Medium Severity

Attachment: Embedded MSG file with payment lure and newly registered domain

Description

Detects inbound messages carrying an .msg attachment that itself contains an embedded email. The nested message combines financial fraud language—references to ACH/wire transfers, invoices, remittance, or urgency-based payment discounts—with a link to a domain registered within the last 30 days, a pattern consistent with business email compromise or invoice fraud schemes hiding their payload inside a forwarded or attached message to evade detection.

References

No references.

Sublime Security
Created Sep 25th, 2026 • Last updated Sep 25th, 2026
Source
type.inbound
and any(filter(attachments, .file_extension =~ "msg"),
        any(file.explode(.),
            // payment request inside the embedded message
            2 of (
              regex.icontains(.scan.strings.raw,
                              '\b(?:ach|wire transfer|remit(?:ted|tance)?)\b'
              ),
              strings.icontains(.scan.strings.raw, 'invoice'),
              regex.icontains(.scan.strings.raw,
                              'payment discount|keep the discount|by (?:today|tomorrow|end of (the )?day)'
              ),
              any(ml.nlu_classifier(.scan.strings.raw).topics,
                  .name == 'Request to View Invoice'
              )
            )
            // newly registered domain referenced in the embedded message
            and any(.scan.url.urls, network.whois(.domain).days_old < 30)
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started