Attachment: HTML with hidden body
This rule identifies HTML attachments which begin directly with a hidden body element. This has been observed in phishing campaigns to hide the content of an otherwise benign HTML attachment that then has remote content injected into the body.
Sublime rule (View on GitHub)
1name: "Attachment: HTML with hidden body"
2description: "This rule identifies HTML attachments which begin directly with a hidden body element. This has been observed in phishing campaigns to hide the content of an otherwise benign HTML attachment that then has remote content injected into the body."
3type: "rule"
4severity: "high"
5source: |
6 type.inbound
7 and not profile.by_sender().solicited
8 // not high trust sender domains
9 and not (
10 sender.email.domain.root_domain in $high_trust_sender_root_domains
11 and coalesce(headers.auth_summary.dmarc.pass, false)
12 )
13 and any(attachments,
14 .file_extension == "html"
15 // starts with the hidden body element
16 and regex.icontains(file.parse_html(.).raw,
17 '^<body style\s*=\s*"\s*display\s*:\s*none\s*;\s*">'
18 )
19 )
20attack_types:
21 - "Credential Phishing"
22tactics_and_techniques:
23 - "Evasion"
24 - "Scripting"
25detection_methods:
26 - "Content analysis"
27 - "HTML analysis"
28 - "File analysis"
29id: "b059a781-b681-5c84-98ba-416deb165555"