Skip to content

Commit 1398cf9

Browse files
authored
Update link_mamba_2fa_phishing_kit.yml (#3877)
1 parent 3c9bf5b commit 1398cf9

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

detection-rules/link_mamba_2fa_phishing_kit.yml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,18 +26,17 @@ source: |
2626
and any(body.links,
2727
any(ml.link_analysis(., mode="aggressive").redirect_history,
2828
(
29-
// sv=o365 to base64
30-
strings.contains(.url, 'c3Y9bzM2NV')
29+
// sv= in base64 as well as commonly observed tag
30+
regex.contains(.url, '(?:(?:/?|=)c3Y9|N0123N)')
3131
// &uid=USER base64 offsets
3232
and (
3333
strings.contains(.url, 'JnVpZD1VU0VS')
3434
or strings.contains(.url, 'Z1aWQ9VVNFU')
3535
or strings.contains(.url, 'mdWlkPVVTRV')
36-
)
36+
)
3737
)
3838
)
3939
)
40-
4140
attack_types:
4241
- "Credential Phishing"
4342
tactics_and_techniques:

0 commit comments

Comments
 (0)