PastePile

Incident investigation report

Reference C-0003 · Issued 2026-09-11 03:54:06 UTC

Demo case. The evidence in this case is synthetic and was generated by PastePile for demonstration. It is not real threat intelligence and does not describe any real organization.

What was examined

1 item(s) of evidence containing 2 record(s), covering 2026-08-26 07:41:15 UTC to 2026-08-26 07:41:15 UTC. Anything outside the evidence supplied is out of scope: nothing was collected, fetched or queried from your environment.

What was found

Email authentication failed (DKIM=fail, DMARC=fail, SPF=fail) high

The receiving mail server recorded DKIM=fail, DMARC=fail, SPF=fail for a message from no-reply@exampl3.com. A DMARC failure means the visible From address was not authenticated by the sending domain, which is what domain spoofing produces.

Recommended: Treat the visible sender address as unverified. Confirm the request through a channel you already trust.

Replies would go to a different domain than the sender high

The message is from no-reply@exampl3.com but replies are directed to helpdesk.recovery@mail-secure.example. A reply-to on an unrelated domain is how a conversation is quietly moved to infrastructure the sender controls, and it is a standard component of business email compromise.

Recommended: If this message asks for payment, credentials or a change of bank details, verify by phone using a number you already hold.

Sending domain resembles the recipient's domain high

The message was sent from exampl3.com, which differs from the recipient's own domain example.com by 1 character(s). Registering a near-identical domain is a standard way to make a message appear internal.

Recommended: Check whether your organization owns the sending domain. If not, consider blocking it and searching for other mail from it.

Display name does not match the sending domain medium

The display name claims to be 'IT Support - Example Ltd' but the message was sent from exampl3.com, which is not associated with that name.

Recommended: Check the actual sending address rather than the display name.

Suspicious link to bit.ly medium

The message contains a link where the link uses the shortener bit.ly, so its real destination is not visible in the message. PastePile did not open this link, and has made no assessment of what it serves.

Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.

Suspicious link to 100.88 medium

The message contains a link where the link points at a bare IP address rather than a hostname, and the link contains 'login' and points at 100.88, which is not the sender's domain. PastePile did not open this link, and has made no assessment of what it serves.

Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.

Suspicious link to 100.88 medium

The message contains a link where the link points at a bare IP address rather than a hostname, and the link contains 'login' and points at 100.88, which is not the sender's domain. PastePile did not open this link, and has made no assessment of what it serves.

Recommended: Do not open the link from a normal workstation. If it needs to be examined, submit it to a URL analysis service from an isolated environment.

Attachment of concern: Password_Policy.pdf.htm medium

The message carries an attachment named Password_Policy.pdf.htm, where the filename has a double extension (.pdf.htm), which disguises the real file type. PastePile has not opened, extracted or executed this file, and makes no assessment of whether it is malicious.

Recommended: Do not open the attachment. If its hash is available, check it against your endpoint tooling or a file reputation service.

Machines and accounts involved

no-reply@exampl3.com

What could not be determined

What we recommend

What was checked

6 check(s) ran against the evidence you supplied. 28 could not run, because the evidence they need was not part of what was submitted.

A check that could not run is not a check that found nothing. These were not assessed:

Supplying the evidence named above would let those checks run. Until then this report describes only what the submitted evidence shows.

How this was produced

The recorded outcomes above describe which evidence was processed and which checks ran. Receiving evidence alone does not mean analysis completed. No suspicious URL was visited, no attachment executed and no sample detonated. PastePile states what the supplied evidence supports and names what it does not establish; the decision about what to do remains yours.

Artificial intelligence. No language model was used in producing this case.


Findings are derived from the evidence supplied to this case and no other source.

Produced with PastePile.