heroui logo

Spoofing: Hidden Outlook headers in self-addressed forwards

Sublime Rules

View Source
Summary
This rule detects inbound messages where the sender address is spoofed to match the recipient (a DMARC failure scenario) by simulating a self-forward. It searches for a hidden HTML block styled to be display:none that mimics Outlook-style forward/reply headers (From/Sent/Subject) used to disguise malicious content (e.g., fake remittance receipts or finance document notifications). The rule requires that the original sender equals the recipient and that DMARC did not pass. It uses an XPath with translate() to detect display:none styling in the HTML, and a regex to find an Outlook-like header sequence (From:... Sent:... Subject:...). It then runs a natural language classifier on the thread text, requiring an intent that is not benign. Attack types include BEC/Fraud and Credential Phishing; detections rely on header analysis, HTML/XML analysis, and sender analysis, complemented by NLU for intent. The rule operates as a defense-in-depth check at the intersection of email headers, content obfuscation, and user-targeted social engineering. Potential false positives may arise from legitimate copy-forward behaviors or templates that accidentally resemble the structure; tuning and contextual evaluation are advised to minimize noise.
Categories
  • Endpoint
  • Web
  • Network
Data Sources
  • Script
  • Application Log
  • Network Traffic
Created: 2026-10-06