Detection rules › Sublime MQL

URL with Unicode U+2044 (⁄) or U+2215 (∕) characters

Severity
low
Type
rule
Source
github.com/sublime-security/sublime-rules

Body of the message, or any links, contain the Unicode U+2044 (⁄) or U+2215 (∕) characters inside a URL.

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesCredential Phishing
Tactics and techniquesEvasion, Social engineering

Event coverage

Rule body MQL

type.inbound
and (
  regex.icontains(body.plain.raw,
                  'https?:\/\/[^\s⁄∕]+(?:\/[^\s⁄∕]+)*[⁄∕][^\s⁄∕]+'
  )
  or any(body.links,
         regex.icontains(.href_url.url,
                         'https?:\/\/[^\s⁄∕]+(?:\/[^\s⁄∕]+)*[⁄∕][^\s⁄∕]+'
         )
  )
)

Detection logic

Scope: inbound message.

Body of the message, or any links, contain the Unicode U+2044 (⁄) or U+2215 (∕) characters inside a URL.

  1. inbound message
  2. any of:
    • body.plain.raw matches 'https?:\\/\\/[^\\s⁄∕]+(?:\\/[^\\s⁄∕]+)*[⁄∕][^\\s⁄∕]+'
    • any of body.links where:
      • .href_url.url matches 'https?:\\/\\/[^\\s⁄∕]+(?:\\/[^\\s⁄∕]+)*[⁄∕][^\\s⁄∕]+'

Inspects: body.links, body.links[].href_url.url, body.plain.raw, type.inbound. Sensors: regex.icontains.

Indicators matched (1)

FieldMatchValue
regex.icontainsregexhttps?:\/\/[^\s⁄∕]+(?:\/[^\s⁄∕]+)*[⁄∕][^\s⁄∕]+