
Summary
Detect inbound emails that abuse mismatched hyperlinks: the displayed link points to a free file hosting service while the actual destination resolves to another free file host or a suspicious top‑level domain. The rule pairs URL/domain analysis with an NLU classifier to identify BEC or credential‑theft intent, requiring a non‑low confidence result. It looks for document‑lure cues in the body (examples include "scanned from", "shared via", "for your review", or phrases like "uploaded/shared via" and similar), and enforces a 2‑of condition across several textual indicators (phrases about scanning or file availability, the presence of long repeated characters, short total length, and requests to review or act). Trusted senders with passing DMARC are excluded to reduce false positives. Data sources include inbound email content and contextual URL/domain information from network traffic and domain metadata. The rule is labeled medium severity and maps to attack types such as BEC/Fraud and Credential Phishing, with detection methods spanning Natural Language Understanding, URL analysis, and content analysis to identify social engineering and link‑based lures using free file hosting infrastructure.
Categories
- Network
- Web
Data Sources
- Network Traffic
- Application Log
- Domain Name
Created: 2026-08-06