Skip to content

Commit aafec63

Browse files
[PR #3808] added rule: Attachment: Fake lawyer & sports agent identities
1 parent aacd45b commit aafec63

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
name: "Attachment: Fake lawyer & sports agent identities"
2+
description: "Detects messages containing attachments or content that reference known fake identities used in FC Barcelona scams, including fake lawyer Michael Gerardus Hermanus Demon and sports agents with the surname Giuffrida. The rule examines EXIF metadata, OCR text from attachments, and message body content for these specific identity markers."
3+
type: "rule"
4+
severity: "high"
5+
source: |
6+
type.inbound
7+
and length(attachments) == 1
8+
and (
9+
// Michael is a fake lawyer used in fc barcelona scam
10+
// Gabriele & Valerio "Giuffrida" are sports agent
11+
any(["Michael Gerardus Hermanus Demon", "Giuffrida"],
12+
any(attachments,
13+
strings.icontains(beta.parse_exif(.).creator, ..)
14+
or strings.icontains(beta.ocr(.).text, ..)
15+
)
16+
or strings.icontains(body.current_thread.text, .)
17+
or strings.icontains(body.current_thread.text, .)
18+
or any(body.previous_threads, strings.icontains(.text, ..))
19+
)
20+
)
21+
22+
attack_types:
23+
- "BEC/Fraud"
24+
tactics_and_techniques:
25+
- "Impersonation: VIP"
26+
- "Social engineering"
27+
detection_methods:
28+
- "Content analysis"
29+
- "Exif analysis"
30+
- "File analysis"
31+
- "Optical Character Recognition"
32+
id: "d8cbbf7d-7230-524d-ac26-e97e6c4e06e8"
33+
og_id: "7d3a2478-a373-50d6-97bb-2dd1c3f710f7"
34+
testing_pr: 3808
35+
testing_sha: 2d724375811e6fd405b04dd006602b2b8348fc05

0 commit comments

Comments
 (0)