
Summary
This rule detects inbound emails that contain hyperlinks to storage.googleapis.com in which the URL fragment or query string includes a highly specific alphanumeric token pattern. The pattern corresponds to a zipper-interleaved tracking token used by a known phishing kit that leverages Google Cloud Storage as the hosting/delivery channel for malicious content. By targeting the token structure rather than the domain alone, the rule aims to bypass generic domain filters and identify a class of campaigns that fetch payloads from cloud storage after the user clicks the link. The detection is implemented via URL analysis: it requires the href_url.domain to be storage.googleapis.com and inspects the fragment and/or query parameters for a regex-matching sequence of digits and lowercase letters with fixed segments (as defined by the token format), including specific subparts such as multi-digit blocks, letter pairs, a fixed 24-prefixed component, trailing two-letter suffixes, and a final six-digit block. This approach aligns with credential phishing use-cases where attackers rely on trusted cloud storage domains to host or deliver payloads while evading basic URL-based filters. The rule is categorized under Credential Phishing and uses URL analysis as its primary detection method to flag these cloud-storage–hosted phishing attempts.
Categories
- Web
- Network
Data Sources
- Network Traffic
Created: 2026-10-06