Forum Discussion
JeremyTBradshaw
Sep 05, 2025Iron Contributor
Undected phish from senders with LONG addresses
I posted about this earlier, but something seems to have deleted my post.
A certain kind of phish is currently coming in hot. Senders who have very long addresses, from my obervation > 300 characters are being overlooked and lots of dangerous phish is making its way into EXO mailboxes.
Do this in Advanced Hunting to see if you are victim and please report the messages as phish so the "system" can learn about it.
EmailEvents
| extend sndrAddrLen = strlen(SenderFromAddress) | where sndrAddrLen >= 200 and (LatestDeliveryLocation in~ (@'Inbox/folder'))
| project-reorder sndrAddrLen, Subject, SenderFromAddress, LatestDeliveryLocation, DeliveryLocation, RecipientEmailAddress
No RepliesBe the first to reply