Approve: Biscuits and Bath request
This message is suspicious due to strong sender-authentication failures (SPF fail, DMARC fail, no DKIM), an approval/request lure, and reliance on an attached spreadsheet while claiming to be from Biscuits & Bath. Deep analysis of the XLSX did not reveal extracted URLs, QR codes, or obvious malware indicators, but the attachment contains embedded image/drawing content and could not be fully content-expanded by automation. The visible links in the email appear to be benign social/media or Mimecast-wrapped brand links, so the primary risk is the impersonated sender plus attachment-based social engineering rather than a clearly malicious URL.
URL Signals
6 analyzed
https://url.de.m.mimecastprotect.com/s/8GPICDqGZlCj8rBZ8...?domain=biscuitsandbath.com/
https://url.de.m.mimecastprotect.com/s/8GPICDqGZlCj8rBZ8...?domain=biscuitsandbath.com/
https://url.de.m.mimecastprotect.com/s/bDlvCEqJXmC1ZoWjZCpi0S7T1ea?domain=facebook.com
https://url.de.m.mimecastprotect.com/s/bDlvCEqJXmC1ZoWjZCpi0S7T1ea?domain=facebook.com
https://url.de.m.mimecastprotect.com/s/s8RMCGRLXoFWzZJ9zfQsYSBSyl-?domain=twitter.com
https://url.de.m.mimecastprotect.com/s/s8RMCGRLXoFWzZJ9zfQsYSBSyl-?domain=twitter.com
https://url.de.m.mimecastprotect.com/s/XOMjCJ8OKrTpjL8ojHvtxSyYnC2?domain=instagram.com/
https://url.de.m.mimecastprotect.com/s/XOMjCJ8OKrTpjL8ojHvtxSyYnC2?domain=instagram.com/
http://www.facebook.com/biscuitsandbath
http://www.facebook.com/biscuitsandbath
https://twitter.com/BiscuitsandBath
https://twitter.com/BiscuitsandBath
Documents
1 processed
0 URLs · 0 QR · 1 risk flags · 1 artifacts
Authentication
Envelope
Fernando Brea <fbrea@biscuitsandbath.com>
n/a
1