Detection rules › Sublime MQL

Attachment: Link to Doubleclick.net open redirect

Severity
medium
Type
rule
Source
github.com/sublime-security/sublime-rules

Doubleclick.net link in a document leveraging an open redirect.

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesBEC/Fraud, Credential Phishing
Tactics and techniquesEvasion, Open redirect, Social engineering

Event coverage

Rule body MQL

type.inbound
and length(body.links) == 0
and any(attachments,
        (.file_type in ("pdf", "doc", "docx"))
        and any(file.explode(.),
                any(.scan.url.urls,
                    .domain.root_domain == "doubleclick.net"
                    and (
                      strings.icontains(.path, "/aclk")
                      or strings.icontains(.path, "/pcs/click")
                      or strings.icontains(.path, "/searchads/link/click")
                    )
                    and regex.icontains(.query_params,
                                        '&(?:adurl|ds_dest_url)=(?:[a-z]+(?:\:|%3a))?(?:\/|%2f)(?:\/|%2f)'
                    )
                )
        )
)

Detection logic

Scope: inbound message.

Doubleclick.net link in a document leveraging an open redirect.

  1. inbound message
  2. length(body.links) is 0
  3. any of attachments where all hold:
    • .file_type in ('pdf', 'doc', 'docx')
    • any of file.explode(.) where:
      • any of .scan.url.urls where all hold:
        • .domain.root_domain is 'doubleclick.net'
        • any of:
          • .path contains '/aclk'
          • .path contains '/pcs/click'
          • .path contains '/searchads/link/click'
        • .query_params matches '&(?:adurl|ds_dest_url)=(?:[a-z]+(?:\\:|%3a))?(?:\\/|%2f)(?:\\/|%2f)'

Inspects: attachments[].file_type, body.links, type.inbound. Sensors: file.explode, regex.icontains, strings.icontains.

Indicators matched (8)

FieldMatchValue
attachments[].file_typememberpdf
attachments[].file_typememberdoc
attachments[].file_typememberdocx
file.explode(attachments[])[].scan.url.urls[].domain.root_domainequalsdoubleclick.net
strings.icontainssubstring/aclk
strings.icontainssubstring/pcs/click
strings.icontainssubstring/searchads/link/click
regex.icontainsregex&(?:adurl|ds_dest_url)=(?:[a-z]+(?:\:|%3a))?(?:\/|%2f)(?:\/|%2f)