Skip to content

Commit a845b59

Browse files
authored
Create attachment_pdf_obj_hash_payment_receipt.yml
1 parent ffe0142 commit a845b59

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: "Attachment: PDF object hash - payment receipt theme"
2+
description: "Detects PDF attachments containing objects with specific hash values known for fake payment receipts and invoice confirmations. The rule identifies PDF files by analyzing their internal object structures and matching against known, harmful object hashes."
3+
type: "rule"
4+
severity: "medium"
5+
source: |
6+
type.inbound
7+
and any(filter(attachments, .file_type == "pdf"),
8+
any(file.explode(.),
9+
.scan.pdf_obj_hash.object_hash in (
10+
"9c6b9dcddee56a38f1be7badaef017a2",
11+
"a6c857527026a1d5fe5d8fea6270ad29",
12+
"de75b9278fcc2b2d6fdc5f217ea4face",
13+
"df866e643dd6c0179bf74df874cf001d"
14+
)
15+
)
16+
)
17+
18+
attack_types:
19+
- "BEC/Fraud"
20+
tactics_and_techniques:
21+
- "PDF"
22+
- "Evasion"
23+
detection_methods:
24+
- "File analysis"
25+
- "Threat intelligence"

0 commit comments

Comments
 (0)