Description

Detects inbound emails with .ics calendar attachments whose parsed events contain links pointing to free file hosts, self-service creation platforms, suspicious TLDs, URL shorteners, or recently registered domains. The rule further confirms suspicion by identifying minimal JavaScript landing pages that load only a script and favicon, a common pattern for redirecting victims to malicious content while evading detection. Emails from highly trusted, DMARC-passing senders are excluded.

References

No references.

Sublime Security
Created Sep 16th, 2026 • Last updated Sep 28th, 2026
Source
type.inbound
and any(attachments,
        (
          .file_type == "ics"
          or .file_extension == "ics"
          or .content_type in ("application/ics", "text/calendar")
        )
        and any(beta.file.parse_ics(.).events,
                // sus link
                any(.links,
                    (
                      .href_url.domain.root_domain in $free_file_hosts
                      or .href_url.domain.domain in $free_file_hosts
                      or .href_url.domain.root_domain in $self_service_creation_platform_domains
                      or .href_url.domain.domain in $self_service_creation_platform_domains
                      or .href_url.domain.tld in $suspicious_tlds
                      or .href_url.domain.domain in $url_shorteners
                      or .href_url.domain.root_domain in $url_shorteners
                      or network.whois(.href_url.domain).days_old < 90
                    )
                    // minimal js landing page
                    and length(filter(ml.link_analysis(., mode="aggressive").unique_urls_accessed,
                                      .url == ..href_url.url
                                      or (
                                        strings.starts_with(.url,
                                                            ..href_url.url
                                        )
                                        and regex.icontains(.url,
                                                            '[a-z]{3,}\.[0-9a-f]{20}\.js'
                                        )
                                      )
                                      or .url == strings.concat(..href_url.url,
                                                                'favicon.png'
                                      )
                               )
                    ) == 3
                )
        )
)
and not (
  sender.email.domain.root_domain in $high_trust_sender_root_domains
  and coalesce(headers.auth_summary.dmarc.pass, false)
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started