Brand Impersonation: PayPal
Impersonation of PayPal.
Sublime rule (View on GitHub)
1name: "Brand Impersonation: PayPal"
2description: |
3 Impersonation of PayPal.
4references:
5 - "https://www.welivesecurity.com/2019/12/20/scam-wants-more-than-paypal-logins/"
6type: "rule"
7severity: "medium"
8source: |
9 type.inbound
10 and (
11 strings.replace_confusables(sender.display_name) =~ "paypal"
12 or strings.ilevenshtein(strings.replace_confusables(sender.display_name),
13 'paypal'
14 ) <= 1
15 or strings.ilike(strings.replace_confusables(sender.display_name), '*paypal*')
16 or strings.icontains(body.current_thread.text, "paypal account services")
17 or regex.icontains(body.current_thread.text,
18 'secure[-\._]?pay[-\._]?pal',
19 'paypal (?:support|billing) team',
20 '(?:pay[-\._\s]*pa[i1]\b|paypa[|!]|p@y\.?p@l)'
21 )
22 or any(ml.nlu_classifier(body.current_thread.text).entities,
23 .name == "sender" and strings.istarts_with(.text, 'paypal support')
24 )
25 or (
26 strings.istarts_with(body.current_thread.text, 'paypal')
27 and length(body.previous_threads) == 0
28 and any(ml.nlu_classifier(body.current_thread.text).intents,
29 .name == "callback_scam"
30 )
31 )
32 or any(attachments,
33 (.file_type in $file_types_images or .file_type == "pdf")
34 and any(ml.logo_detect(.).brands, .name == "PayPal")
35 and any(file.explode(.),
36 // exclude images taken with mobile cameras and screenshots from android
37 not any(.scan.exiftool.fields,
38 .key == "Model"
39 or (
40 .key == "Software"
41 and strings.starts_with(.value, "Android")
42 )
43 )
44 // exclude images taken with mobile cameras and screenshots from Apple
45 and not any(.scan.exiftool.fields,
46 .key == "DeviceManufacturer"
47 and .value == "Apple Computer Inc."
48 )
49 and strings.ilike(.scan.ocr.raw, "*PayPal*")
50 and strings.ilike(.scan.ocr.raw,
51 "*invoice*",
52 "*transaction*",
53 "*bitcoin*",
54 "*dear customer*",
55 "*suspicious activity*",
56 "*contact support*",
57 "*helpdesk*"
58 )
59 )
60 )
61 or (
62 any(ml.logo_detect(file.message_screenshot()).brands, .name == "PayPal")
63 and strings.ilike(body.current_thread.text, "*PayPal*")
64 and strings.ilike(body.current_thread.text,
65 "*invoice*",
66 "*transaction*",
67 "*bitcoin*",
68 "*dear customer*",
69 "*suspicious activity*",
70 "*contact support*",
71 "*helpdesk*"
72 )
73 )
74 )
75 and not any(ml.nlu_classifier(body.current_thread.text).topics,
76 .name in~ (
77 "Professional and Career Development",
78 "Government Services"
79 )
80 )
81 and sender.email.domain.root_domain not in (
82 'google.com',
83 'paypal-brandsfeedback.com',
84 'paypal-creditsurvey.com',
85 'paypal-customerfeedback.com',
86 'paypal-experience.com',
87 'paypal-prepaid.com',
88 'paypal.at',
89 'paypal.be',
90 'paypal.ca',
91 'paypal.ch',
92 'paypal.co.il',
93 'paypal.co.uk',
94 'paypal.com',
95 'paypal.com.au',
96 'paypal.com.mx',
97 'paypal.com.sg',
98 'paypal.de',
99 'paypal.dk',
100 'paypal.es',
101 'paypal.fr',
102 'paypal.hk',
103 'paypal.it',
104 'paypal.nl',
105 'paypal.pl',
106 'paypal.se',
107 'paypalcorp.com',
108 'q4inc.com',
109 'synchrony.com',
110 'synchronybank.com',
111 'synchronyfinancial.com',
112 'xoom.com',
113 'zettle.com'
114 )
115 // negate paypal.co.br explicitly, this cannot be part of the root_domain set above as it uses the PSL (Public suffix list) for parsing and co.br is not a recognized public suffix.
116 and sender.email.domain.domain not in~ ('paypal.co.br')
117
118 // negate highly trusted sender domains unless they fail DMARC authentication
119 and not (
120 sender.email.domain.root_domain in $high_trust_sender_root_domains
121 and coalesce(headers.auth_summary.dmarc.pass, false)
122 )
123attack_types:
124 - "Credential Phishing"
125tactics_and_techniques:
126 - "Impersonation: Brand"
127 - "Lookalike domain"
128 - "Social engineering"
129detection_methods:
130 - "Computer Vision"
131 - "Content analysis"
132 - "File analysis"
133 - "Header analysis"
134 - "Sender analysis"
135id: "a6b2ceee-ea57-594d-8437-698fad55c9bf"