Detection rules › Sublime MQL

Brand impersonation: Zoom with deceptive link display

Severity
medium
Type
rule
Source
github.com/sublime-security/sublime-rules

Detects messages mentioning Zoom in the subject or body that contain links appearing to go to zoom.us but actually redirect to different domains.

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesCredential Phishing, Malware/Ransomware
Tactics and techniquesImpersonation: Brand

Event coverage

Rule body MQL

type.inbound
and sender.email.domain.root_domain in $free_email_providers
and any([subject.base, body.current_thread.text], strings.icontains(., "zoom"))
and any(filter(body.current_thread.links,
               strings.icontains(.href_url.url, "zoom.us")
        ),
        .href_url.domain.root_domain not in ("zoom.us", "zoom.com")
        and .display_url.domain.root_domain not in ("zoom.us", "zoom.com")
)

Detection logic

Scope: inbound message.

Detects messages mentioning Zoom in the subject or body that contain links appearing to go to zoom.us but actually redirect to different domains.

  1. inbound message
  2. sender.email.domain.root_domain in $free_email_providers
  3. any of [subject.base, body.current_thread.text] where:
    • . contains 'zoom'
  4. any of filter(body.current_thread.links) where all hold:
    • .href_url.domain.root_domain not in ('zoom.us', 'zoom.com')
    • .display_url.domain.root_domain not in ('zoom.us', 'zoom.com')

Inspects: body.current_thread.links, body.current_thread.links[].href_url.url, body.current_thread.text, sender.email.domain.root_domain, subject.base, type.inbound. Sensors: strings.icontains. Reference lists: $free_email_providers.

Indicators matched (6)

FieldMatchValue
strings.icontainssubstringzoom
strings.icontainssubstringzoom.us
filter(body.current_thread.links)[].href_url.domain.root_domainmemberzoom.us
filter(body.current_thread.links)[].href_url.domain.root_domainmemberzoom.com
filter(body.current_thread.links)[].display_url.domain.root_domainmemberzoom.us
filter(body.current_thread.links)[].display_url.domain.root_domainmemberzoom.com