Skip to content

Commit 09d5ea8

Browse files
[PR #3502] added rule: Link to a domain with punycode characters
1 parent 2bca95c commit 09d5ea8

File tree

1 file changed

+33
-0
lines changed

1 file changed

+33
-0
lines changed
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
name: "Link to a domain with punycode characters"
2+
description: |
3+
The body contains a link to a domain with Punycode characters to hide the true URL destination, or contains non-printable ASCII content.
4+
references:
5+
- "https://www.bleepingcomputer.com/news/security/hackers-abuse-lookalike-domains-and-favicons-for-credit-card-theft/"
6+
type: "rule"
7+
authors:
8+
- twitter: "ajpc500"
9+
severity: "medium"
10+
source: |
11+
type.inbound
12+
and (
13+
any(body.links,
14+
.href_url.domain.punycode is not null and .href_url.domain.valid == true
15+
)
16+
or any(body.links, strings.starts_with(.href_url.domain.domain, "xn--"))
17+
)
18+
19+
tags:
20+
- "Attack surface reduction"
21+
attack_types:
22+
- "Credential Phishing"
23+
tactics_and_techniques:
24+
- "Evasion"
25+
- "Lookalike domain"
26+
- "Punycode"
27+
detection_methods:
28+
- "Sender analysis"
29+
- "URL analysis"
30+
id: "13bfcdfe-0f61-565f-ac9f-ee45e6bcbaeb"
31+
og_id: "74b3698c-d75e-52db-9596-48af93817822"
32+
testing_pr: 3502
33+
testing_sha: f1f3ba095dfaa87fecff56507becbdf73495fd97

0 commit comments

Comments
 (0)