Skip to content

Commit c8898a1

Browse files
keaton-sublimeCI Bot
andauthored
Create attachment_pdf_w9_invoice_lure.yml (#3890)
Co-authored-by: CI Bot <hello@sublimesecurity.com>
1 parent 289e954 commit c8898a1

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
name: "Attachment: PDF contains W9 or invoice YARA signatures"
2+
description: "PDF attachment contains YARA signatures commonly associated with fraudulent W9 tax forms or invoice documents, which are frequently used in social engineering attacks to steal sensitive information or facilitate business email compromise."
3+
type: "rule"
4+
severity: "medium"
5+
source: |
6+
type.inbound
7+
and any(filter(attachments, .file_type == "pdf"),
8+
any(file.explode(.),
9+
any(.scan.yara.matches, .name in ("w9_pdf_01", "invoice_pdf_01"))
10+
)
11+
)
12+
attack_types:
13+
- "BEC/Fraud"
14+
- "Credential Phishing"
15+
tactics_and_techniques:
16+
- "PDF"
17+
- "Social engineering"
18+
detection_methods:
19+
- "File analysis"
20+
- "YARA"
21+
id: "9a8e8a98-34a6-5cdc-b151-d4eff3322f23"

0 commit comments

Comments
 (0)