heroui logo

Attachment: PDF with dub.sh shortened link

Sublime Rules

View Source
Summary
Detects inbound messages carrying PDF attachments that embed shortened links via the dub.sh service to obscure the final destination and evade URL-based filtering. The rule targets PDFs in inbound attachments, inspects the file content (via file analysis) by exploding the PDF structure, and searches for URLs. If any embedded URL has a root domain of dub.sh, the alert fires. This pattern is common in credential phishing and BEC scenarios, where threat actors lure users with fake password-protected documents, e-signature notifications, or business proposals. Detectors rely on file analysis and URL analysis to identify the shortened link within the PDF.
Categories
  • Endpoint
Data Sources
  • File
Created: 2026-09-10