One ordinary-looking email took its recipient through six stages and ended at a fake Microsoft sign-in page built to steal their password. We traced every hop of the chain, from the impersonated sender to the credential-harvesting page, so that both security teams and everyday users can spot this pattern the next time it lands in an inbox. Below, the SecneurX Threat Research team walks through what we found and how SecneurX Email Security with Sandbox is built to stop each step. Modern phishing rarely puts the malicious link in the email itself. Instead, attackers chain several harmless-looking steps together. Each hop on its own looks clean to an email scanner, and only the full journey reveals the trap.
The attack at a glance
- The email: an "RFP proposal" message impersonating a legitimate corporate account, with a PDF attached.
- The attachment: a polished PDF whose only call to action is a button that links to a compromised website.
- The first-level link: a hijacked page on a legitimate business domain, dressed up as a secure file-sharing portal.
- The identity prompt: the portal asks for the victim's work email, then forwards them to the second stage.
- The CAPTCHA gate: a fake "Human Verification" check that keeps security scanners out.
- The final page: a pixel-perfect imitation of the Microsoft sign-in page that harvests the password.
Stage 1: An email from a "trusted" colleague
The attack began with an email that appeared to come from a legitimate corporate account: an IT staff member at an established manufacturing company. The subject line carried a familiar business hook: "RFP PROPOSAL: Review the proposal documents, sign the required September 16th."
- The sender and the "To" address are identical. The real recipients were hidden in BCC, a classic sign of a bulk mailing rather than a personal message.
- The body is almost empty. There is only a sign-off, a name, a department, and a long legal disclaimer. The disclaimer is there to borrow credibility, not to inform.
- The deadline had already passed. The email arrived on 17 September and asked for a signature by 16 September. That manufactured urgency pushes the reader to act before they think.
- Everything hinges on the attachment, a 16.4 KB PDF named India japan IJL._Proposal_Settlement.pdf.
Stage 2: A clean-looking PDF with one dangerous button
The attachment is a one-page document titled "Official Request for Proposal Settlement." It is professionally laid out, with a reference number (P-91005643), an agreement-package summary, a signature block, and a confidentiality notice. It contains no macros and no malware. Its only purpose is to get the reader to click a green "VIEW PROPOSAL INVITATION" button. Hovering over that button reveals the real destination: the first-level compromised link.
This is the attackers' first evasion trick. Many email filters inspect links in the message body far more aggressively than links inside attachments. A PDF with a single outbound link also looks harmless to a static scanner. There is a small but telling inconsistency, too. The contact block lists a Chennai, India street address alongside a +971 mobile number, which is a United Arab Emirates dialling code.
Stage 3: The first-level compromised link
The button leads to the following address. The domain belongs to a legitimate Bulgarian business whose website has been compromised. The attackers planted their own page in a /shared/ folder on it. hxxps[:]//evrokvarts[.]bg/shared/rfp.html
The page presents itself as "CloudVault – Enterprise File Sharing Platform." It shows a file card for Request For Proposal.pdf ("2.4 MB, shared 2h ago") and reassuring badges: "SOC 2 Compliant," "AES-256 Encrypted" and "Your information is protected with bank-level encryption." None of these claims mean anything; they are decoration designed to lower the visitor's guard. Hosting this stage on a hijacked business domain is deliberate. A real company's website usually passes reputation checks, whereas a freshly registered domain would be flagged far more quickly.
Stage 4: "Verify your identity"
Before showing the promised document, CloudVault asks the visitor to "Verify your identity" by entering their work email. Once the victim types in their details and clicks "Continue to Document," the page sends them on to the second stage of the phishing chain, hosted on a different domain. (For this analysis, our researchers entered a dummy test address, test@id2.com.) This step does three jobs for the attacker:
- It confirms a live target. Anyone who enters a work email has proven they are engaged and likely to keep going.
- It personalises the next stage. The email address is carried forward so the fake sign-in page can show it pre-filled, which makes the page feel genuine.
- It filters out scanners. Automated link checkers rarely fill in forms, so they never see what comes next.
Stage 5: A fake CAPTCHA standing guard
The second stage opens with a "Human Verification" pop-up. It carries a OneDrive-style cloud logo and a familiar "I'm not a robot" checkbox. Behind it, a blurred page imitates a Microsoft 365 home screen, hinting that the document is just one click away. hxxps://api-gofiq8bn7[.]thorkildkristensen[.]sbs//#cmFtQGdtYWlsLmNvbQ==
To the victim, a CAPTCHA feels like a sign of a careful, legitimate service. In reality, it protects the attacker. Basic URL scanners that cannot pass the check see only a harmless verification box, never the credential-harvesting page behind it. Reaching that page is the job of an advanced sandbox. Once the checkbox is ticked, the victim is taken to the final stage.
Stage 6: The fake Microsoft sign-in page
The chain ends at an imitation of the Microsoft sign-in page, hosted at: hxxps[:]//thorkildkristensen[.]sbs/common?key=gofiq8bn7#dGVzdEBpZDIuY29t
The page shows the Microsoft logo, a "Sign in" heading and the message "You've been invited to view or edit a secure document. Please verify your account to access it." Anything typed into it goes straight to the attacker. The URL itself gives the game away to anyone who looks closely:
- The domain has nothing to do with Microsoft. It is a personal-name domain on the low-cost .sbs top-level domain. Genuine Microsoft sign-ins happen on login.microsoftonline.com or login.live.com.
- The path is copied from Microsoft. The /common segment mirrors real Microsoft sign-in URLs, so the fake address looks familiar at a glance.
- The fragment is the victim's email address, Base64-encoded. The text after #, dGVzdEBpZDIuY29t, decodes to test@id2.com, the test address we entered at Stage 4. The page reads it to pre-fill the login and make the impersonation more convincing.
- The styling is slightly off. The message under "Sign in" uses a serif font that Microsoft's real page never uses.
Indicators of compromise
How SecneurX Email Security with Sandbox stops this attack
Each evasion trick in this campaign targets a known gap in conventional email filtering. SecneurX Email Security with Sandbox is designed to close those gaps by examining what an email does, not only what it looks like.
- Links inside attachments are inspected. URLs embedded in PDFs and other attachments are extracted and analysed with the same scrutiny as links in the message body.
- Pages are judged by behaviour, not reputation. A hijacked page on a well-established domain does not get a free pass. It is opened in an isolated environment and its content and behaviour are analysed.
- The whole chain is followed. Dynamic analysis follows the redirects across domains, past identity prompts and verification gates, to reach the final page.
- Brand impersonation is detected. A Microsoft 365 sign-in page on an unrelated domain is flagged as credential phishing.
- Social-engineering signals are scored. The AI/ML phishing engine weighs signals such as a hidden recipient list, an almost empty body and a deadline that has already passed.
- Attachments are rebuilt safely. Content Disarm & Reconstruction (CDR) delivers attachments with active content removed.
The result: the message is quarantined before it reaches the inbox, and the security team gets a full report of every stage in the chain.
Lessons for defenders and users
This campaign works because no single step looks malicious: a familiar sender, a clean PDF, a real business's website and a CAPTCHA all pass quick inspection. Only following the full chain reveals the credential theft at the end.
- Hover before you click, including links inside PDFs and other attachments.
- Check the address bar on every sign-in page. Microsoft will never ask you to sign in on a domain like .sbs.
- Treat "verify your identity to view a document" as a red flag, especially when the document arrived unexpectedly.
- Be wary of deadlines that have already passed. Urgency is the attacker's favourite tool.
- Enable multi-factor authentication so that a stolen password alone is not enough to take over an account.
- Report suspicious emails to your security team, even when they appear to come from a known contact.
See what your email gateway is missing
Most of the stages in this attack are built to look clean to conventional filters. If you want to know how your current setup would handle a campaign like this one, the SecneurX team can show you. Book a demo of SecneurX Email Security with Sandbox, or send us a suspicious email you have received and we will analyse it for you.
About SecneurX
SecneurX is a pure-play cybersecurity company that builds advanced threat protection for government and enterprise organisations. It combines antivirus, anti-spam, Content Disarm & Reconstruction (CDR), AI/ML-powered phishing detection and dynamic sandboxing, and deploys on-premises, virtualized or in hybrid DC/DR configurations.