Credential phishing: Suspicious e-sign agreement document notification

Detects phishing attempts disguised as e-signature requests, characterized by common document sharing phrases, unusual HTML padding, and suspicious link text.

Sublime rule (View on GitHub)

  1name: "Credential phishing: Suspicious e-sign agreement document notification"
  2description: "Detects phishing attempts disguised as e-signature requests, characterized by common document sharing phrases, unusual HTML padding, and suspicious link text."
  3type: "rule"
  4severity: "medium"
  5source: |
  6  type.inbound
  7  and (
  8    any([subject.subject, sender.display_name],
  9        regex.icontains(strings.replace_confusables(.),
 10                        "D[0o]cuLink",
 11                        "Agreement",
 12                        "Access.&.Appr[0o]ved",
 13                        "Agreement.{0,5}Review",
 14                        "Attend.and.Review",
 15                        "action.re?quired",
 16                        "AuthentiSign",
 17                        "Completed.File",
 18                        "D[0o]chsared",
 19                        "D[0o]cshared",
 20                        "D[0o]csPoint",
 21                        "D[0o]cument.Shared",
 22                        "D[0o]cuCentre",
 23                        "D[0o]cuCenter",
 24                        "D[0o]cCenter",
 25                        "D[0o]csOnline",
 26                        "D[0o]cSend",
 27                        "D[0o]cu?Send",
 28                        "d[0o]csign",
 29                        "D[0o]cu-eSin",
 30                        "D[0o]cu-management",
 31                        "\\beSign",
 32                        "e\\.sign",
 33                        "esign.[0o]nline",
 34                        "[SsZz][lL][GgSs][Nn].*D[0o]c",
 35                        "e-d[0o]c",
 36                        "e-signature",
 37                        "e-Verify Doc",
 38                        "eSignature",
 39                        "eSign&Return",
 40                        "eSign[0o]nline",
 41                        "Fileshare",
 42                        "Review.and.C[0o]mplete",
 43                        "Review.&.Sign",
 44                        "Sign[0o]nline",
 45                        "Signature.Request",
 46                        "Shared.C[0o]mpleted",
 47                        "Sign.and.Seal",
 48                        "viaSign",
 49                        "D[0o]cuSign",
 50                        "D[0o]csID",
 51                        "Complete.{0,10}D[0o]cuSign",
 52                        "Enroll & Sign",
 53                        "Review and Sign",
 54                        "Sign(?:Report|Now)",
 55                        "SignD[0o]c",
 56                        "D[0o]cxxx",
 57                        "d[0o]cufile",
 58                        'E\x{00AD}-\x{00AD}S\x{00AD}i\x{00AD}g\x{00AD}n\x{00AD}&Return',
 59                        "d[0o]cument.signature",
 60                        "Electr[0o]nic.?Signature",
 61                        "Complete: ",
 62                        "Please (?:Review|Sign)",
 63                        "^REVIEW$",
 64                        "requests your signature",
 65                        "signature on.*contract",
 66                        "Independent Contract",
 67                        "Contract.*signature",
 68                        "add your signature",
 69                        "signature needed",
 70                        "attn_task",
 71                        "DocReq\\b",
 72                        "noreply_edocx-task[0-9a-f-]{36}",
 73                        "securesign delivery"
 74        )
 75        or (
 76          regex.icontains(strings.replace_confusables(.), "action.re?quired")
 77          and not (
 78            sender.email.domain.root_domain == "sharepointonline.com"
 79            and headers.auth_summary.dmarc.pass
 80            and strings.icontains(subject.subject, "asked to edit")
 81          )
 82        )
 83    )
 84    // lure CTA injected into the body (not subject/display) above a forwarded thread
 85    or (
 86      regex.icontains(strings.replace_confusables(body.current_thread.text),
 87                      "requests? your signature",
 88                      "review, sign, and return",
 89                      "signature on the attached"
 90      )
 91      // legit "please sign & return" mail attaches the actual document; this
 92      // campaign references an "attached" doc but delivers a fake one via an
 93      // off-domain link, with no real document attached
 94      and not any(attachments,
 95                  .file_extension in~ ("pdf", "doc", "docx", "xls", "xlsx", "rtf")
 96      )
 97      // legit notification platforms (e.g. ParentSquare, Panopto) self-host their
 98      // "review/sign/view" CTA on the sender's own root domain; this campaign points
 99      // the CTA at an off-domain credential page. require a suspicious link whose
100      // display text is a document CTA AND that leaves the sender domain, so
101      // self-hosted legit notifications (and incidental links like the aka.ms
102      // first-contact banner, which carries no CTA verb) don't match.
103      and any(body.links,
104              .href_url.domain.root_domain is not null
105              and .href_url.domain.root_domain != sender.email.domain.root_domain
106              and regex.icontains(strings.replace_confusables(.display_text),
107                                  "view",
108                                  "review",
109                                  "sign",
110                                  "document",
111                                  "download",
112                                  "open",
113                                  "complete"
114              )
115      )
116    )
117  )
118  and (
119    // unusual repeated patterns in HTML
120    regex.icontains(body.html.raw, '((<br\s*/?>\s*){20,}|\n{20,})')
121    or regex.icontains(body.html.raw, '(<p[^>]*>\s*<br\s*/?>\s*</p>\s*){30,}')
122    or regex.icontains(body.html.raw,
123                       '(<p class=".*?"><span style=".*?"><o:p>&nbsp;</o:p></span></p>\s*){30,}'
124    )
125    or regex.icontains(body.html.raw, '(<p>&nbsp;</p>\s*){7,}')
126    or regex.icontains(body.html.raw, '(<p[^>]*>\s*&nbsp;<br>\s*</p>\s*){5,}')
127    or regex.icontains(body.html.raw, '(<p[^>]*>&nbsp;</p>\s*){7,}')
128    or strings.count(body.html.raw, "&nbsp;\u{200C}&nbsp;\u{200C}&nbsp") > 50
129    or regex.count(body.html.raw,
130                   '<span\s*class\s*=\s*"[^\"]+"\s*>\s*[a-z]\s*<\/span><span\s*class\s*=\s*"[^\"]+"\s*>\s*[a-z]+\s*<\/span>'
131    ) > 50
132    // lookalike docusign
133    or regex.icontains(body.html.raw, '>Docus[1l]gn<')
134    or strings.icontains(body.current_thread.text, 'completed by all parties')
135    or (
136      regex.icontains(body.html.inner_text, 'Document')
137      and length(body.html.inner_text) < 500
138    )
139    // common greetings via email.local_part
140    or any(recipients.to,
141           // use count to ensure the email address is not part of a disclaimer
142           strings.icount(body.current_thread.text, .email.local_part) > 
143           // sum allows us to add more logic as needed
144           sum([
145                 strings.icount(body.current_thread.text,
146                                strings.concat('was sent to ', .email.email)
147                 ),
148                 strings.icount(body.current_thread.text,
149                                strings.concat('intended for ', .email.email)
150                 )
151               ]
152           )
153    )
154    // common greetings via mailbox display name
155    or strings.icount(body.current_thread.text, mailbox.display_name) > 
156    // sum allows us to add more logic as needed
157    sum([
158          strings.icount(body.current_thread.text,
159                         strings.concat('was sent to ', mailbox.display_name)
160          ),
161          strings.icount(body.current_thread.text,
162                         strings.concat('intended for ', mailbox.display_name)
163          )
164        ]
165    )
166    // Abnormally high count of mailto links in raw html
167    or regex.count(body.html.raw,
168                   'mailto:[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}'
169    ) > 50
170  
171    // High count of empty elements (padding)
172    or regex.count(body.html.raw,
173                   '<(?:p|div|span|td)[^>]*>\s*(?:&nbsp;|\s)*\s*</(?:p|div|span|td)>'
174    ) > 30
175  
176    // HR impersonation
177    or strings.ilike(sender.display_name, "HR", "H?R", "*Human Resources*")
178  
179    // Sender display name contains a phone number
180    or regex.icontains(sender.display_name,
181                       '\+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4}'
182    )
183  
184    // short CTA grafted above a forwarded legitimate thread to borrow its credibility
185    or (
186      length(body.previous_threads) > 0 and length(body.current_thread.text) < 600
187    )
188  )
189  and (
190    any(body.links,
191  
192        // suspicious content within link display_text
193        regex.icontains(strings.replace_confusables(.display_text),
194                        "activate",
195                        "re-auth",
196                        "verify",
197                        "acknowledg",
198                        "(keep|change).{0,20}(active|password|access)",
199                        '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
200                        'use.same.pass',
201                        'validate.{0,15}account',
202                        'recover.{0,15}messages',
203                        '(retry|update).{0,10}payment',
204                        'check activity',
205                        '(listen|play).{0,10}(vm|voice)',
206                        'clarify.{0,20}(deposit|wallet|funds)',
207                        'enter.{0,15}teams',
208                        'Review and sign',
209                        'REVIEW.*DOCUMENT',
210                        'Open Document',
211                        'Sign Now',
212                        'complete tasks?'
213        )
214        // check that the display_text is all lowercase
215        or (
216          regex.contains(.display_text,
217                         "\\bVIEW",
218                         "DOWNLOAD",
219                         "CHECK",
220                         "KEEP.(SAME|MY)",
221                         "VERIFY",
222                         "ACCESS\\b",
223                         "SIGN\\b",
224                         "ENABLE\\b",
225                         "RETAIN",
226                         "PLAY",
227                         "LISTEN",
228          )
229          and regex.match(.display_text, "^[^a-z]*[A-Z][^a-z]*$")
230        )
231  
232        // the display text is _exactly_
233        or .display_text in~ ("Open")
234  
235        // URL fragment containing recipient's address
236        or .href_url.fragment in map(recipients.to, .email.email)
237    )
238    // one hyperlinked image that's not a tracking pixel
239    or (
240      length(html.xpath(body.html,
241                        "//a//img[(number(@width) > 5 or not(@width)) and (number(@height) > 5 or not(@height))]"
242             ).nodes
243      ) == 1
244      and length(body.current_thread.text) < 500
245    )
246    or (
247      length(attachments) > 0
248      and any(attachments,
249              (
250                regex.icontains(beta.ocr(.).text,
251                                "activate",
252                                "re-auth",
253                                "verify",
254                                "acknowledg",
255                                "(keep|change).{0,20}(active|password|access)",
256                                '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
257                                'use.same.pass',
258                                'validate.{0,15}account',
259                                'recover.{0,15}messages',
260                                '(retry|update).{0,10}payment',
261                                'check activity',
262                                '(listen|play).{0,10}(vm|voice)',
263                                'clarify.{0,20}(deposit|wallet|funds)',
264                                'enter.{0,15}teams',
265                                'Review and sign'
266                )
267              )
268              or (
269                any(file.explode(.),
270                    regex.icontains(.scan.ocr.raw,
271                                    "activate",
272                                    "re-auth",
273                                    "verify",
274                                    "acknowledg",
275                                    "(keep|change).{0,20}(active|password|access)",
276                                    '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
277                                    'use.same.pass',
278                                    'validate.{0,15}account',
279                                    'recover.{0,15}messages',
280                                    '(retry|update).{0,10}payment',
281                                    'check activity',
282                                    '(listen|play).{0,10}(vm|voice)',
283                                    'clarify.{0,20}(deposit|wallet|funds)',
284                                    'enter.{0,15}teams',
285                                    'Review and sign'
286                    )
287                )
288              )
289      )
290    )
291  )
292  // the message is unsolicited and no false positives
293  and (
294    not profile.by_sender_email().solicited
295    or profile.by_sender_email().prevalence == "new"
296    or (
297      profile.by_sender_email().any_messages_malicious_or_spam
298      and not profile.by_sender_email().any_messages_benign
299    )
300    or (
301      profile.by_sender_email().any_messages_malicious_or_spam
302      and profile.by_sender_email().any_messages_benign
303      and (
304        not headers.auth_summary.dmarc.pass or not headers.auth_summary.spf.pass
305      )
306    )
307  )
308  
309  // negate replies/fowards containing legitimate docs
310  and not (length(headers.references) > 0 or headers.in_reply_to is not null)
311  
312  // negate highly trusted sender domains unless they fail DMARC authentication
313  and (
314    (
315      sender.email.domain.root_domain in $high_trust_sender_root_domains
316      and (
317        any(distinct(headers.hops, .authentication_results.dmarc is not null),
318            strings.ilike(.authentication_results.dmarc, "*fail")
319        )
320      )
321    )
322    or sender.email.domain.root_domain not in $high_trust_sender_root_domains
323  )  
324attack_types:
325  - "Credential Phishing"
326tactics_and_techniques:
327  - "Social engineering"
328detection_methods:
329  - "Content analysis"
330  - "Header analysis"
331  - "HTML analysis"
332  - "URL analysis"
333  - "Sender analysis"
334id: "9b68c2d8-951e-5e04-9fa3-2ca67d9226a6"
to-top