
Summary
This detection rule targets affiliate marketing spam by identifying messages containing links with excessive display-text lengths, specifically those exceeding 3000 characters. It checks for the presence of specific keywords related to sensitive information, such as 'Password:', in the display-text of those links. The assessment also incorporates sender profile analysis; it checks if the sender's prevalence is categorized as 'new' or 'outlier', or if they have sent previous messages flagged as malicious or spam, while ensuring that no false positives have occurred from these profiles. This rule aims to enhance the identification of potential fraudulent campaigns by analyzing message content and sender behavior in combination.
Categories
- Web
- Application
- Endpoint
- Identity Management
Data Sources
- User Account
- Application Log
- Network Traffic
Created: 2023-03-06