type.inbound
and 0 < length(body.links) < 15
and length(recipients.to) == 1
and recipients.to[0].email.domain.valid
and any(body.links,
// javascript obfuscator code - https://obfuscator.io/
regex.icontains(ml.link_analysis(.).final_dom.raw,
'(?:(?:return|function|var|let|const|parseInt)\(?\s*_0x[a-f0-9]{6}.{0,50}){5}'
)
and regex.icontains(ml.link_analysis(.).final_dom.raw,
// telegram bot token struct
'[\x22\x27][0-9]{10}:[a-z0-9_-]{20,35}[\x22\x27]',
// telegram strings
'(?:telegram(?:chatid|BotToken)|TELEGRAM_(?:BOT_TOKENS|CHAT_IDS)|api\.telegram\.org/bot|telegramToken)'
)
)
Playground
Test against your own EMLs or sample data.