Brand impersonation: Venmo
Impersonation of Venmo
Sublime rule (View on GitHub)
1name: "Brand impersonation: Venmo"
2description: |
3 Impersonation of Venmo
4references:
5 - "https://whnt.com/taking-action/bbb-consumer-alerts/new-venmo-scam-tricks-users/"
6type: "rule"
7severity: "medium"
8source: |
9 type.inbound
10 and (
11 strings.ilike(sender.display_name, '*venmo*')
12 or strings.ilevenshtein(sender.display_name, 'venmo') <= 1
13 )
14 and sender.email.domain.root_domain not in~ (
15 'venmo.com',
16 'synchronybank.com',
17 'venmocreditsurvey.com',
18 'venmo-experience.com',
19 'synchrony.com'
20 )
21
22 // and not if the sender.display.name contains "via" and dmarc pass from venmo.com
23 and not (
24 (
25 headers.auth_summary.dmarc.pass
26 and headers.auth_summary.dmarc.details.from.root_domain == "venmo.com"
27 )
28 and strings.contains(sender.display_name, "via")
29 )
30
31 // negate highly trusted sender domains unless they fail DMARC authentication
32 and not (
33 sender.email.domain.root_domain in $high_trust_sender_root_domains
34 and coalesce(headers.auth_summary.dmarc.pass, false)
35 )
36
37 // and no false positives and not solicited
38 and (
39 not profile.by_sender().any_messages_benign
40 and not profile.by_sender().solicited
41 )
42attack_types:
43 - "Credential Phishing"
44tactics_and_techniques:
45 - "Impersonation: Brand"
46 - "Lookalike domain"
47 - "Social engineering"
48detection_methods:
49 - "Sender analysis"
50id: "0ab15d4f-865f-518c-b54d-81043399e6f2"