Skip to content

Commit b6d98e6

Browse files
[PR #4001] added rule: Attachment: PDF object hash - payment receipt theme
1 parent a152181 commit b6d98e6

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
name: "Attachment: PDF object hash - payment receipt theme"
2+
description: "Detects PDF attachments containing objects with specific hash values known for fake payment receipts and invoice confirmations. The rule identifies PDF files by analyzing their internal object structures and matching against known, harmful object hashes."
3+
type: "rule"
4+
severity: "medium"
5+
source: |
6+
type.inbound
7+
and any(filter(attachments, .file_type == "pdf"),
8+
any(file.explode(.),
9+
.scan.pdf_obj_hash.object_hash in (
10+
"9c6b9dcddee56a38f1be7badaef017a2",
11+
"a6c857527026a1d5fe5d8fea6270ad29",
12+
"de75b9278fcc2b2d6fdc5f217ea4face",
13+
"df866e643dd6c0179bf74df874cf001d"
14+
)
15+
)
16+
)
17+
18+
attack_types:
19+
- "BEC/Fraud"
20+
tactics_and_techniques:
21+
- "PDF"
22+
- "Evasion"
23+
detection_methods:
24+
- "File analysis"
25+
- "Threat intelligence"
26+
id: "40b4bba1-5699-56d2-8e4b-2fd48efcd8f9"
27+
og_id: "e9d5be49-d7f0-5ef4-a931-9d3122aa9322"
28+
testing_pr: 4001
29+
testing_sha: 9c3f5db4eba10b5b3afe74887f7d81c609de5021

0 commit comments

Comments
 (0)