Attachment: ICS voicemail lure with suspicious link
Detects inbound emails containing an ICS calendar attachment whose event description mimics a voicemail notification (e.g., 'new voicemail', 'listen to your voicemail') and includes a link pointing to a free file hosting service, self-service creation platform, URL shortener, suspicious TLD, or a domain registered within the last 90 days. Excludes messages from high-trust sender domains that pass DMARC authentication.
Sublime rule (View on GitHub)
1name: "Attachment: ICS voicemail lure with suspicious link"
2description: "Detects inbound emails containing an ICS calendar attachment whose event description mimics a voicemail notification (e.g., 'new voicemail', 'listen to your voicemail') and includes a link pointing to a free file hosting service, self-service creation platform, URL shortener, suspicious TLD, or a domain registered within the last 90 days. Excludes messages from high-trust sender domains that pass DMARC authentication."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and any(attachments,
8 (
9 .file_type == "ics"
10 or .file_extension == "ics"
11 or .content_type in ("application/ics", "text/calendar")
12 )
13 and any(beta.file.parse_ics(.).events,
14 // voicemail key words
15 any([.summary, .description],
16 regex.icontains(.,
17 '(?:voice\s*mail|voice\s*message|audio\s*message).{0,20}(?:notification|recording|arriv|receiv|waiting|await|pending|available|unheard|ready|logged|in\s+your|from\s+your\s+inbox)|(?:new|pending|unheard|missed|confidential)\s+(?:voice\s*mail|voice\s*message|audio\s*message)|you\s+(?:have|received)\s+a(?:\s+new\s+voice|.{0,30}voice\s*(?:mail|message))|listen\s+to\s+(?:your\s+)?voice\s*mail|listen\s+(?:to\s+)?(?:the|this|your)\s+message|message\s+to\s+listen|wireless\s*caller|audio\s*file|check\s+(?:your\s+)?voice\s*mail|(?:google\s+)?voice\s*mail\s+(?:google\s+voice|google)|google\s+voice\s*mail|voice\s*(?:mail|message)\s+[0-9]{1,2}:[0-9]{2}|duration:\s*[0-9]{1,2}:[0-9]{2}\s*sec'
18 )
19 )
20 // sus link
21 and any(.links,
22 .href_url.domain.root_domain in $free_file_hosts
23 or .href_url.domain.domain in $free_file_hosts
24 or .href_url.domain.root_domain in $self_service_creation_platform_domains
25 or .href_url.domain.domain in $self_service_creation_platform_domains
26 or .href_url.domain.tld in $suspicious_tlds
27 or .href_url.domain.domain in $url_shorteners
28 or .href_url.domain.root_domain in $url_shorteners
29 or network.whois(.href_url.domain).days_old < 90
30 or strings.icontains(.display_url.url, "voicemail")
31 or strings.icontains(.display_text, "voicemail", "wav")
32 // minimal js landing page
33 or length(filter(ml.link_analysis(., mode="aggressive").unique_urls_accessed,
34 .url == ..href_url.url
35 or (
36 strings.starts_with(.url,
37 ..href_url.url
38 )
39 and regex.icontains(.url,
40 '[a-z]{3,}\.[0-9a-f]{20}\.js'
41 )
42 )
43 or .url == strings.concat(..href_url.url,
44 'favicon.png'
45 )
46 )
47 ) == 3
48 or any(html.xpath(ml.link_analysis(., mode="aggressive").final_dom,
49 "//script"
50 ).nodes,
51 regex.icontains(.raw,
52 'setTimeout[\s\S]{0,100}window\.location\.href[\s\S]{0,100},\s*3000'
53 )
54 )
55 or ml.link_analysis(., mode="aggressive").effective_url.domain.root_domain in (
56 'workers.dev'
57 )
58 )
59 )
60 )
61 and not (
62 sender.email.domain.root_domain in $high_trust_sender_root_domains
63 and coalesce(headers.auth_summary.dmarc.pass, false)
64 )
65attack_types:
66 - "ICS Phishing"
67 - "Credential Phishing"
68tactics_and_techniques:
69 - "Social engineering"
70 - "Free file host"
71 - "Evasion"
72detection_methods:
73 - "File analysis"
74 - "Content analysis"
75 - "URL analysis"
76 - "Whois"
77 - "Header analysis"
78id: "ef6082ce-1073-570e-b04d-abac1652ec82"