Detection rules › Sublime MQL
Open redirect: Signature Travel Network
Message contains use of the Signature Travel Network open redirect, but the sender is not Signature Travel Network. This has been exploited in the wild.
Threat classification
Sublime's own taxonomy (not MITRE ATT&CK).
| Category | Values |
|---|---|
| Attack types | Credential Phishing |
| Tactics and techniques | Open redirect |
Event coverage
Rule body MQL
type.inbound
and any(body.links,
.href_url.domain.root_domain == 'sigtn.com'
and strings.iends_with(.href_url.path, "emt.cfm")
and strings.icontains(.href_url.query_params, "link=")
)
and sender.email.domain.root_domain not in (
'signaturetravelnetwork.com',
'sigtn.com'
)
and not any(headers.domains, .root_domain == "signaturetravelnetwork.com")
// negate highly trusted sender domains unless they fail DMARC authentication
and (
(
sender.email.domain.root_domain in $high_trust_sender_root_domains
and not headers.auth_summary.dmarc.pass
)
or sender.email.domain.root_domain not in $high_trust_sender_root_domains
)
Detection logic
Scope: inbound message.
Message contains use of the Signature Travel Network open redirect, but the sender is not Signature Travel Network. This has been exploited in the wild.
- inbound message
any of
body.linkswhere all hold:- .href_url.domain.root_domain is 'sigtn.com'
- .href_url.path ends with 'emt.cfm'
- .href_url.query_params contains 'link='
- sender.email.domain.root_domain not in ('signaturetravelnetwork.com', 'sigtn.com')
not:
any of
headers.domainswhere:- .root_domain is 'signaturetravelnetwork.com'
any of:
all of:
- sender.email.domain.root_domain in $high_trust_sender_root_domains
not:
- headers.auth_summary.dmarc.pass
- sender.email.domain.root_domain not in $high_trust_sender_root_domains
Inspects: body.links, body.links[].href_url.domain.root_domain, body.links[].href_url.path, body.links[].href_url.query_params, headers.auth_summary.dmarc.pass, headers.domains, headers.domains[].root_domain, sender.email.domain.root_domain, type.inbound. Sensors: strings.icontains, strings.iends_with. Reference lists: $high_trust_sender_root_domains.
Indicators matched (6)
| Field | Match | Value |
|---|---|---|
body.links[].href_url.domain.root_domain | equals | sigtn.com |
strings.iends_with | suffix | emt.cfm |
strings.icontains | substring | link= |
sender.email.domain.root_domain | member | signaturetravelnetwork.com |
sender.email.domain.root_domain | member | sigtn.com |
headers.domains[].root_domain | equals | signaturetravelnetwork.com |