
Summary
Detects inbound emails containing hyperlinks to an /amsweb.php path on domains outside the Tranco 1M list, typically used in giveaway/prize spam that impersonates insurance, retail, or roadside-assistance brands. The rule scans the email body for links (body.links) and examines each href_url.path for the string '/amsweb.php'. It also ensures the link’s root domain is not in $tranco_1m (a trusted-domain blocklist). To reduce FP from legitimate high-trust senders, the rule excludes messages from domains listed in $high_trust_sender_root_domains unless DMARC authentication fails; i.e., if the sender is high-trust and DMARC passes, the message is not flagged, otherwise it is. This combination targets URL-based phishing and fraud attempts that leverage affiliate-style redirects via /amsweb.php, observed in disposable sender domains on the .pro TLD using homoglyph display names. Attack types include Spam and BEC/Fraud, with detection primarily through URL analysis and domain checks. The rule relies on inbound data (type.inbound) and headers evidence (headers.auth_summary.dmarc.pass) to distinguish legitimate senders from spoofed ones. Potential limitations include legitimate affiliates that legitimately redirect through /amsweb.php and URL-encoding or obfuscated paths that bypass simple substring matches. The rule complements broader anti-phishing controls by focusing on problematic redirect patterns and sender-domain trust signals.
Categories
- Web
- Application
Data Sources
- Application Log
- Network Traffic
Created: 2026-10-09