EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Fraudulent state business filing notice

Detects inbound messages impersonating official state business compliance communications, such as Statements of Information or Certificates of Good Standing, that contain links to free subdomain hosting services. These messages use urgent language around filing deadlines or business suspensions to pressure recipients into clicking credential-harvesting links.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Free file host from freemail sender with NLU intent

Detects free file host links sent by freemail senders with a short body and NLU indicators.

T1566T1566.001T1566.002T1598
Sublimelow

Link: Free file host link with 'Important Viewing Note' lure

Detects inbound messages containing links to free file hosting domains paired with the phrase 'important viewing note' in the message body. These messages often masquerade as institutional or educational communications — such as student conduct reports or advancement initiatives — to add legitimacy and encourage recipients to follow the hosted link.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Free file host links from suspicious support sender with credential theft language

Detects inbound messages from senders using the local part 'support' that contain a small number of links pointing exclusively to free file hosting services. The message contains NLU signals indicate credential theft intent related to file sharing or cloud services.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Free file hosting with undisclosed recipients

Detects messages containing links to free file hosting or subdomain services that are sent to undisclosed recipients or only CC/BCC recipients. The rule identifies suspicious distribution patterns where legitimate recipients are hidden, potentially indicating mass distribution of malicious content through file sharing platforms.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Free subdomain host with undisclosed recipients

Detects messages with undisclosed recipients, containing links to free subdomain hosts

Sublimemedium

Link: Generic financial document with proceedural timeline template

Detects messages with generic greetings that reference payment releases & timelines, and exhibit unusual recipient patterns such as self-sending or missing recipients.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender

Attackers invite users to view a Google Calendar whose name contains a suspicious link, generally linking to spam content such as crypto giveaways, using open redirects to mask the true destination.

T1566T1598
Sublimehigh

Link: Google Cloud Storage hosted credential harvesting page

Detects inbound messages containing links to Google Cloud Storage (storage.googleapis.com) that follow a pattern of randomized bucket paths ending in a hashed directory and an index.html file. These links have been observed in messages impersonating professional networking and HR platform notifications, such as those mimicking recruiting outreach or job opportunity alerts from services like Sloneek and BambooHR, luring recipients to hosted credential harvesting pages.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Link: Google Cloud Storage impersonating with googledrive in URL path

Detects inbound messages containing links to Google Cloud Storage (storage.googleapis.com) with paths ending in 'googledrive.html', indicating abuse of Google's cloud storage service to impersonate Google Drive and potentially deliver malicious content.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Link: Google Cloud Storage link with index.php in URL

Detects inbound messages containing links hosted on storage.googleapis.com that point to an index.php path, either in the URL path or fragment. Attackers abuse Google Cloud Storage to host malicious content, leveraging the trusted domain to bypass security filters.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Google Cloud Storage link with redirect.html in URL

Detects inbound messages containing links that route through a redirect.html page hosted on Google Cloud Storage (storage.googleapis.com). Attackers abuse legitimate cloud storage infrastructure to host redirect pages that forward victims to malicious destinations, evading URL reputation checks.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Google Cloud Storage redirect to external domain

Messages contain links hosted on storage.googleapis.com that, when followed, redirect to a destination outside of googleapis.com. This technique abuses Google Cloud Storage's trusted reputation to bypass link reputation checks, with the actual payload hosted on an unrelated external domain. Observed lures include parcel delivery notifications impersonating shipping carriers (UPS, GLS), gambling bonus offers, health product promotions, and storage quota warnings.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

Link: Google Cloud Storage with short-path link delivery

Detects inbound messages containing links to Google Cloud Storage (storage.googleapis.com) where the URL path ends in 'ls' or 'lis', matching a pattern used to host redirector or landing pages. Observed across multilingual spam and unsolicited promotional messages — including fake parcel delivery notifications impersonating FedEx and T&T, as well as product advertisement lures — sent from a variety of compromised or unrelated sender domains. The consistent use of this specific GCS path pattern suggests a shared delivery infrastructure across multiple senders.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Link: Google Cloud Storage with suspicious URL pattern

Detects inbound messages containing links to Google Cloud Storage (storage.googleapis.com) with suspicious URL path patterns that follow a specific actor-controlled structure commonly used for hosting malicious content.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Google Drawings link from new sender

Detects messages containing Google Drawings links from previously unseen senders, which may indicate abuse of Google's drawing service for malicious content delivery.

T1566T1566.001T1566.002T1598T1534+1
Sublimemedium

Link: Google Firebase dynamic link that redirects to new domain (<7 days old)

An attacker may use Google's Firebase Dynamic Links to redirect a user to a malicious site. This rule identifies Firebase Dynamic Links where the destination domain is less than a week old.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimelow

Link: Google Forms link with credential theft language

Detects messages containing Google Forms links paired with credential theft language from new senders. This technique abuses Google's trusted domain to host malicious forms designed to steal user credentials.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Google Translate (unsolicited)

Attackers have used the Google Translate service to deliver links to malicious sites repackaged with a translate.goog top-level domain. This rule identifies instances of Google Translate links from unsolicited senders.

T1566T1566.001T1566.002T1598
Sublimelow

Link: GoPhish query param values

Detects links containing a 7-character alphanumeric 'rid' (default) query parameter, or any other variant identified, commonly used in tracking and targeting systems for malicious purposes.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimelow

Link: Hotel booking spoofed display URL

Detects messages containing links with hotel-related display URLs that either redirect to different domains or contain suspicious parameters commonly used in booking scams and fraudulent hotel reservation schemes.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Link: HR impersonation with suspicious domain indicators and credential theft

Detects messages impersonating HR departments containing many links with malformed domains, suspicious TLD patterns, and credential theft language detected through URL analysis.

T1566T1566.001T1566.002T1598T1534+1
Sublimehigh

Link: HTML file with suspicious binary fragment ending pattern

Detects links to HTML files containing fragments with a suspicious pattern of alphanumeric characters followed by a 5-digit binary sequence, commonly used in malicious URL structures.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Intuit link abuse with file share context

Detects messages linking to Intuit notification domains from non-Intuit senders, combined with credential harvesting language and file sharing themes

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium
PreviousPage 31 of 53Next