EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Multistage landing - JotForm abuse

Detects a disabled JotForm that contains suspicious elements like secured document messaging, cloned forms, or suspicious action words in form items. Also checks for human verification pages and embedded links to credential collection sites.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Multistage landing - Ludus presentation

Detects when a standalone Ludus document link contains embedded links that are suspicious, particularly those targeting Microsoft services through various evasion techniques. The rule analyzes both the presentation content and linked destinations for suspicious patterns and redirects.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Link: Multistage landing - Microsoft Forms abuse

The detection rule matches on message groups which make use of Microsoft Forms as a landing page. The landing page contains links which are newly registered, use free file or subdomain hosts, URL shorteners or when visited are phishing pages, lead to a captcha or redirect to a top website.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Link: Multistage landing - Published Google Doc

A Google Docs document contains suspicious text and links that redirect to either newly registered domains, free subdomain hosts, URL shorteners, or domains with suspicious TLDs.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: Multistage landing - Scribd document

Detects when a Scribd document contains embedded links that are suspicious, particularly those targeting Microsoft services through various evasion techniques. The rule analyzes both the document content and linked destinations for suspicious patterns and redirects.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Link: Multistage landing - Trello board abuse

Detects suspicious Trello board links containing malicious indicators such as credential theft content, blocked users, malicious attachments, or boards with minimal content from unsolicited senders.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: MyActiveCampaign Link Abuse

Detects messages from myactivecampaign.com containing links and suspicious language that do not exclusively point to activehosted.com domains.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Non-standard port 8443 in display URL

Detects links containing port 8443 in the display URL, which may indicate suspicious redirect or hosting infrastructure.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Numeric IP obfuscation in URL

Detects inbound messages containing links where the host is a numeric-only IP representation, commonly used to bypass domain-based URL filtering.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Obfuscation via userinfo with excessive URL padding

Identifies instances where a malicious actor leverages an excessively padded username within the userinfo portion of the URL to hide the true destination in preview windows.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Link: Obfuscation via userinfo with suspicious indicators

Detects URLs that use the @ symbol to hide suspicious domains or URL shorteners within the link structure, excluding legitimate email addresses and malformed mailto/telto links.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimelow

Link: Observed malicious URL path /redirect/redirect/

Inbound messages containing links whose path includes a repeated '/redirect/redirect/' segment. Observed lures include fake academic transcript notices, internal administrative notices, and generic invitations sent from a mix of compromised or unrelated legitimate domains, all leveraging the nested redirect to bypass link-scanning defenses and lead recipients to malicious landing pages.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Observed URL pattern with specific domain registrar

Detects messages using Element Email service infrastructure, identified by characteristic URL patterns with /f/ paths, unsubscribe links, single domain usage, and Cloudflare domain registration. This pattern indicates potential abuse of legitimate email marketing services.

T1566
Sublimehigh

Link: PDF and financial display text to free file host

Detects messages containing a single link with PDF-named display text containing financial phrases that redirects to a free file hosting service, sent without previous message threads.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: PDF display text with fake copyright claim template

Detects messages containing fake copyright claims with table rows with 25px height images and links where the display text references PDF content, potentially indicating malicious PDF delivery attempts through deceptive formatting.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: PDF file disguised as HTML page

Detects inbound messages containing links that appear to reference PDF files but are actually HTML pages, indicated by URLs ending with '.pdf' followed by additional characters and '.html'. This technique is commonly used to bypass security filters and deceive recipients into believing they are accessing a legitimate PDF document.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: PDF filename impersonation with credential theft language

Detects messages where the link display text mimics a PDF filename containing the sender's domain name, combined with credential theft language or suspicious requests. The message is sent to an invalid recipient address or to the sender themselves, indicating potential abuse of email infrastructure.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Personal SharePoint with invalid recipients and credential theft language

Detects messages with undisclosed or invalid recipients containing a single link to a personal SharePoint domain (with '-my' pattern) and high-confidence credential theft language in short message body.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Personalized URL with recipient address on commonly abused web service

Detects messages containing links to file hosting or self-service platforms where the recipient's email address is embedded in the URL path, fragment, or base64-encoded components, indicating targeted personalization tactics.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Link: QR code in EML attachment with credential phishing indicators

This rule detects QR codes in EML attachments that return a phishing disposition when analyzed, or are leveraging a known open redirect.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: QR code with phishing disposition in img or pdf

This rule analyzes image attachments for QR Codes in which LinkAnalysis concludes is phishing. The rule ensures that the URLs do not link to any organizational domains.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: QR Code with suspicious language (untrusted sender)

This rule analyzes image attachments for QR Codes that contain URLs including the recipient's email address. It ensures that the URLs do not link to any organizational domains. Additionally, it examines the email body using Natural Language Processing to detect credential phishing language.In cases of null bodies, the rule is conditioned to check the image for any suspicious terms.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: QuickBooks image lure with suspicious link

This rule detects messages with image attachments containing QuickBooks logo containing exactly 1 link to a suspicious URL.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Recently registered .vu domain in lure

Flags inbound messages containing links that point to a .vu domain registered within the last 90 days. Observed samples span a range of lures - fake DocuSign contract requests, billing dispute notices, calendar invites, birthday and BBQ party invitations, and bidding process invites - all using freshly registered .vu domains to host malicious content while evading domain-reputation based detection.

T1566T1566.001T1566.002T1598T1534+2
Sublimelow
PreviousPage 33 of 53Next