For the complete documentation index, see llms.txt. This page is also available as Markdown.

Email sent using an automated system or script detected

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Microsoft 365 Emails

Detection Modules

Email

Detector Tags

Phishing

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Phishing (T1566)

Severity

Informational

Description

The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications.

Attacker's Goals

Automate the process of email sending, increasing the chances of an email to pass spam filtration.

Investigative actions

  • Examine the sender's IP address and reputation.

  • Verify whether the sender's IP address has appeared in different log sources before, and if it is recognizable.

  • If the message contains attachments or links, scrutinize them for any suspicious indications.

  • Monitor further actions taken, such as file downloads or access to potentially malicious links.

Variations

Unusual automated email or script usage detected from a known sender

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Phishing (T1566)

Severity

Informational

Description

The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. This sender doesn't typically send emails using scripts.

Attacker's Goals

Automate the process of email sending, increasing the chances of an email to pass spam filtration.

Investigative actions

  • Examine the sender's IP address and reputation.

  • Verify whether the sender's IP address has appeared in different log sources before, and if it is recognizable.

  • If the message contains attachments or links, scrutinize them for any suspicious indications.

  • Monitor further actions taken, such as file downloads or access to potentially malicious links.

Was this helpful?