
Summary
This inbound rule detects Google Cloud Storage links whose fragment contains a highly structured affiliate tracking token. It watches for links where the href_url.domain.domain equals storage.googleapis.com, and requires the fragment to contain a long, fixed-format sequence designed to encode a click or unsubscribe action. The token starts with 4 or 5 (indicating click or unsubscribe) followed by alternating letter and digit groups with case-specific fillers (e.g., mixed lowercase and uppercase segments). The regex pattern enforces a token composed of: a leading 4/5, five letters, digits, four letters, digits, ten lowercase letters, digits, fifteen uppercase letters, digits, 1-4 uppercase or slash characters, digits, a final letter, and trailing digits, bounded by word boundaries. This pattern is observed in mass-mail spam campaigns that use Google Cloud Storage links to carry affiliate tokens, notably in kits, gift cards, and account suspension messages. The rule uses URL analysis to inspect inbound traffic and flags those fragments that match the pattern as potential spam with evasion characteristics. This technique aligns with evading straightforward keyword or simple URL checks by encoding a long, non-obvious token within the fragment. Potential false positives may arise if legitimate marketing or affiliate flows inadvertently produce similarly structured fragments; tuning may be needed to correlate with known campaigns or host paths. Overall, the rule helps detect obfuscated affiliate tracking in cloud storage links commonly used in spam campaigns."
Categories
- Cloud
- Web
- GCP
Data Sources
- Network Traffic
Created: 2026-10-06