Brand impersonation: UPS
Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.
Sublime rule (View on GitHub)
1name: "Brand impersonation: UPS"
2description: |
3 Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.
4references:
5 - "https://www.bleepingcomputer.com/news/security/phishing-campaign-uses-upscom-xss-vuln-to-distribute-malware/"
6 - "https://twitter.com/DanielGallagher/status/1429794038463479813"
7 - "https://www.ups.com/us/en/help-center/legal-terms-conditions/fight-fraud/recognize.page"
8type: "rule"
9severity: "low"
10source: |
11 type.inbound
12 and sender.email.domain.root_domain not in ("ups.com", "upsemail.com")
13 and (
14 sender.display_name in~ ("UPS My Choice", "UPS Services", "Ups.com")
15 or regex.icontains(sender.display_name, 'ups-\w+')
16 or strings.ilike(sender.email.local_part, "*united*parcel*service*")
17 or strings.ilike(sender.email.domain.domain, '*united*parcel*service*')
18 or strings.icontains(subject.subject, 'UPS delivery')
19 or sender.email.local_part =~ "ups"
20 or regex.icontains(sender.display_name,
21 "U[^a-zA-Z]P[^a-zA-Z]S(?:[^a-zA-Z]|$)"
22 )
23 or strings.icontains(body.html.raw, 'background-color:#351d20')
24 or strings.icontains(body.html.raw, 'background-color: #351d20')
25 or (
26 regex.imatch(sender.display_name, 'ups')
27 and not sender.email.domain.root_domain == "appleid.com"
28 )
29 )
30 and (
31 // Observed in the "footer" of impersation messages
32 // added this due to the UPS image not loading on some emails
33 strings.icontains(body.current_thread.text, "United Parcel Service of")
34 or regex.icontains(body.current_thread.text,
35 "(©|®).{0,15}(?:U.?P.?S.?|United Parcel Service)"
36 )
37 or any(ml.logo_detect(file.message_screenshot()).brands, .name is not null)
38 )
39 and sender.email.email not in $recipient_emails
40
41 // negate highly trusted sender domains unless they fail DMARC authentication
42 and (
43 (
44 sender.email.domain.root_domain in $high_trust_sender_root_domains
45 and not headers.auth_summary.dmarc.pass
46 )
47 or sender.email.domain.root_domain not in $high_trust_sender_root_domains
48 )
49
50attack_types:
51 - "Credential Phishing"
52tactics_and_techniques:
53 - "Impersonation: Brand"
54 - "Lookalike domain"
55 - "Social engineering"
56detection_methods:
57 - "Computer Vision"
58 - "Sender analysis"
59id: "73b68869-5720-5dc3-b4bc-15730de972d8"