heroui logo

Brand impersonation: Microsoft logo image linking to free file host

Sublime Rules

View Source
Summary
Detects inbound messages containing an inline image displaying a Microsoft-branded logo (identified via logo detection with Microsoft branding at high confidence) that includes discernible text (OCR) and is embedded as a clickable link within the message body. The image must be larger than 96x96 and include OCR text with more than five word-like tokens. The rule then inspects the anchor tags wrapping the image to identify links that point to self-service platform domains or free file-hosting domains (by domain or root_domain) while excluding tenant/SharePoint domains. This combination indicates potential credential phishing or malware delivery masquerading as trusted Microsoft content. Detection uses Computer Vision, OCR, EXIF analysis, HTML analysis, and URL/domain checks. Attacks covered include Credential Phishing and Malware/Ransomware; Techniques include Brand Impersonation, Image-as-content, Free File Host usage, and Social Engineering.
Categories
  • Web
  • Endpoint
Data Sources
  • Image
  • File
Created: 2026-08-22