Analytics BIOC Informational

Unusual display name in From header

An email was detected with an unusual display name in the From header.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Reconnaissance (TA0043) Initial Access (TA0001)
ATT&CK techniques: Phishing for Information (T1598) Phishing (T1566)
Attacker's goals:

Evade defenses and hide potential malicious data inside the email display name.

Investigative actions:

Analyze the email further to determine the source of the anomaly and what can be done about it.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Unusual display name in the From header containing an embedded URL Low (parent: Informational)
  • Unusual display name in the From header that is identical to the email address Informational