Skip to content

Commit fb71b72

Browse files
[PR #3746] added rule: Service Abuse: GoDaddy infrastructure
1 parent 5943f24 commit fb71b72

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: "Service Abuse: GoDaddy infrastructure"
2+
description: "Detects messages from legitimate GoDaddy domains with suspicious indicators. Observed abused for call back phishing and extortion campaigns."
3+
type: "rule"
4+
severity: "medium"
5+
source: |
6+
type.inbound
7+
and length(attachments) == 0
8+
// legitimate GoDaddy sending infrastructure
9+
and (
10+
sender.email.domain.root_domain == "godaddy.com"
11+
and headers.auth_summary.dmarc.pass
12+
)
13+
and any(body.links, .display_text in~ ("Pay Now", "Accept Access"))
14+
attack_types:
15+
- "Callback Phishing"
16+
- "Extortion"
17+
tactics_and_techniques:
18+
- "Evasion"
19+
detection_methods:
20+
- "Natural Language Understanding"
21+
- "Content analysis"
22+
id: "e645c524-c0b8-538a-8198-4a82bf78a1e2"
23+
og_id: "8a2dd357-3ecf-5d23-bcd8-d215a5f677dd"
24+
testing_pr: 3746
25+
testing_sha: fdae05abc38e8c72152718110bf41cbee4c51ebb

0 commit comments

Comments
 (0)