// BTLO  ·  writeup

Bec-Ky

BTLO Azure AD Sign-in LogsExchange Audit LogsEmail Header Analysis

Overview

Business Email Compromise investigation on BTLO — a CFO mailbox was used to authorise fraudulent pension-fund transfers. The investigation traces the phishing source, the attacker sign-ins, the destination bank, and the inbox rules used to hide the evidence.

Investigation Overview

StepObjectiveKey FindingsEvidence
1 – Identify the initial phishing sourceLocate the malicious email that started the compromise.Suspicious sender: sabastian@flanaganspensions.co.uk – look-alike phishing domain.Email headers & message details
2 – Determine the type of compromiseClassify the attack vector.Business Email Compromise (BEC) – attacker used valid credentials to send fraudulent transfers.No malware observed; activity originated from CFO mailbox
3 – Trace attacker IPsIdentify unauthorized sign-in sources.159.203.17.81 and 95.181.232.30 – anomalous geo-locations aligned with transaction timing.Azure AD sign-in logs filtered for victim (Becky)
4 – Identify the destination bankDetermine where funds were transferred.First Bank of Nigeria Ltd. (SWIFT: FBNINGLA)SWIFT code found in compromised email threads
5 – Detect inbox folder creationCheck for persistence or activity hiding mechanisms.Folder named “History” created via inbox rule.Azure audit log showing "MoveToFolder" event
6 – Analyse malicious rule keywordUnderstand filtering behavior.Rule deleted emails containing “Withdrawal”Rule log: SubjectOrBodyContainsWords="Withdrawal"; DeleteMessage=True

🔍 Attack Narrative

  1. A phishing email from a spoofed domain tricks Becky into interacting.
  2. The attacker compromises the CFO mailbox and initiates legitimate-looking bank transfers (classic BEC behavior).
  3. Azure sign-in logs reveal two suspicious IP addresses:
    • 159.203.17.81
    • 95.181.232.30
  4. Transaction emails include SWIFT code FBNINGLA, linked to First Bank of Nigeria Ltd.
  5. The attacker creates a hidden folder called “History” using an inbox rule.
  6. A malicious rule automatically deletes emails containing “Withdrawal”, removing evidence of fraudulent activity.

🛡 Key Defensive Takeaways


🎯 MITRE ATT&CK Mapping