Link: Webflow link from unsolicited sender
This detection rule matches on messaging containing at least one link to webflow.io from an unsolicited sender. Webflow.io provides a free plan enabling users to create custom websites and file hosting. This services has been abused by threat actors to host landing pages directing victims to a next stage of credential phishing.
Sublime rule (View on GitHub)
1name: "Link: Webflow link from unsolicited sender"
2description: "This detection rule matches on messaging containing at least one link to webflow.io from an unsolicited sender. Webflow.io provides a free plan enabling users to create custom websites and file hosting. This services has been abused by threat actors to host landing pages directing victims to a next stage of credential phishing."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and any(body.links,
8 // webflow link
9 .href_url.domain.root_domain == 'webflow.io'
10 and .href_url.domain.subdomain != ""
11 and .href_url.domain.subdomain != "www"
12 and .href_url.path == "/"
13 )
14 // not solicited or from malicious/spam user with no FPs
15 and (
16 not profile.by_sender_email().solicited
17 or (
18 profile.by_sender_email().any_messages_malicious_or_spam
19 and not profile.by_sender_email().any_messages_benign
20 )
21 )
22
23 // not from high trust sender root domains
24 and not (
25 sender.email.domain.root_domain in $high_trust_sender_root_domains
26 and coalesce(headers.auth_summary.dmarc.pass, false)
27 )
28attack_types:
29 - "Callback Phishing"
30tactics_and_techniques:
31 - "Free file host"
32 - "Free subdomain host"
33detection_methods:
34 - "Content analysis"
35 - "URL analysis"
36 - "Sender analysis"
37id: "d4f3b8cf-6aa9-5e21-8307-8f4df248dded"