Credential phishing: Suspicious e-sign agreement document notification
Detects phishing attempts disguised as e-signature requests, characterized by common document sharing phrases, unusual HTML padding, and suspicious link text.
Sublime rule (View on GitHub)
1name: "Credential phishing: Suspicious e-sign agreement document notification"
2description: "Detects phishing attempts disguised as e-signature requests, characterized by common document sharing phrases, unusual HTML padding, and suspicious link text."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and (
8 any([subject.subject, sender.display_name],
9 regex.icontains(strings.replace_confusables(.),
10 "D[0o]cuLink",
11 "Agreement",
12 "Access.&.Appr[0o]ved",
13 "Agreement.{0,5}Review",
14 "Attend.and.Review",
15 "action.re?quired",
16 "AuthentiSign",
17 "Completed.File",
18 "D[0o]chsared",
19 "D[0o]cshared",
20 "D[0o]csPoint",
21 "D[0o]cument.Shared",
22 "D[0o]cuCentre",
23 "D[0o]cuCenter",
24 "D[0o]cCenter",
25 "D[0o]csOnline",
26 "D[0o]cSend",
27 "D[0o]cu?Send",
28 "d[0o]csign",
29 "D[0o]cu-eSin",
30 "D[0o]cu-management",
31 "\\beSign",
32 "e\\.sign",
33 "esign.[0o]nline",
34 "[SsZz][lL][GgSs][Nn].*D[0o]c",
35 "e-d[0o]c",
36 "e-signature",
37 "e-Verify Doc",
38 "eSignature",
39 "eSign&Return",
40 "eSign[0o]nline",
41 "Fileshare",
42 "Review.and.C[0o]mplete",
43 "Review.&.Sign",
44 "Sign[0o]nline",
45 "Signature.Request",
46 "Shared.C[0o]mpleted",
47 "Sign.and.Seal",
48 "viaSign",
49 "D[0o]cuSign",
50 "D[0o]csID",
51 "Complete.{0,10}D[0o]cuSign",
52 "Enroll & Sign",
53 "Review and Sign",
54 "Sign(?:Report|Now)",
55 "SignD[0o]c",
56 "D[0o]cxxx",
57 "d[0o]cufile",
58 'E\x{00AD}-\x{00AD}S\x{00AD}i\x{00AD}g\x{00AD}n\x{00AD}&Return',
59 "d[0o]cument.signature",
60 "Electr[0o]nic.?Signature",
61 "Complete: ",
62 "Please (?:Review|Sign)",
63 "^REVIEW$",
64 "requests your signature",
65 "signature on.*contract",
66 "Independent Contract",
67 "Contract.*signature",
68 "add your signature",
69 "signature needed",
70 "attn_task",
71 "DocReq\\b",
72 "noreply_edocx-task[0-9a-f-]{36}",
73 "securesign delivery"
74 )
75 or (
76 regex.icontains(strings.replace_confusables(.), "action.re?quired")
77 and not (
78 sender.email.domain.root_domain == "sharepointonline.com"
79 and headers.auth_summary.dmarc.pass
80 and strings.icontains(subject.subject, "asked to edit")
81 )
82 )
83 )
84 // lure CTA injected into the body (not subject/display) above a forwarded thread
85 or (
86 regex.icontains(strings.replace_confusables(body.current_thread.text),
87 "requests? your signature",
88 "review, sign, and return",
89 "signature on the attached"
90 )
91 // legit "please sign & return" mail attaches the actual document; this
92 // campaign references an "attached" doc but delivers a fake one via an
93 // off-domain link, with no real document attached
94 and not any(attachments,
95 .file_extension in~ ("pdf", "doc", "docx", "xls", "xlsx", "rtf")
96 )
97 // legit notification platforms (e.g. ParentSquare, Panopto) self-host their
98 // "review/sign/view" CTA on the sender's own root domain; this campaign points
99 // the CTA at an off-domain credential page. require a suspicious link whose
100 // display text is a document CTA AND that leaves the sender domain, so
101 // self-hosted legit notifications (and incidental links like the aka.ms
102 // first-contact banner, which carries no CTA verb) don't match.
103 and any(body.links,
104 .href_url.domain.root_domain is not null
105 and .href_url.domain.root_domain != sender.email.domain.root_domain
106 and regex.icontains(strings.replace_confusables(.display_text),
107 "view",
108 "review",
109 "sign",
110 "document",
111 "download",
112 "open",
113 "complete"
114 )
115 )
116 )
117 )
118 and (
119 // unusual repeated patterns in HTML
120 regex.icontains(body.html.raw, '((<br\s*/?>\s*){20,}|\n{20,})')
121 or regex.icontains(body.html.raw, '(<p[^>]*>\s*<br\s*/?>\s*</p>\s*){30,}')
122 or regex.icontains(body.html.raw,
123 '(<p class=".*?"><span style=".*?"><o:p> </o:p></span></p>\s*){30,}'
124 )
125 or regex.icontains(body.html.raw, '(<p> </p>\s*){7,}')
126 or regex.icontains(body.html.raw, '(<p[^>]*>\s* <br>\s*</p>\s*){5,}')
127 or regex.icontains(body.html.raw, '(<p[^>]*> </p>\s*){7,}')
128 or strings.count(body.html.raw, " \u{200C} \u{200C} ") > 50
129 or regex.count(body.html.raw,
130 '<span\s*class\s*=\s*"[^\"]+"\s*>\s*[a-z]\s*<\/span><span\s*class\s*=\s*"[^\"]+"\s*>\s*[a-z]+\s*<\/span>'
131 ) > 50
132 // lookalike docusign
133 or regex.icontains(body.html.raw, '>Docus[1l]gn<')
134 or strings.icontains(body.current_thread.text, 'completed by all parties')
135 or (
136 regex.icontains(body.html.inner_text, 'Document')
137 and length(body.html.inner_text) < 500
138 )
139 // common greetings via email.local_part
140 or any(recipients.to,
141 // use count to ensure the email address is not part of a disclaimer
142 strings.icount(body.current_thread.text, .email.local_part) >
143 // sum allows us to add more logic as needed
144 sum([
145 strings.icount(body.current_thread.text,
146 strings.concat('was sent to ', .email.email)
147 ),
148 strings.icount(body.current_thread.text,
149 strings.concat('intended for ', .email.email)
150 )
151 ]
152 )
153 )
154 // common greetings via mailbox display name
155 or strings.icount(body.current_thread.text, mailbox.display_name) >
156 // sum allows us to add more logic as needed
157 sum([
158 strings.icount(body.current_thread.text,
159 strings.concat('was sent to ', mailbox.display_name)
160 ),
161 strings.icount(body.current_thread.text,
162 strings.concat('intended for ', mailbox.display_name)
163 )
164 ]
165 )
166 // Abnormally high count of mailto links in raw html
167 or regex.count(body.html.raw,
168 'mailto:[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}'
169 ) > 50
170
171 // High count of empty elements (padding)
172 or regex.count(body.html.raw,
173 '<(?:p|div|span|td)[^>]*>\s*(?: |\s)*\s*</(?:p|div|span|td)>'
174 ) > 30
175
176 // HR impersonation
177 or strings.ilike(sender.display_name, "HR", "H?R", "*Human Resources*")
178
179 // Sender display name contains a phone number
180 or regex.icontains(sender.display_name,
181 '\+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4}'
182 )
183
184 // short CTA grafted above a forwarded legitimate thread to borrow its credibility
185 or (
186 length(body.previous_threads) > 0 and length(body.current_thread.text) < 600
187 )
188 )
189 and (
190 any(body.links,
191
192 // suspicious content within link display_text
193 regex.icontains(strings.replace_confusables(.display_text),
194 "activate",
195 "re-auth",
196 "verify",
197 "acknowledg",
198 "(keep|change).{0,20}(active|password|access)",
199 '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
200 'use.same.pass',
201 'validate.{0,15}account',
202 'recover.{0,15}messages',
203 '(retry|update).{0,10}payment',
204 'check activity',
205 '(listen|play).{0,10}(vm|voice)',
206 'clarify.{0,20}(deposit|wallet|funds)',
207 'enter.{0,15}teams',
208 'Review and sign',
209 'REVIEW.*DOCUMENT',
210 'Open Document',
211 'Sign Now',
212 'complete tasks?'
213 )
214 // check that the display_text is all lowercase
215 or (
216 regex.contains(.display_text,
217 "\\bVIEW",
218 "DOWNLOAD",
219 "CHECK",
220 "KEEP.(SAME|MY)",
221 "VERIFY",
222 "ACCESS\\b",
223 "SIGN\\b",
224 "ENABLE\\b",
225 "RETAIN",
226 "PLAY",
227 "LISTEN",
228 )
229 and regex.match(.display_text, "^[^a-z]*[A-Z][^a-z]*$")
230 )
231
232 // the display text is _exactly_
233 or .display_text in~ ("Open")
234
235 // URL fragment containing recipient's address
236 or .href_url.fragment in map(recipients.to, .email.email)
237 )
238 // one hyperlinked image that's not a tracking pixel
239 or (
240 length(html.xpath(body.html,
241 "//a//img[(number(@width) > 5 or not(@width)) and (number(@height) > 5 or not(@height))]"
242 ).nodes
243 ) == 1
244 and length(body.current_thread.text) < 500
245 )
246 or (
247 length(attachments) > 0
248 and any(attachments,
249 (
250 regex.icontains(beta.ocr(.).text,
251 "activate",
252 "re-auth",
253 "verify",
254 "acknowledg",
255 "(keep|change).{0,20}(active|password|access)",
256 '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
257 'use.same.pass',
258 'validate.{0,15}account',
259 'recover.{0,15}messages',
260 '(retry|update).{0,10}payment',
261 'check activity',
262 '(listen|play).{0,10}(vm|voice)',
263 'clarify.{0,20}(deposit|wallet|funds)',
264 'enter.{0,15}teams',
265 'Review and sign'
266 )
267 )
268 or (
269 any(file.explode(.),
270 regex.icontains(.scan.ocr.raw,
271 "activate",
272 "re-auth",
273 "verify",
274 "acknowledg",
275 "(keep|change).{0,20}(active|password|access)",
276 '((verify|view|click|download|goto|keep|Vιew|release).{0,15}(attachment|current|download|fax|file|document|message|same)s?)',
277 'use.same.pass',
278 'validate.{0,15}account',
279 'recover.{0,15}messages',
280 '(retry|update).{0,10}payment',
281 'check activity',
282 '(listen|play).{0,10}(vm|voice)',
283 'clarify.{0,20}(deposit|wallet|funds)',
284 'enter.{0,15}teams',
285 'Review and sign'
286 )
287 )
288 )
289 )
290 )
291 )
292 // the message is unsolicited and no false positives
293 and (
294 not profile.by_sender_email().solicited
295 or profile.by_sender_email().prevalence == "new"
296 or (
297 profile.by_sender_email().any_messages_malicious_or_spam
298 and not profile.by_sender_email().any_messages_benign
299 )
300 or (
301 profile.by_sender_email().any_messages_malicious_or_spam
302 and profile.by_sender_email().any_messages_benign
303 and (
304 not headers.auth_summary.dmarc.pass or not headers.auth_summary.spf.pass
305 )
306 )
307 )
308
309 // negate replies/fowards containing legitimate docs
310 and not (length(headers.references) > 0 or headers.in_reply_to is not null)
311
312 // negate highly trusted sender domains unless they fail DMARC authentication
313 and (
314 (
315 sender.email.domain.root_domain in $high_trust_sender_root_domains
316 and (
317 any(distinct(headers.hops, .authentication_results.dmarc is not null),
318 strings.ilike(.authentication_results.dmarc, "*fail")
319 )
320 )
321 )
322 or sender.email.domain.root_domain not in $high_trust_sender_root_domains
323 )
324attack_types:
325 - "Credential Phishing"
326tactics_and_techniques:
327 - "Social engineering"
328detection_methods:
329 - "Content analysis"
330 - "Header analysis"
331 - "HTML analysis"
332 - "URL analysis"
333 - "Sender analysis"
334id: "9b68c2d8-951e-5e04-9fa3-2ca67d9226a6"