heroui logo

Link: Credential phishing with cloaked content

Sublime Rules

View Source
Summary
The rule detects credential-phishing attempts where an inbound email contains a small number of links (1–9) with cloaked content. The visible link text is interpreted as credential-theft intent with a security/authentication theme, while the linked page’s full text is benign and unrelated to security topics. A mismatch between the link’s displayed text and the actual page content triggers detection. Additionally, the rule requires that the accessed page loads a Cloudflare Insights beacon script (static.cloudflareinsights.com/beacon.min.js) as part of the page’s URLs, indicating an evasion technique designed to mask the credential-harvesting page from automated analysis while presenting a convincing login lure to the user. The detection relies on a combination of URL/HTML analysis and natural language understanding (NLU) signals to assess intent, topic, and content alignment between display_text and inner_text, in conjunction with the beacon script. If triggered, the rule represents a credential phishing attempt that leverages evasion and social engineering techniques, aiming to mislead users into entering credentials on a cloaked page while appearing legitimate in the link’s visible text. The rule is designed to reduce false positives by cross-checking the NLU-intended cred_theft signal against benign intents for the underlying page text and by requiring the presence of a specific beacon request as a corroborating artifact.
Categories
  • Web
  • Endpoint
  • Application
Data Sources
  • Script
  • Network Traffic
Created: 2026-10-08