Detection rules › Sublime MQL
Sublime MQL rules: predatory
| Rule | Severity |
|---|---|
| Spam/fraud: Predatory journal/research paper request | medium |
Spam/fraud: Predatory journal/research paper request
#Detects messages related to academic research and publishing that contain suspicious patterns including character manipulation, flattering language, time pressure tactics, and domain registration anomalies. Focuses on unsolicited invitations for manuscript submissions, peer reviews, or editorial roles.
Threat classification
Sublime's own taxonomy (not MITRE ATT&CK).
| Category | Values |
|---|---|
| Attack types | BEC/Fraud, Spam |
| Tactics and techniques | Social engineering, Impersonation: Brand, Lookalike domain, Evasion |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Sublime | Inbound email message |
Message attributes
Rule body
type.inbound
and any(beta.ml_topic(body.current_thread.text).topics,
.name == "Educational and Research"
and .confidence in ("medium", "high")
)
and not any(beta.ml_topic(body.current_thread.text).topics,
.name in ("Health and Wellness") and .confidence == "high"
)
and ml.nlu_classifier(body.current_thread.text).language == "english"
and 3 of (
regex.count(body.current_thread.text,
'[Æ×æı-ijʼnŒœƁƄƇƊƍƓƖƘƠơƤƦƧƬƳƷƼƽǀǁLJ-njDZ-dzȜȢȣɑɡɣɩɪɯʋʏʣʦʪʫ˛ͺͿΑΒΕ-ΗΙΚΜΝΟΡΤΥΧαγινορσυϒϜϨϱ-ϳϹϺЅІЈАВЕЗКМ-ОР-УХЫЬЮабгеорсухѕіјѡѴѵґҮүһҽӀӏӔӕӠԁԌԛ-ԝՍՏՕագզհոռսցքօ׀וטןסװױاه١٥٧ھہە۱۵۷߀ߊ०০৪৭੦੧੪ଠ୦୨ഠ൦๐໐ဝ၀ყჿሀዐᎠ-ᎢᎤᎥᎩ-ᎬᎳᎷᎻᎽᏀᏂᏃᏎᏏᏒᏔᏕᏙᏚᏞᏟᏢᏦᏧᏮᏳᏴᐯᑌᑧᑭᑯᑲᒆ-ᒈᒍᒪᒿᕁᕼᕽᖇᖯᖴᗅᗞᗪᗰᗷ᙭᙮ᚷᛁᛕᛖᴄᴏᴑᴜᴠ-ᴢᴦᵫᶃᶌẝỿι‖₨₶℀-ℂ℅℆ℊ-ℎℐ-ℓℕ№ℙ-ℝ℡ℤℨℬ-ℱℳℴℹ℻ℽⅅ-ⅉⅠ-ⅿ∞∣∥∨∪⊤⋁⋃⋿⍳⍴⍺⏽⑴-⒵╳⟙⤫⤬⨯ⲅⲎⲒⲔⲘⲚⲞⲟⲢ-ⲦⲨⲬⳊⳌⳐⳒⴸⴹⵏⵔⵕⵝ〇ꓐ-ꓔꓖꓗꓙꓚꓜꓝꓟ-ꓣꓦꓧꓪ-ꓬꓮꓰꓲ-ꓴꙄꙇꚘꚙꛟꛯꜨꜱ-ꜽꝎꝏꝚꝪꝮꝷꭵꮁꮃꮓꮩꮪꮯff-fflstﮦ-ﮭﺍﺎﻩ-ﻬA-CEH-KM-PSTX-Zaceg-jlopsvxy│𐊂𐊆𐊇𐊊𐊐𐊒𐊕-𐊗𐊠-𐊢𐊥𐊫𐊰-𐊲𐊴𐋏𐋵𐌁𐌂𐌉𐌑𐌕𐌗𐌚𐌠𐌢𐐄𐐕𐐛𐐠𐐬𐐽𐑈𐒴𐓂𐓎𐓒𐓪𐓶𐔓𐔖𐔘𐔜𐔝𐔥-𐔧𑓐𑜀𑜆𑜊𑜎𑜏𑢠𑢢-𑢤𑢦𑢩𑢬𑢮𑢯𑢲𑢵𑢸𑢻𑢼𑣀-𑣄𑣆𑣈𑣊𑣌𑣕-𑣘𑣜𑣠𑣣𑣥𑣦𑣩𑣬𑣯𑣲𖼈𖼊𖼖𖼨𖼵𖼺𖼻𖽀𖽂𖽃𝐀-𝑔𝑖-𝒜𝒞𝒟𝒢𝒥𝒦𝒩-𝒬𝒮-𝒹𝒻𝒽-𝓃𝓅-𝔅𝔇-𝔊𝔍-𝔔𝔖-𝔜𝔞-𝔹𝔻-𝔾𝕀-𝕄𝕆𝕊-𝕐𝕒-𝚤𝚨𝚩𝚬-𝚮𝚰𝚱𝚳𝚴𝚶𝚸𝚻𝚼𝚾𝛂𝛄𝛊𝛎𝛐𝛒𝛔𝛖𝛠𝛢𝛣𝛦-𝛨𝛪𝛫𝛭𝛮𝛰𝛲𝛵𝛶𝛸𝛼𝛾𝜄𝜈𝜊𝜌𝜎𝜐𝜚𝜜𝜝𝜠-𝜢𝜤𝜥𝜧𝜨𝜪𝜬𝜯𝜰𝜲𝜶𝜸𝜾𝝂𝝄𝝆𝝈𝝊𝝔𝝖𝝗𝝚-𝝜𝝞𝝟𝝡𝝢𝝤𝝦𝝩𝝪𝝬𝝰𝝲𝝸𝝼𝝾𝞀𝞂𝞄𝞎𝞐𝞑𝞔-𝞖𝞘𝞙𝞛𝞜𝞞𝞠𝞣𝞤𝞦𝞪𝞬𝞲𝞶𝞸𝞺𝞼𝞾𝟈𝟊𝟎]'
) > 100,
regex.icontains(strings.replace_confusables(body.current_thread.text),
"Impact Factor",
"Special Issue",
"Guest Editor",
"peer-review",
"manuscript",
"workshop",
"journal (of|editor)",
"inclusive research",
"abstract",
"open-access",
"upcoming edition",
"title of (your (work|published article)|the study)",
"your paper's title",
"and the abstract",
"abstract of (your work|the study)",
"detailed abstract",
'contribution\b',
"accepted paper",
"submit.{0,20}.(manuscript|article)",
"call for editorial",
"reviewer team",
"review.{0,15}.(journal|issue)"
),
// flattering language, as seen in previous research
regex.icontains(strings.replace_confusables(body.current_thread.text),
'your\s+(article|paper|research|publication|work)\s+"?[^"]+?"?\s+(is\s+very\s+excellent|strongly\s+reflects|will\s+be\s+a\s+valuable)',
'we\s+believe\s+(that\s+)?your\s+(experience|perspective|expertise|comments?)\s+(will\s+add|can\s+play|will\s+be)\s+.{0,100}(important|valuable)',
'(you\s+are\s+one\s+of\s+the\s+leading\s+experts?|someone\s+of\s+your\s+caliber)',
'(emerging\s+voices?\s+like\s+yours|shape\s+the\s+scholarly\s+direction)',
'(learning\s+from\s+the\s+internet|know\s+your\s+"[^"]+"\s+is\s+very\s+excellent)',
'(world''s|global|international)\s+(foremost|leading|top|premier)\s+(authorities|experts|researchers)',
// The "highly valued" variants
'your\s+(participation|contribution|presence|involvement)\s+(would\s+be|is)\s+(highly|greatly|immensely|extremely)\s+(valued|appreciated|welcomed)',
// Time pressure tactics
'(short\s+notice|busy\s+schedule|quick\s+turnaround|urgent\s+deadline|limited\s+slots)',
// "No charge" red flags
'(no\s+charge|free\s+of\s+charge|waived\s+fee|complimentary|at\s+no\s+cost)',
// Vague topic promises
'(topic\s+of\s+your\s+choice|any\s+topic\s+related|broad\s+range\s+of\s+topics|multidisciplinary\s+approach)',
// Easy publication promises
'(guaranteed\s+publication|fast\s+track\s+review|expedited\s+process|will\s+not\s+be\s+too\s+time-consuming)',
// Template giveaways
'(do\s+hope\s+you\s+can\s+make\s+time|kindly\s+submit|gentle\s+reminder|esteemed\s+researcher)'
),
// Message contains the users last name, but not their first name
// Presumably, this is because names are listed that way on academic papers
strings.icontains(body.current_thread.text, mailbox.last_name)
and not strings.icontains(body.current_thread.text, mailbox.first_name)
and not any(recipients.to,
strings.icontains(body.current_thread.text, .email.email)
)
and length(mailbox.last_name) > 4,
// Or, message contains the users last, first
// Example: Doe, John
// Presumably, this is because names are listed that way on academic papers
strings.icontains(body.current_thread.text,
strings.concat(mailbox.last_name, ", ", mailbox.first_name)
),
// new sender or link domain
network.whois(sender.email.domain).days_old < 90,
any(body.links, network.whois(.href_url.domain).days_old < 90),
// Crossref DOI registration abuse (https://doi.org/10.29328)
any(body.links,
.href_url.domain.root_domain == "doi.org"
and strings.istarts_with(.href_url.path, '/10.29328')
),
// Sender does not match original thread sender
length(body.previous_threads) > 0
and any(regex.iextract(body.html.display_text, 'From: (?P<email_address>\S*)'),
strings.parse_email(.named_groups['email_address']).email != sender.email.email
),
// sent from Windows Server with default name
strings.contains(headers.message_id, "@DESKTOP-"),
// requesting a manuscript review
strings.ilike(body.current_thread.text, "*review*")
and strings.ilike(body.current_thread.text, "*manuscript*", "*submission*"),
// Chinese registrant country
network.whois(sender.email.domain).registrant_country_code == "CN",
any(body.links,
network.whois(.href_url.domain).registrant_country_code == "CN"
),
// Alibaba infrastructure
any(headers.domains, .root_domain in ("aliyun.com", "aliyun-inc.com")),
// Known predatory journals that we've observed and matched to beallslist.net
sender.email.domain.root_domain in (
"iris-research.net",
"irispublishers.com",
"lidsen.com"
),
// sender domain and body link domains do not match, but have the same registration details
(
length(body.links) > 0
and all(body.links,
(
network.whois(.href_url.domain).registrant_company == network.whois(sender.email.domain
).registrant_company
and network.whois(.href_url.domain).registrar_name == network.whois(sender.email.domain
).registrar_name
)
and .href_url.domain.root_domain != sender.email.domain.root_domain
)
),
// known patterns
any(body.links, regex.imatch(.href_url.path, '^/ey[a-z]/.{2,}$'))
)
// negate microsoft quarantine messages
and not (
sender.email.email == "quarantine@messaging.microsoft.com"
and (
headers.auth_summary.dmarc.pass
// no sender auth but MS AuthAs is Internal
or (
not coalesce(headers.auth_summary.dmarc.pass, false)
and any(headers.hops,
.index == 0
and any(.fields,
.name == "X-MS-Exchange-CrossTenant-AuthAs"
and .value == "Internal"
)
)
)
)
)
Detection logic
Scope: inbound message.
Detects messages related to academic research and publishing that contain suspicious patterns including character manipulation, flattering language, time pressure tactics, and domain registration anomalies. Focuses on unsolicited invitations for manuscript submissions, peer reviews, or editorial roles.
- inbound message
any of
beta.ml_topic(body.current_thread.text).topicswhere all hold:- .name is 'Educational and Research'
- .confidence in ('medium', 'high')
not:
any of
beta.ml_topic(body.current_thread.text).topicswhere all hold:- .name in ('Health and Wellness')
- .confidence is 'high'
- ml.nlu_classifier(body.current_thread.text).language is 'english'
at least 3 of:
- regex.count(body.current_thread.text, '[Æ×æı-ijʼnŒœƁƄƇƊƍƓƖƘƠơƤƦƧƬƳƷƼƽǀǁLJ-njDZ-dzȜȢȣɑɡɣɩɪɯʋʏʣʦʪʫ˛ͺͿΑΒΕ-ΗΙΚΜΝΟΡΤΥΧαγινορσυϒϜϨϱ-ϳϹϺЅІЈАВЕЗКМ-ОР-УХЫЬЮабгеорсухѕіјѡѴѵґҮүһҽӀӏӔӕӠԁԌԛ-ԝՍՏՕագզհոռսցքօ׀וטןסװױاه١٥٧ھہە۱۵۷߀ߊ०০৪৭੦੧੪ଠ୦୨ഠ൦๐໐ဝ၀ყჿሀዐᎠ-ᎢᎤᎥᎩ-ᎬᎳᎷᎻᎽᏀᏂᏃᏎᏏᏒᏔᏕᏙᏚᏞᏟᏢᏦᏧᏮᏳᏴᐯᑌᑧᑭᑯᑲᒆ-ᒈᒍᒪᒿᕁᕼᕽᖇᖯᖴᗅᗞᗪᗰᗷ᙭᙮ᚷᛁᛕᛖᴄᴏᴑᴜᴠ-ᴢᴦᵫᶃᶌẝỿι‖₨₶℀-ℂ℅℆ℊ-ℎℐ-ℓℕ№ℙ-ℝ℡ℤℨℬ-ℱℳℴℹ℻ℽⅅ-ⅉⅠ-ⅿ∞∣∥∨∪⊤⋁⋃⋿⍳⍴⍺⏽⑴-⒵╳⟙⤫⤬⨯ⲅⲎⲒⲔⲘⲚⲞⲟⲢ-ⲦⲨⲬⳊⳌⳐⳒⴸⴹⵏⵔⵕⵝ〇ꓐ-ꓔꓖꓗꓙꓚꓜꓝꓟ-ꓣꓦꓧꓪ-ꓬꓮꓰꓲ-ꓴꙄꙇꚘꚙꛟꛯꜨꜱ-ꜽꝎꝏꝚꝪꝮꝷꭵꮁꮃꮓꮩꮪꮯff-fflstﮦ-ﮭﺍﺎﻩ-ﻬA-CEH-KM-PSTX-Zaceg-jlopsvxy│𐊂𐊆𐊇𐊊𐊐𐊒𐊕-𐊗𐊠-𐊢𐊥𐊫𐊰-𐊲𐊴𐋏𐋵𐌁𐌂𐌉𐌑𐌕𐌗𐌚𐌠𐌢𐐄𐐕𐐛𐐠𐐬𐐽𐑈𐒴𐓂𐓎𐓒𐓪𐓶𐔓𐔖𐔘𐔜𐔝𐔥-𐔧𑓐𑜀𑜆𑜊𑜎𑜏𑢠𑢢-𑢤𑢦𑢩𑢬𑢮𑢯𑢲𑢵𑢸𑢻𑢼𑣀-𑣄𑣆𑣈𑣊𑣌𑣕-𑣘𑣜𑣠𑣣𑣥𑣦𑣩𑣬𑣯𑣲𖼈𖼊𖼖𖼨𖼵𖼺𖼻𖽀𖽂𖽃𝐀-𝑔𝑖-𝒜𝒞𝒟𝒢𝒥𝒦𝒩-𝒬𝒮-𝒹𝒻𝒽-𝓃𝓅-𝔅𝔇-𝔊𝔍-𝔔𝔖-𝔜𝔞-𝔹𝔻-𝔾𝕀-𝕄𝕆𝕊-𝕐𝕒-𝚤𝚨𝚩𝚬-𝚮𝚰𝚱𝚳𝚴𝚶𝚸𝚻𝚼𝚾𝛂𝛄𝛊𝛎𝛐𝛒𝛔𝛖𝛠𝛢𝛣𝛦-𝛨𝛪𝛫𝛭𝛮𝛰𝛲𝛵𝛶𝛸𝛼𝛾𝜄𝜈𝜊𝜌𝜎𝜐𝜚𝜜𝜝𝜠-𝜢𝜤𝜥𝜧𝜨𝜪𝜬𝜯𝜰𝜲𝜶𝜸𝜾𝝂𝝄𝝆𝝈𝝊𝝔𝝖𝝗𝝚-𝝜𝝞𝝟𝝡𝝢𝝤𝝦𝝩𝝪𝝬𝝰𝝲𝝸𝝼𝝾𝞀𝞂𝞄𝞎𝞐𝞑𝞔-𝞖𝞘𝞙𝞛𝞜𝞞𝞠𝞣𝞤𝞦𝞪𝞬𝞲𝞶𝞸𝞺𝞼𝞾𝟈𝟊𝟎]') > 100
strings.replace_confusables(body.current_thread.text) matches any of 22 patterns
Impact FactorSpecial IssueGuest Editorpeer-reviewmanuscriptworkshopjournal (of|editor)inclusive researchabstractopen-accessupcoming editiontitle of (your (work|published article)|the study)your paper's titleand the abstractabstract of (your work|the study)detailed abstractcontribution\baccepted papersubmit.{0,20}.(manuscript|article)call for editorialreviewer teamreview.{0,15}.(journal|issue)
strings.replace_confusables(body.current_thread.text) matches any of 12 patterns
your\s+(article|paper|research|publication|work)\s+"?[^"]+?"?\s+(is\s+very\s+excellent|strongly\s+reflects|will\s+be\s+a\s+valuable)we\s+believe\s+(that\s+)?your\s+(experience|perspective|expertise|comments?)\s+(will\s+add|can\s+play|will\s+be)\s+.{0,100}(important|valuable)(you\s+are\s+one\s+of\s+the\s+leading\s+experts?|someone\s+of\s+your\s+caliber)(emerging\s+voices?\s+like\s+yours|shape\s+the\s+scholarly\s+direction)(learning\s+from\s+the\s+internet|know\s+your\s+"[^"]+"\s+is\s+very\s+excellent)(world's|global|international)\s+(foremost|leading|top|premier)\s+(authorities|experts|researchers)your\s+(participation|contribution|presence|involvement)\s+(would\s+be|is)\s+(highly|greatly|immensely|extremely)\s+(valued|appreciated|welcomed)(short\s+notice|busy\s+schedule|quick\s+turnaround|urgent\s+deadline|limited\s+slots)(no\s+charge|free\s+of\s+charge|waived\s+fee|complimentary|at\s+no\s+cost)(topic\s+of\s+your\s+choice|any\s+topic\s+related|broad\s+range\s+of\s+topics|multidisciplinary\s+approach)(guaranteed\s+publication|fast\s+track\s+review|expedited\s+process|will\s+not\s+be\s+too\s+time-consuming)(do\s+hope\s+you\s+can\s+make\s+time|kindly\s+submit|gentle\s+reminder|esteemed\s+researcher)
all of:
- strings.icontains(body.current_thread.text)
not:
- strings.icontains(body.current_thread.text)
not:
any of
recipients.towhere:- strings.icontains(body.current_thread.text)
- length(mailbox.last_name) > 4
- strings.icontains(body.current_thread.text)
- network.whois(sender.email.domain).days_old < 90
any of
body.linkswhere:- network.whois(.href_url.domain).days_old < 90
any of
body.linkswhere all hold:- .href_url.domain.root_domain is 'doi.org'
- .href_url.path starts with '/10.29328'
all of:
- length(body.previous_threads) > 0
any of
regex.iextract(body.html.display_text)where:- strings.parse_email(.named_groups['email_address']).email is not sender.email.email
- headers.message_id contains '@DESKTOP-'
all of:
- body.current_thread.text matches '*review*'
body.current_thread.text matches any of 2 patterns
*manuscript**submission*
- network.whois(sender.email.domain).registrant_country_code is 'CN'
any of
body.linkswhere:- network.whois(.href_url.domain).registrant_country_code is 'CN'
any of
headers.domainswhere:- .root_domain in ('aliyun.com', 'aliyun-inc.com')
- sender.email.domain.root_domain in ('iris-research.net', 'irispublishers.com', 'lidsen.com')
all of:
- length(body.links) > 0
all of
body.linkswhere all hold:all of:
- network.whois(.href_url.domain).registrant_company is network.whois(sender.email.domain).registrant_company
- network.whois(.href_url.domain).registrar_name is network.whois(sender.email.domain).registrar_name
- .href_url.domain.root_domain is not sender.email.domain.root_domain
any of
body.linkswhere:- .href_url.path matches '^/ey[a-z]/.{2,}$'
not:
all of:
- sender.email.email is 'quarantine@messaging.microsoft.com'
any of:
- headers.auth_summary.dmarc.pass
all of:
not:
- coalesce(headers.auth_summary.dmarc.pass)
any of
headers.hopswhere all hold:- .index is 0
any of
.fieldswhere all hold:- .name is 'X-MS-Exchange-CrossTenant-AuthAs'
- .value is 'Internal'
Inspects: body.current_thread.text, body.html.display_text, body.links, body.links[].href_url.domain, body.links[].href_url.domain.root_domain, body.links[].href_url.path, body.previous_threads, headers.auth_summary.dmarc.pass, headers.domains, headers.domains[].root_domain, headers.hops, headers.hops[].fields, headers.hops[].fields[].name, headers.hops[].fields[].value, headers.hops[].index, headers.message_id, mailbox.first_name, mailbox.last_name, recipients.to, recipients.to[].email.email, sender.email.domain, sender.email.domain.root_domain, sender.email.email, type.inbound. Sensors: beta.ml_topic, ml.nlu_classifier, network.whois, regex.count, regex.icontains, regex.iextract, regex.imatch, strings.concat, strings.contains, strings.icontains, strings.ilike, strings.istarts_with, strings.parse_email, strings.replace_confusables.
Indicators matched (51)
| Field | Match | Value |
|---|---|---|
beta.ml_topic(body.current_thread.text).topics[].name | equals | Educational and Research |
beta.ml_topic(body.current_thread.text).topics[].confidence | member | medium |
beta.ml_topic(body.current_thread.text).topics[].confidence | member | high |
regex.count | regex | [Æ×æı-ijʼnŒœƁƄƇƊƍƓƖƘƠơƤƦƧƬƳƷƼƽǀǁLJ-njDZ-dzȜȢȣɑɡɣɩɪɯʋʏʣʦʪʫ˛ͺͿΑΒΕ-ΗΙΚΜΝΟΡΤΥΧαγινορσυϒϜϨϱ-ϳϹϺЅІЈАВЕЗКМ-ОР-УХЫЬЮабгеорсухѕіјѡѴѵґҮүһҽӀӏӔӕӠԁԌԛ-ԝՍՏՕագզհոռսցքօ׀וטןסװױاه١٥٧ھہە۱۵۷߀ߊ०০৪৭੦੧੪ଠ୦୨ഠ൦๐໐ဝ၀ყჿሀዐᎠ-ᎢᎤᎥᎩ-ᎬᎳᎷᎻᎽᏀᏂᏃᏎᏏᏒᏔᏕᏙᏚᏞᏟᏢᏦᏧᏮᏳᏴᐯᑌᑧᑭᑯᑲᒆ-ᒈᒍᒪᒿᕁᕼᕽᖇᖯᖴᗅᗞᗪᗰᗷ᙭᙮ᚷᛁᛕᛖᴄᴏᴑᴜᴠ-ᴢᴦᵫᶃᶌẝỿι‖₨₶℀-ℂ℅℆ℊ-ℎℐ-ℓℕ№ℙ-ℝ℡ℤℨℬ-ℱℳℴℹ℻ℽⅅ-ⅉⅠ-ⅿ∞∣∥∨∪⊤⋁⋃⋿⍳⍴⍺⏽⑴-⒵╳⟙⤫⤬⨯ⲅⲎⲒⲔⲘⲚⲞⲟⲢ-ⲦⲨⲬⳊⳌⳐⳒⴸⴹⵏⵔⵕⵝ〇ꓐ-ꓔꓖꓗꓙꓚꓜꓝꓟ-ꓣꓦꓧꓪ-ꓬꓮꓰꓲ-ꓴꙄꙇꚘꚙꛟꛯꜨꜱ-ꜽꝎꝏꝚꝪꝮꝷꭵꮁꮃꮓꮩꮪꮯff-fflstﮦ-ﮭﺍﺎﻩ-ﻬA-CEH-KM-PSTX-Zaceg-jlopsvxy│𐊂𐊆𐊇𐊊𐊐𐊒𐊕-𐊗𐊠-𐊢𐊥𐊫𐊰-𐊲𐊴𐋏𐋵𐌁𐌂𐌉𐌑𐌕𐌗𐌚𐌠𐌢𐐄𐐕𐐛𐐠𐐬𐐽𐑈𐒴𐓂𐓎𐓒𐓪𐓶𐔓𐔖𐔘𐔜𐔝𐔥-𐔧𑓐𑜀𑜆𑜊𑜎𑜏𑢠𑢢-𑢤𑢦𑢩𑢬𑢮𑢯𑢲𑢵𑢸𑢻𑢼𑣀-𑣄𑣆𑣈𑣊𑣌𑣕-𑣘𑣜𑣠𑣣𑣥𑣦𑣩𑣬𑣯𑣲𖼈𖼊𖼖𖼨𖼵𖼺𖼻𖽀𖽂𖽃𝐀-𝑔𝑖-𝒜𝒞𝒟𝒢𝒥𝒦𝒩-𝒬𝒮-𝒹𝒻𝒽-𝓃𝓅-𝔅𝔇-𝔊𝔍-𝔔𝔖-𝔜𝔞-𝔹𝔻-𝔾𝕀-𝕄𝕆𝕊-𝕐𝕒-𝚤𝚨𝚩𝚬-𝚮𝚰𝚱𝚳𝚴𝚶𝚸𝚻𝚼𝚾𝛂𝛄𝛊𝛎𝛐𝛒𝛔𝛖𝛠𝛢𝛣𝛦-𝛨𝛪𝛫𝛭𝛮𝛰𝛲𝛵𝛶𝛸𝛼𝛾𝜄𝜈𝜊𝜌𝜎𝜐𝜚𝜜𝜝𝜠-𝜢𝜤𝜥𝜧𝜨𝜪𝜬𝜯𝜰𝜲𝜶𝜸𝜾𝝂𝝄𝝆𝝈𝝊𝝔𝝖𝝗𝝚-𝝜𝝞𝝟𝝡𝝢𝝤𝝦𝝩𝝪𝝬𝝰𝝲𝝸𝝼𝝾𝞀𝞂𝞄𝞎𝞐𝞑𝞔-𝞖𝞘𝞙𝞛𝞜𝞞𝞠𝞣𝞤𝞦𝞪𝞬𝞲𝞶𝞸𝞺𝞼𝞾𝟈𝟊𝟎] |
regex.icontains | regex | Impact Factor |
regex.icontains | regex | Special Issue |
regex.icontains | regex | Guest Editor |
regex.icontains | regex | peer-review |
regex.icontains | regex | manuscript |
regex.icontains | regex | workshop |
regex.icontains | regex | journal (of|editor) |
regex.icontains | regex | inclusive research |
39 more
regex.icontains | regex | abstract |
regex.icontains | regex | open-access |
regex.icontains | regex | upcoming edition |
regex.icontains | regex | title of (your (work|published article)|the study) |
regex.icontains | regex | your paper's title |
regex.icontains | regex | and the abstract |
regex.icontains | regex | abstract of (your work|the study) |
regex.icontains | regex | detailed abstract |
regex.icontains | regex | contribution\b |
regex.icontains | regex | accepted paper |
regex.icontains | regex | submit.{0,20}.(manuscript|article) |
regex.icontains | regex | call for editorial |
regex.icontains | regex | reviewer team |
regex.icontains | regex | review.{0,15}.(journal|issue) |
regex.icontains | regex | your\s+(article|paper|research|publication|work)\s+"?[^"]+?"?\s+(is\s+very\s+excellent|strongly\s+reflects|will\s+be\s+a\s+valuable) |
regex.icontains | regex | we\s+believe\s+(that\s+)?your\s+(experience|perspective|expertise|comments?)\s+(will\s+add|can\s+play|will\s+be)\s+.{0,100}(important|valuable) |
regex.icontains | regex | (you\s+are\s+one\s+of\s+the\s+leading\s+experts?|someone\s+of\s+your\s+caliber) |
regex.icontains | regex | (emerging\s+voices?\s+like\s+yours|shape\s+the\s+scholarly\s+direction) |
regex.icontains | regex | (learning\s+from\s+the\s+internet|know\s+your\s+"[^"]+"\s+is\s+very\s+excellent) |
regex.icontains | regex | (world's|global|international)\s+(foremost|leading|top|premier)\s+(authorities|experts|researchers) |
regex.icontains | regex | your\s+(participation|contribution|presence|involvement)\s+(would\s+be|is)\s+(highly|greatly|immensely|extremely)\s+(valued|appreciated|welcomed) |
regex.icontains | regex | (short\s+notice|busy\s+schedule|quick\s+turnaround|urgent\s+deadline|limited\s+slots) |
regex.icontains | regex | (no\s+charge|free\s+of\s+charge|waived\s+fee|complimentary|at\s+no\s+cost) |
regex.icontains | regex | (topic\s+of\s+your\s+choice|any\s+topic\s+related|broad\s+range\s+of\s+topics|multidisciplinary\s+approach) |
regex.icontains | regex | (guaranteed\s+publication|fast\s+track\s+review|expedited\s+process|will\s+not\s+be\s+too\s+time-consuming) |
regex.icontains | regex | (do\s+hope\s+you\s+can\s+make\s+time|kindly\s+submit|gentle\s+reminder|esteemed\s+researcher) |
body.links[].href_url.domain.root_domain | equals | doi.org |
strings.istarts_with | prefix | /10.29328 |
regex.iextract | regex | From: (?P<email_address>\S*) |
strings.contains | substring | @DESKTOP- |
strings.ilike | substring | *review* |
strings.ilike | substring | *manuscript* |
strings.ilike | substring | *submission* |
headers.domains[].root_domain | member | aliyun.com |
headers.domains[].root_domain | member | aliyun-inc.com |
sender.email.domain.root_domain | member | iris-research.net |
sender.email.domain.root_domain | member | irispublishers.com |
sender.email.domain.root_domain | member | lidsen.com |
regex.imatch | regex | ^/ey[a-z]/.{2,}$ |
Stages and Predicates
Stage 1: mql_rule
and
not
and
or
and
any(headers.hops)
and
any(headers.hops.fields)
and
headers.hops.fields[].name eq "X-MS-Exchange-CrossTenant-AuthAs"
headers.hops.fields[].value eq "Internal"
headers.hops.index eq "0"
not
coalesce func_call "coalesce(headers.auth_summary.dmarc.pass)"
headers.auth_summary.dmarc.pass eq "true"
sender.email.email eq "quarantine@messaging.microsoft.com"
or
and
not
any(recipients.to)
strings.icontains func_call "strings.icontains(body.current_thread.text)"
not
strings.icontains func_call "strings.icontains(body.current_thread.text)"
mailbox.last_name length_compare "4"
strings.icontains func_call "strings.icontains(body.current_thread.text)"
and
or
body.current_thread.text match "manuscript"
body.current_thread.text match "submission"
body.current_thread.text match "review"
any(body.links)
and
body.links.href_url.domain.root_domain eq "doi.org"
body.links.href_url.path starts_with "/10.29328"
and
any(regex.iextract(body.html.display_text))
strings.parse_email func_call "strings.parse_email(regex.iextract(body.html.display_text)[].named_groups['email_address']).email != sender.email.email"
body.previous_threads length_compare "0"
and
body.links length_compare "0"
macro "all(body.links)"
any(body.links)
body.links.href_url.path regex_match "^/ey[a-z]/.{2,}$"
any(headers.domains)
headers.domains.root_domain in ["aliyun-inc.com", "aliyun.com"]
any(body.links)
network.whois func_call "network.whois(body.links[].href_url.domain).days_old < 90"
any(body.links)
network.whois func_call "network.whois(body.links[].href_url.domain).registrant_country_code == CN"
headers.message_id contains "@DESKTOP-"
network.whois func_call "network.whois(sender.email.domain).days_old < 90"
network.whois func_call "network.whois(sender.email.domain).registrant_country_code == CN"
regex.count func_call "regex.count(body.current_thread.text, \"[Æ×æı-ijʼnŒœƁƄƇƊƍƓƖƘƠơƤƦƧƬƳƷƼƽǀǁLJ-njDZ-dzȜȢȣɑɡɣɩɪɯʋʏʣʦʪʫ˛ͺͿΑΒΕ-ΗΙΚΜΝΟΡΤΥΧαγινορσυϒϜϨϱ-ϳϹϺЅІЈАВЕЗКМ-ОР-УХЫЬЮабгеорсухѕіјѡѴѵґҮүһҽӀӏӔӕӠԁԌԛ-ԝՍՏՕագզհոռսցքօ׀וטןסװױاه١٥٧ھہە۱۵۷߀ߊ०০৪৭੦੧੪ଠ୦୨ഠ൦๐໐ဝ၀ყჿሀዐᎠ-ᎢᎤᎥᎩ-ᎬᎳᎷᎻᎽᏀᏂᏃᏎᏏᏒᏔᏕᏙᏚᏞᏟᏢᏦᏧᏮᏳᏴᐯᑌᑧᑭᑯᑲᒆ-ᒈᒍᒪᒿᕁᕼᕽᖇᖯᖴᗅᗞᗪᗰᗷ᙭᙮ᚷᛁᛕᛖᴄᴏᴑᴜᴠ-ᴢᴦᵫᶃᶌẝỿι‖₨₶℀-ℂ℅℆ℊ-ℎℐ-ℓℕ№ℙ-ℝ℡ℤℨℬ-ℱℳℴℹ℻ℽⅅ-ⅉⅠ-ⅿ∞∣∥∨∪⊤⋁⋃⋿⍳⍴⍺⏽⑴-⒵╳⟙⤫⤬⨯ⲅⲎⲒⲔⲘⲚⲞⲟⲢ-ⲦⲨⲬⳊⳌⳐⳒⴸⴹⵏⵔⵕⵝ〇ꓐ-ꓔꓖꓗꓙꓚꓜꓝꓟ-ꓣꓦꓧꓪ-ꓬꓮꓰꓲ-ꓴꙄꙇꚘꚙꛟꛯꜨꜱ-ꜽꝎꝏꝚꝪꝮꝷꭵꮁꮃꮓꮩꮪꮯff-fflstﮦ-ﮭﺍﺎﻩ-ﻬA-CEH-KM-PSTX-Zaceg-jlopsvxy│𐊂𐊆𐊇𐊊𐊐𐊒𐊕-𐊗𐊠-𐊢𐊥𐊫𐊰-𐊲𐊴𐋏𐋵𐌁𐌂𐌉𐌑𐌕𐌗𐌚𐌠𐌢𐐄𐐕𐐛𐐠𐐬𐐽𐑈𐒴𐓂𐓎𐓒𐓪𐓶𐔓𐔖𐔘𐔜𐔝𐔥-𐔧𑓐𑜀𑜆𑜊𑜎𑜏𑢠𑢢-𑢤𑢦𑢩𑢬𑢮𑢯𑢲𑢵𑢸𑢻𑢼𑣀-𑣄𑣆𑣈𑣊𑣌𑣕-𑣘𑣜𑣠𑣣𑣥𑣦𑣩𑣬𑣯𑣲𖼈𖼊𖼖𖼨𖼵𖼺𖼻𖽀𖽂𖽃𝐀-𝑔𝑖-𝒜𝒞𝒟𝒢𝒥𝒦𝒩-𝒬𝒮-𝒹𝒻𝒽-𝓃𝓅-𝔅𝔇-𝔊𝔍-𝔔𝔖-𝔜𝔞-𝔹𝔻-𝔾𝕀-𝕄𝕆𝕊-𝕐𝕒-𝚤𝚨𝚩𝚬-𝚮𝚰𝚱𝚳𝚴𝚶𝚸𝚻𝚼𝚾𝛂𝛄𝛊𝛎𝛐𝛒𝛔𝛖𝛠𝛢𝛣𝛦-𝛨𝛪𝛫𝛭𝛮𝛰𝛲𝛵𝛶𝛸𝛼𝛾𝜄𝜈𝜊𝜌𝜎𝜐𝜚𝜜𝜝𝜠-𝜢𝜤𝜥𝜧𝜨𝜪𝜬𝜯𝜰𝜲𝜶𝜸𝜾𝝂𝝄𝝆𝝈𝝊𝝔𝝖𝝗𝝚-𝝜𝝞𝝟𝝡𝝢𝝤𝝦𝝩𝝪𝝬𝝰𝝲𝝸𝝼𝝾𝞀𝞂𝞄𝞎𝞐𝞑𝞔-𝞖𝞘𝞙𝞛𝞜𝞞𝞠𝞣𝞤𝞦𝞪𝞬𝞲𝞶𝞸𝞺𝞼𝞾𝟈𝟊𝟎]\") > 100"
sender.email.domain.root_domain in ["iris-research.net", "irispublishers.com", "lidsen.com"]
strings.icontains func_call "strings.icontains(body.current_thread.text)"
strings.replace_confusables(body.current_thread.text) regex_match "(do\\s+hope\\s+you\\s+can\\s+make\\s+time|kindly\\s+submit|gentle\\s+reminder|esteemed\\s+researcher)"
strings.replace_confusables(body.current_thread.text) regex_match "(emerging\\s+voices?\\s+like\\s+yours|shape\\s+the\\s+scholarly\\s+direction)"
strings.replace_confusables(body.current_thread.text) regex_match "(guaranteed\\s+publication|fast\\s+track\\s+review|expedited\\s+process|will\\s+not\\s+be\\s+too\\s+time-consuming)"
strings.replace_confusables(body.current_thread.text) regex_match "(learning\\s+from\\s+the\\s+internet|know\\s+your\\s+\"[^\"]+\"\\s+is\\s+very\\s+excellent)"
strings.replace_confusables(body.current_thread.text) regex_match "(no\\s+charge|free\\s+of\\s+charge|waived\\s+fee|complimentary|at\\s+no\\s+cost)"
strings.replace_confusables(body.current_thread.text) regex_match "(short\\s+notice|busy\\s+schedule|quick\\s+turnaround|urgent\\s+deadline|limited\\s+slots)"
strings.replace_confusables(body.current_thread.text) regex_match "(topic\\s+of\\s+your\\s+choice|any\\s+topic\\s+related|broad\\s+range\\s+of\\s+topics|multidisciplinary\\s+approach)"
strings.replace_confusables(body.current_thread.text) regex_match "(world's|global|international)\\s+(foremost|leading|top|premier)\\s+(authorities|experts|researchers)"
strings.replace_confusables(body.current_thread.text) regex_match "(you\\s+are\\s+one\\s+of\\s+the\\s+leading\\s+experts?|someone\\s+of\\s+your\\s+caliber)"
strings.replace_confusables(body.current_thread.text) regex_match "Guest Editor"
strings.replace_confusables(body.current_thread.text) regex_match "Impact Factor"
strings.replace_confusables(body.current_thread.text) regex_match "Special Issue"
strings.replace_confusables(body.current_thread.text) regex_match "abstract of (your work|the study)"
strings.replace_confusables(body.current_thread.text) regex_match "abstract"
strings.replace_confusables(body.current_thread.text) regex_match "accepted paper"
strings.replace_confusables(body.current_thread.text) regex_match "and the abstract"
strings.replace_confusables(body.current_thread.text) regex_match "call for editorial"
strings.replace_confusables(body.current_thread.text) regex_match "contribution\\b"
strings.replace_confusables(body.current_thread.text) regex_match "detailed abstract"
strings.replace_confusables(body.current_thread.text) regex_match "inclusive research"
strings.replace_confusables(body.current_thread.text) regex_match "journal (of|editor)"
strings.replace_confusables(body.current_thread.text) regex_match "manuscript"
strings.replace_confusables(body.current_thread.text) regex_match "open-access"
strings.replace_confusables(body.current_thread.text) regex_match "peer-review"
strings.replace_confusables(body.current_thread.text) regex_match "review.{0,15}.(journal|issue)"
strings.replace_confusables(body.current_thread.text) regex_match "reviewer team"
strings.replace_confusables(body.current_thread.text) regex_match "submit.{0,20}.(manuscript|article)"
strings.replace_confusables(body.current_thread.text) regex_match "title of (your (work|published article)|the study)"
strings.replace_confusables(body.current_thread.text) regex_match "upcoming edition"
strings.replace_confusables(body.current_thread.text) regex_match "we\\s+believe\\s+(that\\s+)?your\\s+(experience|perspective|expertise|comments?)\\s+(will\\s+add|can\\s+play|will\\s+be)\\s+.{0,100}(important|valuable)"
strings.replace_confusables(body.current_thread.text) regex_match "workshop"
strings.replace_confusables(body.current_thread.text) regex_match "your paper's title"
strings.replace_confusables(body.current_thread.text) regex_match "your\\s+(article|paper|research|publication|work)\\s+\"?[^\"]+?\"?\\s+(is\\s+very\\s+excellent|strongly\\s+reflects|will\\s+be\\s+a\\s+valuable)"
strings.replace_confusables(body.current_thread.text) regex_match "your\\s+(participation|contribution|presence|involvement)\\s+(would\\s+be|is)\\s+(highly|greatly|immensely|extremely)\\s+(valued|appreciated|welcomed)"
not
any(beta.ml_topic(body.current_thread.text).topics)
and
beta.ml_topic(body.current_thread.text).topics.confidence eq "high"
beta.ml_topic(body.current_thread.text).topics.name eq "Health and Wellness"
any(beta.ml_topic(body.current_thread.text).topics)
and
beta.ml_topic(body.current_thread.text).topics.confidence in ["high", "medium"]
beta.ml_topic(body.current_thread.text).topics.name eq "Educational and Research"
ml.nlu_classifier func_call "ml.nlu_classifier(body.current_thread.text).language == english"
type.inbound eq "true"Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
headers.hops | array_any | excludes:headers.hops | |
headers.auth_summary.dmarc.pass | eq | true | excludes:headers.auth_summary.dmarc.pass field:"headers.auth_summary.dmarc.pass" value:"true" |
sender.email.email | eq | quarantine@messaging.microsoft.com | excludes:sender.email.email field:"sender.email.email" value:"quarantine@messaging.microsoft.com" |
beta.ml_topic(body.current_thread.text).topics | array_any | excludes:beta.ml_topic(body.current_thread.text).topics |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
body.current_thread.text | wildcard |
| field:"body.current_thread.text" kind:wildcard |
headers.message_id | contains |
| field:"headers.message_id" kind:contains value:"@DESKTOP-" |
sender.email.domain.root_domain | in |
| field:"sender.email.domain.root_domain" kind:in |
strings.replace_confusables(body.current_thread.text) | regex_match |
| field:"strings.replace_confusables(body.current_thread.text)" kind:regex_match |
type.inbound | eq |
| field:"type.inbound" kind:eq value:"true" |