
Summary
This rule detects inbound emails that abuse Google Cloud Storage hosting by embedding exactly two distinct links to the same bucket, where the paths follow the pattern /<bucket>/index and /<bucket>/unsub (the unsub variant may be unsub or unsubv). It analyzes body.links to collect href_url.domain.domain values equal to storage.googleapis.com and href_url.path values, requiring exactly two unique links. It validates that both links reside in the same bucket by extracting the bucket name from the path and ensuring the bucket is identical across both links. The rule then confirms both links match the index/unsub pattern, and that they share the same bucket, indicating a coordinated landing/unsubscribe setup used in spam campaigns. This pattern is commonly used to promote wellness products, supplements, or loyalty offers and to lend legitimacy by leveraging a trusted cloud storage domain, helping to evade reputation-based filtering. The detection relies on URL analysis and content analysis, and is tagged as medium severity with indicators for spam and social engineering (free file host) tactics.
Categories
- Endpoint
Data Sources
- Cloud Storage
- Network Traffic
Created: 2026-10-06