Brand impersonation: AARP
Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders.
Sublime rule (View on GitHub)
1name: "Brand impersonation: AARP"
2description: "Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and (
8 (
9 strings.icontains(sender.display_name, "AARP")
10 and any(ml.nlu_classifier(body.current_thread.text).entities,
11 .name in ("request", "financial")
12 and regex.icontains(.text, "(?:gift|win|free|renewal)")
13 )
14 )
15 or 2 of (
16 strings.icontains(body.current_thread.text, 'AARP'),
17 strings.icontains(body.current_thread.text, '601 E Street NW'),
18 strings.icontains(body.current_thread.text, 'Washington, DC 20049')
19 )
20 or (
21 strings.icontains(body.current_thread.text, 'AARP')
22 and (
23 regex.icontains(body.current_thread.text,
24 'quick .{0,10}survey',
25 '\bAAR-[A-Za-z0-9]{0,}(-[A-Za-z0-9]{0,})?', // member number regex
26 'comp[Il]imentary item' // contains a suspicious captilization
27 )
28 or strings.icontains(body.current_thread.text,
29 "last attempt",
30 "renewal is complete",
31 "select membership item",
32 "renew membership"
33 )
34 )
35 )
36 //
37 // This rule makes use of a beta feature and is subject to change without notice
38 // using the beta feature in custom rules is not suggested until it has been formally released
39 //
40 or (
41 strings.icontains(beta.ocr(file.message_screenshot()).text, "AARP")
42 and strings.icontains(beta.ocr(file.message_screenshot()).text,
43 "join or renew now"
44 )
45 and strings.icontains(beta.ocr(file.message_screenshot()).text,
46 "to opt out"
47 )
48 )
49 )
50 // negate job postings related to AARP and newsletters containing AARP
51 and not any(ml.nlu_classifier(body.current_thread.text).topics,
52 .name in (
53 "Professional and Career Development",
54 "Newsletters and Digests"
55 )
56 and .confidence == "high"
57 )
58 // and the sender is not in org_domains or from AARP domains and passes auth
59 and not (
60 sender.email.domain.root_domain in $org_domains
61 or (
62 sender.email.domain.root_domain in (
63 "aarp.org",
64 "proofpointessentials.com",
65 "expedia.com",
66 "eventbrite.com",
67 "zixcorp.com"
68 )
69 and headers.auth_summary.dmarc.pass
70 )
71 )
72attack_types:
73 - "BEC/Fraud"
74 - "Credential Phishing"
75tactics_and_techniques:
76 - "Impersonation: Brand"
77 - "Social engineering"
78detection_methods:
79 - "Content analysis"
80 - "Header analysis"
81 - "Sender analysis"
82id: "561a7f87-0af7-5f34-8d5d-86bdc0fe213d"