Detection rules › Sublime MQL
Sublime MQL rules: dropbox
| Rule | Severity |
|---|---|
| Credential Phishing via Dropbox comment abuse | medium |
Credential Phishing via Dropbox comment abuse
#This rule detects Credential Phishing attacks exploiting familiar brands via Dropbox comments. These attacks originate from legitimate Dropbox infrastructure and attempt to pivot to external freemail addresses.
Threat classification
Sublime's own taxonomy (not MITRE ATT&CK).
| Category | Values |
|---|---|
| Attack types | Credential Phishing |
| Tactics and techniques | Evasion, Out of band pivot, Social engineering |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Sublime | Inbound email message |
Message attributes
Rule body
type.inbound
and length(attachments) == 0
// Legitimate Dropbox sending infratructure
and (
sender.email.domain.root_domain in ('dropbox.net', 'dropbox.com')
// check for DMARC fail for spoofs
and headers.auth_summary.dmarc.pass
)
// Dropbox Logo or text
and (
any(ml.logo_detect(file.message_screenshot()).brands, .name == "Dropbox")
or strings.contains(body.current_thread.text, "Dropbox")
)
// Require common brand impersonation
and strings.ilike(body.current_thread.text,
"*mcafee*",
"*norton*",
"*geek*squad*",
"*paypal*",
"*ebay*",
"*symantec*",
"*best buy*",
"*lifelock*",
"*geek*support*"
)
and 3 of (
strings.ilike(body.current_thread.text, '*purchase*'),
strings.ilike(body.current_thread.text, '*payment*'),
strings.ilike(body.current_thread.text, '*transaction*'),
strings.ilike(body.current_thread.text, '*subscription*'),
strings.ilike(body.current_thread.text, '*antivirus*'),
strings.ilike(body.current_thread.text, '*order*'),
strings.ilike(body.current_thread.text, '*support*'),
strings.ilike(body.current_thread.text, '*help line*'),
strings.ilike(body.current_thread.text, '*receipt*'),
strings.ilike(body.current_thread.text, '*invoice*'),
strings.ilike(body.current_thread.text, '*call*'),
strings.ilike(body.current_thread.text, '*cancel*'),
strings.ilike(body.current_thread.text, '*renew*'),
strings.ilike(body.current_thread.text, '*refund*'),
strings.ilike(body.current_thread.text, '*transfer*'),
strings.ilike(body.current_thread.text, '*message*')
)
// there's an email in the body
and regex.contains(body.current_thread.text,
"[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,}"
)
// and it's likely a freemail
and any($free_email_providers, strings.icontains(body.current_thread.text, .))
Detection logic
Scope: inbound message.
This rule detects Credential Phishing attacks exploiting familiar brands via Dropbox comments. These attacks originate from legitimate Dropbox infrastructure and attempt to pivot to external freemail addresses.
- inbound message
- length(attachments) is 0
all of:
- sender.email.domain.root_domain in ('dropbox.net', 'dropbox.com')
- headers.auth_summary.dmarc.pass
any of:
any of
ml.logo_detect(file.message_screenshot()).brandswhere:- .name is 'Dropbox'
- body.current_thread.text contains 'Dropbox'
body.current_thread.text matches any of 9 patterns
*mcafee**norton**geek*squad**paypal**ebay**symantec**best buy**lifelock**geek*support*
at least 3 of 16: body.current_thread.text matches any of 16 patterns
*purchase**payment**transaction**subscription**antivirus**order**support**help line**receipt**invoice**call**cancel**renew**refund**transfer**message*
- body.current_thread.text matches '[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\\\.[A-Za-z]{2,}'
any of
$free_email_providerswhere:- strings.icontains(body.current_thread.text)
Inspects: body.current_thread.text, headers.auth_summary.dmarc.pass, sender.email.domain.root_domain, type.inbound. Sensors: file.message_screenshot, ml.logo_detect, regex.contains, strings.contains, strings.icontains, strings.ilike. Reference lists: $free_email_providers.
Indicators matched (30)
| Field | Match | Value |
|---|---|---|
sender.email.domain.root_domain | member | dropbox.net |
sender.email.domain.root_domain | member | dropbox.com |
ml.logo_detect(file.message_screenshot()).brands[].name | equals | Dropbox |
strings.contains | substring | Dropbox |
strings.ilike | substring | *mcafee* |
strings.ilike | substring | *norton* |
strings.ilike | substring | *geek*squad* |
strings.ilike | substring | *paypal* |
strings.ilike | substring | *ebay* |
strings.ilike | substring | *symantec* |
strings.ilike | substring | *best buy* |
strings.ilike | substring | *lifelock* |
18 more
strings.ilike | substring | *geek*support* |
strings.ilike | substring | *purchase* |
strings.ilike | substring | *payment* |
strings.ilike | substring | *transaction* |
strings.ilike | substring | *subscription* |
strings.ilike | substring | *antivirus* |
strings.ilike | substring | *order* |
strings.ilike | substring | *support* |
strings.ilike | substring | *help line* |
strings.ilike | substring | *receipt* |
strings.ilike | substring | *invoice* |
strings.ilike | substring | *call* |
strings.ilike | substring | *cancel* |
strings.ilike | substring | *renew* |
strings.ilike | substring | *refund* |
strings.ilike | substring | *transfer* |
strings.ilike | substring | *message* |
regex.contains | regex | [A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,} |
Stages and Predicates
Stage 1: mql_rule
and
or
any(ml.logo_detect(file.message_screenshot()).brands)
ml.logo_detect(file.message_screenshot()).brands.name eq "Dropbox"
body.current_thread.text contains "Dropbox"
or
body.current_thread.text match "antivirus"
body.current_thread.text match "call"
body.current_thread.text match "cancel"
body.current_thread.text match "help line"
body.current_thread.text match "invoice"
body.current_thread.text match "message"
body.current_thread.text match "order"
body.current_thread.text match "payment"
body.current_thread.text match "purchase"
body.current_thread.text match "receipt"
body.current_thread.text match "refund"
body.current_thread.text match "renew"
body.current_thread.text match "subscription"
body.current_thread.text match "support"
body.current_thread.text match "transaction"
body.current_thread.text match "transfer"
or
body.current_thread.text match "best buy"
body.current_thread.text match "ebay"
body.current_thread.text match "lifelock"
body.current_thread.text match "mcafee"
body.current_thread.text match "norton"
body.current_thread.text match "paypal"
body.current_thread.text match "symantec"
body.current_thread.text wildcard "*geek*squad*"
body.current_thread.text wildcard "*geek*support*"
any($free_email_providers)
strings.icontains func_call "strings.icontains(body.current_thread.text)"
attachments length_compare "0"
body.current_thread.text regex_match "[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\\\.[A-Za-z]{2,}"
headers.auth_summary.dmarc.pass eq "true"
sender.email.domain.root_domain in ["dropbox.com", "dropbox.net"]
type.inbound eq "true"Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
body.current_thread.text | contains |
| field:"body.current_thread.text" kind:contains value:"Dropbox" |
body.current_thread.text | regex_match |
| field:"body.current_thread.text" kind:regex_match value:"[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}" |
body.current_thread.text | wildcard |
| field:"body.current_thread.text" kind:wildcard |
headers.auth_summary.dmarc.pass | eq |
| field:"headers.auth_summary.dmarc.pass" kind:eq value:"true" |
sender.email.domain.root_domain | in |
| field:"sender.email.domain.root_domain" kind:in |
type.inbound | eq |
| field:"type.inbound" kind:eq value:"true" |