-
Notifications
You must be signed in to change notification settings - Fork 62
/
WarnAudit-HighRiskDomains.txt
81 lines (70 loc) · 1.82 KB
/
WarnAudit-HighRiskDomains.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
== SWIFTFILTER HEADER - BEGIN ===
Name: Warn and Audit high-risk domains
Description: Alert on links to abusive hosts and abused TLDs
Rules:
- the sender is outside the organization
- subject or body matches text patterns: <SET0>
Exceptions:
- the subject or body matches text patterns: This email originated from outside of the organization
Actions:
- Prepend the disclaimer: <SET1>
- Send an incident report to monitoring mailbox
== SWIFTFILTER HEADER - END ==
== SET0 - BEGIN <REGULAR EXPRESSIONS> ==
sendspace\.com
://soo\.gd/
://cuu\.su/
://www\.b00\.fr/
://ssh\.tf/
://vzt\.me/
\.yolasite\.com
://snip\.ly/
://lc\.cx/
://urly\.fi/
://i-to\.cc/
://pxlme\.me/
://bit\.do/
://smarturl\.it/
://s\.id/
webredirect\.org
://flyt\.it/
\.pl.ua
://tny\.im/
\.16mb\.com
\.ulcraft\.com
topstyle\.me
\.skclick\.in
://tiny\.cc/
://hubn\.jp
://spbver\.de
\.appzoneteam\.com
://wurl\.cc
\.5gbfree\.com
://x\.co/
hyperurl\.co
sites\.google\.com
\.website2\.me
\w\.xyz/
\.webhostbox\.net
\.inmotionhosting\.com
\.free\.fr/
godaddysites\.com
jotformeu\.com
\.c9users\.io
url\.fit/
\.your-server\.de
/u\.to/
\.ukit\.me
form2pay\.com
\.cl/
\.uz/
myfreesites\.net
\.tripod\.com
contabo\.net
is\.gd/
\.weebly\.com
\.joburg
== SET0 - END <REGULAR EXPRESSIONS> ==
== SET1 - BEGIN <TEXT> ==
<div style="background-color:#FFEB9C; width:100%; border-style: solid; border-color:#9C6500; border-width:1pt; padding:2pt; font-size:10pt; line-height:12pt; font-family:'Calibri'; color:Black; text-align: left;"><span style="color:#9C6500; font-weight:bold;">CAUTION:</span> This email originated from outside of the organization and contains <b>potentially dangerous</b> website links. Please use caution before clicking any links or following instructions below. Do not sign-in with your corporate account. Please contact IT Helpdesk if in doubt.</div><br>
== SET0 - END <TEXT> ==