Brand impersonation: Adobe (QR code)

Detects messages using Adobe image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

Sublime rule (View on GitHub)

  1name: "Brand impersonation: Adobe (QR code)"
  2description: "Detects messages using Adobe image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads."
  3type: "rule"
  4severity: "high"
  5source: |
  6  type.inbound
  7  and (
  8    any(attachments,
  9        (.file_type in $file_types_images or .file_type == "pdf")
 10        and (
 11          any(ml.logo_detect(.).brands,
 12              .name == "Adobe" and .confidence in ("medium", "high")
 13          )
 14          or any(ml.logo_detect(file.message_screenshot()).brands,
 15                 .name == "Adobe"
 16          )
 17          or any(file.explode(.),
 18                 any(.scan.strings.strings,
 19                     regex.icontains(., "adobe (acrobat|sign)")
 20                     // negate PDF data, like "xmp:CreatorTool>Adobe Acrobat Pro (64-bit) 24.4.20272</xmp:CreatorTool>"
 21                     and not regex.icontains(.,
 22                                             "(creatortool|producer|creator).{1,5}adobe acrobat"
 23                     )
 24                 )
 25          )
 26        )
 27    )
 28    or any(attachments,
 29           .file_extension in $file_extensions_macros
 30           and any(file.explode(.), .depth == 0 and .scan.docx.image_count > 0)
 31           and any(file.explode(.),
 32                   any(.scan.strings.strings, strings.ilike(., "*adobe*"))
 33           )
 34    )
 35  )
 36  and any(attachments,
 37          (
 38            .file_type in $file_types_images
 39            or .file_type == "pdf"
 40            or .file_type in $file_extensions_macros
 41          )
 42          and (
 43            any(file.explode(.),
 44                regex.icontains(.scan.ocr.raw, 'scan|camera')
 45                and regex.icontains(.scan.ocr.raw, '\bQR\b|Q\.R\.|barcode')
 46            )
 47            or (
 48              any(file.explode(.),
 49                  .scan.qr.type == "url"
 50                  // recipient email address is present in the URL, a common tactic used in credential phishing attacks
 51                  and (
 52                    any(recipients.to,
 53                        (
 54                          (
 55                            .email.domain.valid
 56                            and (
 57                              strings.icontains(..scan.qr.data, .email.email)
 58                              or any(strings.scan_base64(..scan.qr.data,
 59                                                         format="url"
 60                                     ),
 61                                     strings.icontains(., ..email.email)
 62                              )
 63                              // QR code contains the hex encoded email address in fragment
 64                              or strings.decode_hex(..scan.qr.url.fragment) == .email.email
 65                            )
 66                          )
 67                          or strings.icontains(.display_name, "undisclosed")
 68                        )
 69                    )
 70
 71                    // the recipients sld is in the senders display name
 72                    or any(recipients.to,
 73                           strings.icontains(sender.display_name,
 74                                             .email.domain.sld
 75                           )
 76                    )
 77
 78                    // the recipient local is in the body
 79                    or any(recipients.to,
 80                           strings.icontains(body.current_thread.text,
 81                                             .email.local_part
 82                           )
 83                    )
 84
 85                    // or the body is null
 86                    or body.current_thread.text is null
 87                    or body.current_thread.text == ""
 88
 89                    // or the subject contains authentication/urgency verbiage
 90                    or regex.contains(subject.subject,
 91                                      "(Authenticat(e|or|ion)|2fa|Multi.Factor|(qr|bar).code|action.require|alert|Att(n|ention):)"
 92                    )
 93
 94                    // high confidence cred theft in body
 95                    or any(ml.nlu_classifier(body.current_thread.text).intents,
 96                           .name == "cred_theft" and .confidence in ("high")
 97                    )
 98                  )
 99              )
100            )
101          )
102  )
103  and (
104    not sender.email.domain.root_domain in (
105      "acrobat.com",
106      "adobecc.com",
107      "adobecces.com",
108      "adobeccstatic.com",
109      "adobe.com",
110      "adobeexchange.com",
111      "adobe-identity.com",
112      "adobe.io",
113      "adobejanus.com",
114      "adobelogin.com",
115      "adobe.net",
116      "adobeprojectm.com",
117      "adoberesources.net",
118      "adobesc.com",
119      "adobesign.com",
120      "adobestock.com",
121      "createjs.com",
122      "licensingstack.com",
123      "myportfolio.com",
124      "photoshop.com",
125      "typekit.com",
126      "typekit.net"
127    )
128    or not any(headers.hops,
129               .authentication_results.compauth.verdict is not null
130               and .authentication_results.compauth.verdict == "pass"
131    )
132  )
133
134  // negate highly trusted sender domains unless they fail DMARC authentication
135  and not (
136    sender.email.domain.root_domain in $high_trust_sender_root_domains
137    and coalesce(headers.auth_summary.dmarc.pass, false)
138  )  
139attack_types:
140  - "Credential Phishing"
141tactics_and_techniques:
142  - "Impersonation: Brand"
143  - "PDF"
144  - "QR code"
145detection_methods:
146  - "Computer Vision"
147  - "Header analysis"
148  - "QR code analysis"
149  - "Sender analysis"
150id: "2fc36c6d-86a2-5b12-b5a4-5d8744858381"
to-top