• delivr.to Feed
Medium Severity

Link: Brand Impersonation Phishing Site

Labels

No labels.

Description

Link to a hosted or auto-downloading zip file that contains a OneNote file.

@delivr_to
Created Aug 17th, 2023 • Last updated Apr 22nd, 2024
Feed Source
delivr.to Feed
Source
type.inbound 
// Any link we identify as a brand with 
// above medium confidence, classified as phishing
and any(body.links,
    beta.linkanalysis(.).credphish.brand.name is not null and 
    beta.linkanalysis(.).credphish.brand.confidence in ("high", "medium") and
    beta.linkanalysis(.).credphish.disposition == "phishing"
)
and (
    (
        not profile.by_sender_email().solicited
        and profile.by_sender_email().prevalence in ("new", "outlier")
    )
    or (
        profile.by_sender_email().any_messages_malicious_or_spam
        and not profile.by_sender_email().any_false_positives
    )
    or sender.email.domain.domain == "delivrto.me"
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started