Brand impersonation: Dotloop
Impersonation of Dotloop, a real estate transaction management platform.
Sublime rule (View on GitHub)
1name: "Brand impersonation: Dotloop"
2description: "Impersonation of Dotloop, a real estate transaction management platform."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and (
8 strings.ilike(sender.display_name, '*dotloop*')
9 or strings.ilike(sender.email.domain.domain, '*dotloop*')
10 or (
11 // dotloop logo
12 any(html.xpath(body.html, '//img').nodes,
13 strings.icontains(.inner_text, 'dotloop')
14 )
15 and strings.contains(strings.replace_confusables(body.current_thread.text),
16 '(888)-DOTLOOP'
17 )
18 and 3 of (
19 strings.contains(strings.replace_confusables(body.current_thread.text),
20 'DOTLOOP',
21 ),
22 strings.contains(strings.replace_confusables(body.current_thread.text),
23 '1301 Second Avenue',
24 ),
25 strings.contains(strings.replace_confusables(body.current_thread.text),
26 'Floor 36',
27 ),
28 strings.contains(strings.replace_confusables(body.current_thread.text),
29 'Seattle, WA 98101'
30 )
31 )
32 )
33 )
34 and sender.email.domain.root_domain not in~ ('dotloop.com', 'showingtime.com')
35 and (
36 (
37 profile.by_sender().prevalence in ("new", "outlier")
38 and not profile.by_sender().solicited
39 )
40 or profile.by_sender().any_messages_malicious_or_spam
41 )
42 and not profile.by_sender().any_messages_benign
43
44 // negate highly trusted sender domains unless they fail DMARC authentication
45 and not (
46 sender.email.domain.root_domain in $high_trust_sender_root_domains
47 and coalesce(headers.auth_summary.dmarc.pass, false)
48 )
49attack_types:
50 - "Credential Phishing"
51tactics_and_techniques:
52 - "Impersonation: Brand"
53 - "Social engineering"
54detection_methods:
55 - "Header analysis"
56 - "Sender analysis"
57id: "f997581a-ca08-5b21-8a52-ee0ca78fcea5"