PastePile
Demo case. The evidence in this case is synthetic and was generated by PastePile for demonstration. It is not real threat intelligence and does not describe any real organization.
1 item(s) of evidence containing 2 record(s), covering 2026-08-26 07:41:15 UTC to 2026-08-26 07:41:15 UTC. Anything outside the evidence supplied is out of scope: nothing was collected, fetched or queried from your environment.
The receiving mail server recorded DKIM=fail, DMARC=fail, SPF=fail for a message from no-reply@exampl3.com. A DMARC failure means the visible From address was not authenticated by the sending domain, which is what domain spoofing produces.
Recommended: Treat the visible sender address as unverified. Confirm the request through a channel you already trust.
The message is from no-reply@exampl3.com but replies are directed to helpdesk.recovery@mail-secure.example. A reply-to on an unrelated domain is how a conversation is quietly moved to infrastructure the sender controls, and it is a standard component of business email compromise.
Recommended: If this message asks for payment, credentials or a change of bank details, verify by phone using a number you already hold.
The message was sent from exampl3.com, which differs from the recipient's own domain example.com by 1 character(s). Registering a near-identical domain is a standard way to make a message appear internal.
Recommended: Check whether your organization owns the sending domain. If not, consider blocking it and searching for other mail from it.
The display name claims to be 'IT Support - Example Ltd' but the message was sent from exampl3.com, which is not associated with that name.
Recommended: Check the actual sending address rather than the display name.
The message contains a link where the link uses the shortener bit.ly, so its real destination is not visible in the message. PastePile did not open this link, and has made no assessment of what it serves.
Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.
The message contains a link where the link points at a bare IP address rather than a hostname, and the link contains 'login' and points at 100.88, which is not the sender's domain. PastePile did not open this link, and has made no assessment of what it serves.
Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.
The message contains a link where the link points at a bare IP address rather than a hostname, and the link contains 'login' and points at 100.88, which is not the sender's domain. PastePile did not open this link, and has made no assessment of what it serves.
Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.
The message carries an attachment named Password_Policy.pdf.htm, where the filename has a double extension (.pdf.htm), which disguises the real file type. PastePile has not opened, extracted or executed this file, and makes no assessment of whether it is malicious.
Recommended: Do not open the attachment. If its hash is available, check it against your endpoint tooling or a file reputation service.
no-reply@exampl3.com
6 check(s) ran against the evidence you supplied. 28 could not run, because the evidence they need was not part of what was submitted.
A check that could not run is not a check that found nothing. These were not assessed:
Supplying the evidence named above would let those checks run. Until then this report describes only what the submitted evidence shows.
The recorded outcomes above describe which evidence was processed and which checks ran. Receiving evidence alone does not mean analysis completed. No suspicious URL was visited, no attachment executed and no sample detonated. PastePile states what the supplied evidence supports and names what it does not establish; the decision about what to do remains yours.
Artificial intelligence. No language model was used in producing this case.
Findings are derived from the evidence supplied to this case and no other source.
Produced with PastePile.