Detection rules › Sublime MQL

Service abuse: Dropbox Paper with copy-paste instructions

Severity
medium
Type
rule
Source
github.com/sublime-security/sublime-rules

Detects messages containing copy-paste instructions with links to Dropbox Paper documents, commonly used to bypass security controls by instructing users to manually navigate to malicious content.

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesCredential Phishing
Tactics and techniquesSocial engineering, Free file host, Evasion

Event coverage

Message attribute
body.current_thread
type

Rule body MQL

type.inbound
and strings.icontains(body.current_thread.text, 'copy')
and strings.icontains(body.current_thread.text, 'paste')
and any(body.current_thread.links,
        strings.icontains(.display_url.url, 'https://www.dropbox.com/scl/fi/')
        and strings.icontains(.display_url.url, '.paper')
)

Detection logic

Scope: inbound message.

Detects messages containing copy-paste instructions with links to Dropbox Paper documents, commonly used to bypass security controls by instructing users to manually navigate to malicious content.

  1. inbound message
  2. body.current_thread.text contains 'copy'
  3. body.current_thread.text contains 'paste'
  4. any of body.current_thread.links where all hold:
    • .display_url.url contains 'https://www.dropbox.com/scl/fi/'
    • .display_url.url contains '.paper'

Inspects: body.current_thread.links, body.current_thread.links[].display_url.url, body.current_thread.text, type.inbound. Sensors: strings.icontains.

Indicators matched (4)

FieldMatchValue
strings.icontainssubstringcopy
strings.icontainssubstringpaste
strings.icontainssubstringhttps://www.dropbox.com/scl/fi/
strings.icontainssubstring.paper