
Summary
This rule detects inbound emails that abuse tracking-style URLs by appending the recipient’s own address to the URL path. Specifically, it flags messages where any link in the body has an href_url.path that ends with /&lht=<recipient_email>, using the first recipient’s email for comparison. The pattern is tied to a fake missed voicemail/voicecall lure, with obfuscated or zero-width characters in the subject line and spoofed sender domains, directing recipients to a credential-harvesting page personalized to their address. Detection relies on URL analysis (path-end matching), content analysis (link extraction and path inspection), and header analysis (spoofed sender indicators). The attack type is Credential Phishing, executed through social engineering and impersonation, with evasion tactics to circumvent naive filters. Given the targeted, address-specific nature of the lure, this rule is high severity and intended to reduce credential harvesting attempts that rely on tailoring the lure to the recipient’s identity.
Categories
- Network
Data Sources
- Network Traffic
Created: 2026-10-06