Sublime Security medium experimental mql

Advance Fee Fraud (AFF) from freemail provider or suspicious TLD

Advance Fee Fraud (AFF) is a type of BEC/Fraud involving upfront fees for promised future returns, such as lottery scams, inheritance payouts, and investment opportunities. This rule identifies messages from Freemail domains or suspicious TLDS, including those with suspicious reply-to addresses. It utilizes Natural Language Understanding to detect AFF language in their contents.

View Source

Detection Logic

type.inbound
and (
  sender.email.domain.domain in $free_email_providers
  or (
    length(headers.reply_to) > 0
    and all(headers.reply_to,
            (
              .email.domain.root_domain in $free_email_providers
              or .email.domain.tld in $suspicious_tlds
              or (
                network.whois(.email.domain).days_old < 365
                and length(coalesce(body.html.raw, "")) == 0
              )
            )
            and .email.email != sender.email.email
    )
  )
  or sender.email.domain.tld in $suspicious_tlds
  or any(["jp", "jo"], strings.iends_with(sender.email.domain.tld, .))
  or (
    length(recipients.to) == 0
    and any(headers.reply_to,
            .email.domain.root_domain != sender.email.domain.root_domain
    )
  )
)
and (
  any(ml.nlu_classifier(body.current_thread.text).intents,
      .name == "advance_fee" and .confidence in ("medium", "high")
  )
  or (
    length(body.current_thread.text) < 200
    and regex.icontains(body.current_thread.text,
                        '(?:donation
| inheritence
| \$\d,\d{3}\,\d{3}
| lottery)'
    )
    and not regex.icontains(body.current_thread.text,
                            '(?:closed.{0,50})?\$\d,\d{3}\,\d{3}.{0,100}(?:homes
| realty
| sale)?'
    )
    and not any(body.links,
                regex.icontains(.href_url.url,
                                '(?:donation
| inheritence
| \$\d,\d{3}\,\d{3}
| lottery)'
                )
    )
    and (
      (
        (length(headers.references) > 0 or headers.in_reply_to is null)
        and not (
          (
            strings.istarts_with(subject.subject, "RE:")
            // out of office auto-reply
            or strings.istarts_with(subject.subject, "Automatic reply:")
            or strings.istarts_with(subject.subject, "R:")
            or strings.istarts_with(subject.subject, "ODG:")
            or strings.istarts_with(subject.subject, "答复:")
            or strings.istarts_with(subject.subject, "AW:")
            or strings.istarts_with(subject.subject, "TR:")
            or strings.istarts_with(subject.subject, "FWD:")
            or regex.icontains(subject.subject,
                               '^(\[[^\]]+\]\s?){0,3}(re
| fwd?)\s?:'
            )
          )
        )
      )
      or any(headers.reply_to, .email.email != sender.email.email)
    )
  )
)
and (
  not profile.by_sender().solicited
  or profile.by_sender().any_messages_malicious_or_spam
)
and not profile.by_sender().any_messages_benign

Field Validations

Loading…

Comments (0)

Loading comments...