Medium Severity

Link: Google Cloud Storage short filename pattern

Description

Detects inbound emails containing links to storage.googleapis.com where the URL path matches a suspicious pattern of a single-character folder followed by a one or two letter HTML filename (e.g., /x/ab.html). This naming convention is commonly used by phishing kits hosted on legitimate cloud storage to evade detection and obscure the true destination of the link.

References

No references.

Sublime Security
Created Sep 24th, 2026 • Last updated Sep 28th, 2026
Source
type.inbound
and any(body.links,
        .href_url.domain.domain == "storage.googleapis.com"
        and regex.imatch(.href_url.path, '/[^/]+/[a-z0-9]{1,4}\.html')
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started