Skip to content

Commit 2ab6378

Browse files
Update link_credential_phishing_voicemail_language.yml (#3473)
1 parent cecf4b0 commit 2ab6378

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

detection-rules/link_credential_phishing_voicemail_language.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,13 @@ source: |
3535
// obfuscated phone number with at least one digit in the prefix
3636
// XXX-555-5555, XXX-5XX-XXXX
3737
'\b1?\(?(\d{2}[\*X]|\d[\*X]{2}|[\*X]{2,3})\)?[^a-z0-9]{0,2}(\d{2,3}|\d{2}[\*X]|\d[\*X]{2})[^a-z0-9]{0,4}(\d{4}|\d{3}[\*X]|\d{2}[\*X]{2}|\d[\*X]{3}|[\*X]{3,4})\b',
38+
// obfuscated voicemail/voicemessage keywords
39+
'v[o0][il1]ce[\s\-_]?m(?:ail|sg|essage)?[\*X\.\-_]{2,}',
40+
'v[o0][il1]cem[\*X\.\-_]{2,}',
41+
// "X new voice..." patterns
42+
'\d+\s+new.*v[o0][il1]ce(?:mail|message|m[\*]+)?',
43+
// sent-message patterns
44+
'(?:sent|new|incoming)[\s\-]+message.*v[o0][il1]ce',
3845
)
3946
)
4047
// body.current_thread.text inspection should be very specific to avoid FP

0 commit comments

Comments
 (0)