Brand impersonation: AARP

Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders.

Sublime rule (View on GitHub)

 1name: "Brand impersonation: AARP"
 2description: "Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders."
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7  and (
 8    (
 9      strings.icontains(sender.display_name, "AARP")
10      and any(ml.nlu_classifier(body.current_thread.text).entities,
11              .name in ("request", "financial")
12              and regex.icontains(.text, "(?:gift|win|free|renewal)")
13      )
14    )
15    or 2 of (
16      strings.icontains(body.current_thread.text, 'AARP'),
17      strings.icontains(body.current_thread.text, '601 E Street NW'),
18      strings.icontains(body.current_thread.text, 'Washington, DC 20049')
19    )
20    or (
21      strings.icontains(body.current_thread.text, 'AARP')
22      and (
23        regex.icontains(body.current_thread.text,
24                        'quick .{0,10}survey',
25                        '\bAAR-[A-Za-z0-9]{0,}(-[A-Za-z0-9]{0,})?', // member number regex
26                        'comp[Il]imentary item' // contains a suspicious captilization
27        )
28        or strings.icontains(body.current_thread.text,
29                             "last attempt",
30                             "renewal is complete",
31                             "select membership item",
32                             "renew membership"
33        )
34      )
35    )
36    //
37    // This rule makes use of a beta feature and is subject to change without notice
38    // using the beta feature in custom rules is not suggested until it has been formally released
39    //
40    or (
41      strings.icontains(beta.ocr(file.message_screenshot()).text, "AARP")
42      and strings.icontains(beta.ocr(file.message_screenshot()).text,
43                            "join or renew now"
44      )
45      and strings.icontains(beta.ocr(file.message_screenshot()).text,
46                            "to opt out"
47      )
48    )
49  )
50  // negate job postings related to AARP and newsletters containing AARP
51  and not any(ml.nlu_classifier(body.current_thread.text).topics,
52              .name in (
53                "Professional and Career Development",
54                "Newsletters and Digests"
55              )
56              and .confidence == "high"
57  )
58  // and the sender is not in org_domains or from AARP domains and passes auth
59  and not (
60    sender.email.domain.root_domain in $org_domains
61    or (
62      sender.email.domain.root_domain in (
63        "aarp.org",
64        "proofpointessentials.com",
65        "expedia.com",
66        "eventbrite.com",
67        "zixcorp.com"
68      )
69      and headers.auth_summary.dmarc.pass
70    )
71  )  
72attack_types:
73  - "BEC/Fraud"
74  - "Credential Phishing"
75tactics_and_techniques:
76  - "Impersonation: Brand"
77  - "Social engineering"
78detection_methods:
79  - "Content analysis"
80  - "Header analysis"
81  - "Sender analysis"
82id: "561a7f87-0af7-5f34-8d5d-86bdc0fe213d"
to-top