heroui logo

Attachment: HTML smuggling with dynamically constructed redirect URL

Sublime Rules

View Source
Summary
Detects HTML attachments, including those nested inside forwarded EML files, that contain obfuscated JavaScript designed to dynamically assemble a redirect URL at runtime rather than embedding it directly in the markup. The rule analyzes inbound mail and inspects attachments: for HTML attachments, it requires two or more of the following indicators: (1) a route.join with an empty string used to build a path, (2) a script setting an image or iframe src from a url or protocol variable, and (3) a separately defined host constant. It also applies to EMLs and their HTML attachments (file_extension 'eml' or content_type 'message/rfc822') by recursively parsing nested attachments. This pattern is commonly used in HTML smuggling to evade static URL scanners and direct the user to a credential phishing page. The rule flags both direct HTML attachments and HTML content embedded in forwarded messages as potential credential phishing attempts. Detection methods include HTML analysis, JavaScript analysis, and file analysis. Attack types: Credential Phishing. Tactics/techniques: HTML smuggling, evasion, impersonation: brand, social engineering, scripting.
Categories
  • Endpoint
Data Sources
  • File
  • Script
Created: 2026-09-29