Brand Impersonation: SiriusXM

Impersonation of the broadcasting corporation SiriusXM.

Sublime rule (View on GitHub)

 1name: "Brand Impersonation: SiriusXM"
 2description: "Impersonation of the broadcasting corporation SiriusXM."
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7  and (
 8    strings.ilike(sender.display_name, '*siriusxm*')
 9    or strings.ilevenshtein(sender.display_name, 'siriusxm') <= 1
10    or strings.ilike(sender.email.domain.domain, '*siriusxm*')
11  )
12  and (
13    sender.email.domain.root_domain not in (
14      'siriusxm.com',
15      'siriusxmmedia.com',
16      'siriusxm.ca',
17      'engagement360.net' // SiriusXM survey vendor
18    )
19    or (
20      sender.email.domain.root_domain in (
21        'siriusxm.com',
22        'siriusxmmedia.com',
23        'siriusxm.ca',
24        'engagement360.net' // SiriusXM survey vendor
25      )
26      and not headers.auth_summary.dmarc.pass
27    )
28  )
29  and not profile.by_sender().solicited  
30attack_types:
31  - "Callback Phishing"
32  - "Credential Phishing"
33  - "Spam"
34tactics_and_techniques:
35  - "Free email provider"
36  - "Impersonation: Brand"
37  - "Social engineering"
38detection_methods:
39  - "Content analysis"
40  - "Header analysis"
41  - "Sender analysis"
42id: "70eb3792-cd7a-5369-b1c3-65a3b772de00"
to-top