Medium Severity

Link: Credential phishing with visit-tracking script

Description

Flags inbound messages where the message body is classified as credential theft with medium or high confidence, and where at least one linked page's rendered DOM contains a script that generates a unique visitor token (via Date.now() and Math.random() concatenation) and uses it to beacon back through a dynamically created Image object, a common pattern for tracking link clicks or victim visits in phishing infrastructure.

References

No references.

Sublime Security
Created Sep 25th, 2026 • Last updated Sep 25th, 2026
Source
type.inbound
and any(ml.nlu_classifier(body.current_thread.text).intents,
        .name == 'cred_theft' and .confidence != 'low'
)
and any(body.current_thread.links,
        any(html.xpath(ml.link_analysis(., mode="aggressive").final_dom,
                       "//script"
            ).nodes,
            // unique visit token
            regex.icontains(.raw,
                            'Date\.now\(\)\.toString\(36\)\s*\+\s*Math\.random\(\)\.toString\(36\)\.slice\(2'
            )
            and strings.icontains(.raw, 'new Image();')
            and regex.icontains(.raw, '.src=[a-z][+]')
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started