWQhtsC6hPAY2+fzmYtV55whYoSqueI1l5gWO8q3bMFOaB5HjzQnHDnFeSxQ1d0x3Sc/jbEY2oNJfldP7vmP86ZPnDTgYvqAXnE7FG5m3UtbCXjKamzaEUNLBWJr+ufV+bTO/FUZg/+rqM021vFLnOl7MfwCZ0e0mg3SQEPtkzQbvevtmgSiBTl97pP1ze2ZS4JGpEmQckXOePxUC7G/5D0svT3GxDBEkN0u8gAHdW8wt++Ta7jg9gA==X-TM-Addin-ProductCode: EMS<HTML><HEAD><TITLE></TITLE></HEAD><BODY bgcolor=#FFFFFF leftmargin=5 topmargin=5 rightmargin=5 bottommargin=5><FONT size=2 color=#000000 face=”Arial”><DIV>I have made a donation in your name.Note, this is the second time I am contacting you. Contact me on my private email on: edwincastro7891@gmail.com</DIV></FONT></BODY></HTML>
Upon checking the SPF records first, we can see spf=pass (google.com: domain of postmaster@repostorp01.tmes.trendmicro.com designates 18.208.22.164 as permitted sender). This confirms the last hop of the message was 18.208.22.164 – an Amazon Web Services (AWS) IP address originated by their autonomous system AS14618. Note that there are no DMARC or DKIM records in this case.
Analyzing the headers further, we can trace path of the message: 200.243.120.130 (Brazil) –> 187.73.238.226 (Brazil) –> 18.208.22.164 (AWS) –> Victim’s inbox.
This seems incredibly odd that Trend Micro would even allow this message to be processed, let alone for AWS to relay it to the world. From “LEGACY” which is not even close to a valid email address coupled with a completely different reply-to address of “edwincastro7891@gmail.com” is glaring red flag.
Upon contacting the AWS abuse team, they denied any responsibility for facilitating the attack and only offered the following comment, “Our customer runs a cloud hosted email filter service for the their customers. They try their best to detect and block the outbound spam from their service.”
Well I guess that’s it – case closed!


Leave a Reply