Skip to content

Commit bbfd8ce

Browse files
[PR #3808] modified rule: Attachment: Fake lawyer & sports agent identities
1 parent f92f7d7 commit bbfd8ce

File tree

1 file changed

+2
-18
lines changed

1 file changed

+2
-18
lines changed

detection-rules/3808_attachment_fake_lawyer_sports_agent.yml

Lines changed: 2 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -5,23 +5,7 @@ severity: "high"
55
source: |
66
type.inbound
77
and length(attachments) == 1
8-
and (
9-
// Michael is a fake lawyer used in fc barcelona scam
10-
// Gabriele & Valerio "Giuffrida" are sports agent
11-
any([
12-
"Michael Gerardus Hermanus Demon",
13-
"Gabriele Giuffrida",
14-
"Valerio Giuffrida"
15-
],
16-
any(attachments,
17-
strings.icontains(beta.parse_exif(.).creator, ..)
18-
or strings.icontains(beta.ocr(.).text, ..)
19-
)
20-
or strings.icontains(body.current_thread.text, .)
21-
or strings.icontains(body.current_thread.text, .)
22-
or any(body.previous_threads, strings.icontains(.text, ..))
23-
)
24-
)
8+
and beta.parse_exif(attachments[0]).creator == "Gabriele Giuffrida"
259
attack_types:
2610
- "BEC/Fraud"
2711
tactics_and_techniques:
@@ -35,4 +19,4 @@ detection_methods:
3519
id: "d8cbbf7d-7230-524d-ac26-e97e6c4e06e8"
3620
og_id: "7d3a2478-a373-50d6-97bb-2dd1c3f710f7"
3721
testing_pr: 3808
38-
testing_sha: bcba077ea73deb74a13d883b328aa6ff26b31169
22+
testing_sha: c92cceb3cc01b9a0b0d4f7468a89414ab2e7d710

0 commit comments

Comments
 (0)