heroui logo

Link: Google Cloud Storage with prefixed base64 dash-record fragment

Sublime Rules

View Source
Summary
Detects inbound messages containing Google Cloud Storage links where the fragment encodes a tracking payload used in credential-phishing and spam campaigns. The rule targets URLs with domain storage.googleapis.com and requires the fragment to begin with a 30-character alphanumeric block (A-Z0-9) followed by a single-character marker 'r' or 'u'. The remainder of the fragment is base64-decoded (padding ignored) and must match a dash-delimited pattern that includes multiple numeric segments, a single alphabetic segment, and a final token composed of a 9-character alphanumeric block and an 8-character hexadecimal block. This structure corresponds to a tracking/verification record used in fake account suspension, health, and warranty spam. The detection relies on URL analysis of inbound links to identify these crafted Google Cloud Storage references, which are then associated with credential phishing and spam campaigns employing social engineering and evasion techniques to defeat simple filters.
Categories
  • Cloud
  • Web
Data Sources
  • Cloud Storage
Created: 2026-10-06