
Summary
Detects inbound messages carrying PDF attachments that embed shortened links via the dub.sh service to obscure the final destination and evade URL-based filtering. The rule targets PDFs in inbound attachments, inspects the file content (via file analysis) by exploding the PDF structure, and searches for URLs. If any embedded URL has a root domain of dub.sh, the alert fires. This pattern is common in credential phishing and BEC scenarios, where threat actors lure users with fake password-protected documents, e-signature notifications, or business proposals. Detectors rely on file analysis and URL analysis to identify the shortened link within the PDF.
Categories
- Endpoint
Data Sources
- File
Created: 2026-09-10