Medium Severity

Attachment: Hex-encoded recipient email in URL fragment

Description

Detects non-ICS attachments (PDFs, Office docs, HTML, etc.) that embed a URL whose fragment contains the recipient's email address encoded in hexadecimal. This technique is used to personalize or track clicks on malicious links delivered via file attachments rather than inline in the message body. Observed samples largely spoof financial or invoicing correspondence—such as invoice notices, AR aging reports, and cashflow or change-order updates—to lure recipients into opening the attachment and following the embedded link, often leading to credential phishing.

References

No references.

Sublime Security
Created Sep 16th, 2026 • Last updated Sep 16th, 2026
Source
type.inbound
and any(attachments,
        not (
          .file_type == "ics"
          or .file_extension == "ics"
          or .content_type in ("application/ics", "text/calendar")
        )
        and any(file.explode(.),
                any(.scan.url.urls,
                    strings.decode_hex(.fragment) == recipients.to[0].email.email
                )
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started