EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Apple App Store malicious ad manager themed apps from free email provider

Detects messages containing Apple App Store links with sent from free email providers, indicating potential abuse of legitimate Apple services hosting malicious ad manager themed applications.

T1566T1566.001T1566.002T1598T1534+5
Sublimemedium

Link: Apple TestFlight from suspicious sender

Detects messages containing Apple TestFlight links from free email providers or suspicious senders with no prior benign communication history.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Base64 encoded recipient address in URL fragment with hex subdomain

Detects links containing a 40-character hexadecimal subdomain with the recipient's email address base64 encoded in the URL fragment, a technique used to personalize malicious links and evade detection.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Base64 encoded recipient address in URL fragment with subject hash

Detects messages containing an alphanumeric string that is between 32 and 64 characters in the subject line that corresponds to a URL fragment containing the recipient's email address encoded in base64. This technique is commonly used to personalize malicious links and evade detection by embedding the target's email address within the URL structure.

T1566T1566.001T1566.002T1598T1027+2
Sublimelow

Link: BEC with newly registered domains and financial keywords

Detects Business Email Compromise attacks containing links to newly registered domains (less than 60 days old) with invoice-related language and engaging action words. The message includes financial or payment terminology and prompts the recipient to take action through suspicious links. Uses natural language processing to identify credential theft or BEC intent while filtering out benign communications.

T1566.002T1534T1656T1566T1598+2
Sublimemedium

Link: Blogspot hosting explicit romance content

Detects inbound messages containing links to Blogspot domains that host explicit romance content, identified through natural language processing of the message body.

T1566T1598
Sublimemedium

Link: Breely link masquerading as PDF

Detects messages containing a single Breely link that displays as a PDF file. Typically, redirects to a different destination for malicious purposes.

T1566.002T1534T1656T1566T1566.001+1
Sublimehigh

Link: chatbot.page platform abuse

Detects abuse of chatbot.page where configurations suggest malicious intent, including incomplete contact information, free-tier usage, and suspicious question content.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Common hidden directory observed

Links in the message point to sensitive system directories like .git, .env, or .well-known that could expose confidential configuration data or system files. Actors will often abuse these directories to hide credential phishing landing pages of compromised sites.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Commonly Abused Web Service redirecting to ZIP file

Detects messages containing links from URL shorteners, free file hosts, or suspicious domains that redirect to ZIP file downloads, potentially indicating malware distribution.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Link: Compromised WordPress site redirecting to suspicious root domain

Inbound messages contain links routing through compromised WordPress installations (matching paths such as /wp-admin, /wp-includes, or /wp-content) that ultimately redirect to the root of an unrelated domain with no query parameters. The lure theme across observed samples centers on urgency around agreement review, document signing, and fund/profit notifications — designed to pressure recipients into clicking. The redirect pattern, combined with WordPress path indicators, suggests adversaries are abusing vulnerable WordPress sites as an intermediary hop to obscure the true destination.

T1566T1566.001T1566.002T1598T1534+3
Sublimehigh

Link: Concatenated display text concealing duplicate URLs with PDF reference

Detects messages where two identical links are displayed as a single continuous text string, with the second link containing 'PDF' in its display text. This technique can be used to obscure the true nature of links by making them appear as legitimate document references.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Credential harvesting with excess padding evasion

Detects inbound messages containing credential-related action links with tall screenshot images and HTML padding techniques used to evade detection. The rule identifies messages with excessive empty div tags, non-breaking spaces, or large margin-top values that artificially increase content height while hiding malicious intent.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Link: Credential phishing link with undisclosed recipients

This rule detects messages with "Undisclosed Recipients" that contain a link to a credential phishing page.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Credential phishing traversing Russian infrastructure

This rule detects credential phishing attempts in emails traversing Russian TLDs by aggressively analyzing links for signs of phishing, including suspicious keywords, login prompts, or links flagged for credential theft, excluding emails from trusted domains unless they fail DMARC verification.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: Credential phishing via WordPress

Detects when non-WordPress senders link to suspended or malicious WordPress blog sites, commonly used to redirect users to credential harvesting pages.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: Credential phishing with obfuscated JavaScript redirect

Flags inbound messages where the current thread contains between 1 and 9 links and NLU classification identifies credential theft intent with at least medium confidence. Additionally requires that aggressive link analysis reveal a redirect chain containing a query parameter with an obfuscated JavaScript payload that uses an onerror handler combined with atob and decodeURIComponent to dynamically redirect the browser, a technique commonly used to evade static URL scanning while ultimately routing victims to a credential harvesting page.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Link: Credential theft with Cloudflare tunnel and recipient targeting

Detects messages containing credential theft language and links to trycloudflare.com tunnels that include the recipient's email address in the URL path, indicating personalized targeting for credential harvesting.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Credential theft with invisible Unicode character in page title from unsolicited sender

Detects messages containing credential theft language and links to pages with invisible Unicode characters in the title tag, a technique commonly used to evade detection in fraudulent pages.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Cryptocurrency fraud with suspicious links

Detects messages containing financial communications about cryptocurrency or bitcoin with links to suspicious domains, URL shorteners, newly registered domains, or domains with known cryptocurrency fraud indicators. The rule analyzes link behavior including redirects, specific abuse patterns, and JavaScript configurations commonly used in cryptocurrency scams. Excludes legitimate cryptocurrency platforms with proper authentication.

T1566.002T1534T1656T1566T1598+3
Sublimehigh

Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability

This rule detects messages containing links exploiting CVE-2024-21413, which can lead to RCE. Successful exploitation can bypass built-in Outlook protections for malicious links embedded in messages by using the file:// protocol and an exclamation mark to URLs pointing to attacker-controlled servers."

T1566.001T1204.002T1486T1036T1027+2
Sublimecritical

Link: Delimited encoded path parameters (~V~ scheme)

This rule flags inbound messages containing a link with a repeating encoded pattern in the URL path, a technique used to obfuscate the true destination and evade static URL matching. The captured samples span a range of unrelated senders and lures - fake system/data access suspension notices, payment authorization failures, case submission confirmations, and backup storage reminders - all designed to create urgency and drive recipients to click through disguised links. The variety of spoofed sending domains and generic account/security themes suggests a shared link-obfuscation infrastructure being reused across many opportunistic lures rather than a single brand or campaign.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Direct download of executable file

Detects messages containing links that directly download executable (.exe) files, with a limited number of distinct links that are either unrelated to the sender's domain or not in the top 10k most popular websites.

T1566.001T1204.002T1486T1036T1027
Sublimelow

Link: Direct link to Dropbox Paper file

Detects inbound messages containing links to Dropbox Paper documents using the /scl/fi/ sharing path with a .paper file extension and an rlkey query parameter. This pattern is commonly abused to host phishing content or malicious redirects behind Dropbox's trusted domain, allowing messages to bypass reputation-based filtering while luring recipients into opening a shared document.

T1566T1566.001T1566.002T1598
Sublimelow
PreviousPage 29 of 53Next