Sublime Security high experimental mql

Attachment: HTML smuggling with excessive line break obfuscation

Credential Phishing attacks have been observed using excessive line breaks to obfuscate javascript functions within html files.

View Source

Detection Logic

type.inbound
and any(attachments,
        (
          .file_extension in~ ("html", "htm", "shtml", "dhtml")
          or .file_extension in~ $file_extensions_common_archives
          or .file_type == "html"
        )
        and any(file.explode(.),
                any(.scan.strings.strings,
                    // return new line padded obfuscation 
                    regex.contains(., '(\\r\\n\S{2}){50,}')
                    and strings.contains(., 'decodeURIComponent')
                )
        )
)

Field Validations

Loading…

Comments (0)

Loading comments...