
Summary
This detection identifies inbound messages containing Google Cloud Storage links (storage.googleapis.com) where the fragment portion after the # is a base64-encoded string. The detector decodes fragment[1:] (ignoring padding) and matches a query pattern that encodes affiliate/tracking data: go=[12]&s1=
\d+&s2=\d+&s3=[a-z]+. The decoded fragment carries a click/unsubscribe flag and a per-recipient ID, which spam campaigns use for tracking and evasion. The rule targets observed instances in free kit and parcel delivery spam and uses URL analysis of inbound content to flag these suspicious links.
Categories
- Web
- GCP
Data Sources
- Cloud Storage
Created: 2026-10-06