Link: QR Code with suspicious language (untrusted sender)

This rule analyzes image attachments for QR Codes that contain URLs including the recipient's email address. It ensures that the URLs do not link to any organizational domains. Additionally, it examines the email body using Natural Language Processing to detect credential phishing language.In cases of null bodies, the rule is conditioned to check the image for any suspicious terms.

Sublime rule (View on GitHub)

 1name: "Link: QR Code with suspicious language (untrusted sender)"
 2description: |
 3  This rule analyzes image attachments for QR Codes that contain URLs including the recipient's email address. It ensures that the URLs do not link to any organizational domains.
 4  Additionally, it examines the email body using Natural Language Processing to detect credential phishing language.In cases of null bodies,
 5  the rule is conditioned to check the image for any suspicious terms.  
 6type: "rule"
 7severity: "medium"
 8source: |
 9  type.inbound
10  
11  // check image attachments for QR code, will want to add message.screenshot functionality here when it's ready
12  // and length(attachments) < 10
13  and any(attachments,
14          (.file_type in $file_types_images or .file_type == "pdf")
15          and any(file.explode(.),
16                  .scan.qr.type == "url"
17  
18                  // recipient email address is present in the URL, a common tactic used in credential phishing attacks and the url is not in $org_domains
19                  and (
20                    any(recipients.to,
21                        .email.domain.valid
22                        and (
23                          strings.icontains(..scan.qr.data, .email.email)
24                          or (
25                            // recipient email found in qr data base64 encoded
26                            any(beta.scan_base64(..scan.qr.data, format="url"),
27                                strings.icontains(., ..email.email)
28                            )
29                          )
30                          // QR code contains the hex encoded email address in fragment
31                          or strings.decode_hex(..scan.qr.url.fragment) == .email.email
32                        )
33                    )
34                    and .scan.qr.url.domain.root_domain not in $org_domains
35                  )
36          )
37  )
38  
39  // NLU has identified cred_theft language with high confidence
40  and (
41    any(ml.nlu_classifier(body.current_thread.text).intents,
42        .name == "cred_theft" and .confidence == "high"
43    )
44    or 
45    // the attachment contains suspicious strings
46    (
47      any(attachments,
48          (.file_type in $file_types_images or .file_type == "pdf")
49          and any(file.explode(.),
50                  any(.scan.strings.strings,
51                      regex.icontains(.,
52                                      '(\b2fa\b|\bQ.?R\.?\s?\b|MFA|Muti[ -]?Factor Auth(entication)?)'
53                      )
54                  )
55          )
56      )
57    )
58  )
59  and (
60    profile.by_sender().prevalence in ("new", "outlier")
61    or (
62      profile.by_sender().any_messages_malicious_or_spam
63      and not profile.by_sender().any_messages_benign
64    )
65    or (
66      sender.email.domain.domain in $org_domains
67      and not coalesce(headers.auth_summary.dmarc.pass, false)
68    )
69  )
70  
71  // negate highly trusted sender domains unless they fail DMARC authentication
72  and not (
73    sender.email.domain.root_domain in $high_trust_sender_root_domains
74    and coalesce(headers.auth_summary.dmarc.pass, false)
75  )  
76attack_types:
77  - "Credential Phishing"
78tactics_and_techniques:
79  - "Impersonation: Brand"
80  - "QR code"
81  - "Social engineering"
82detection_methods:
83  - "Content analysis"
84  - "Computer Vision"
85  - "Natural Language Understanding"
86  - "QR code analysis"
87  - "Sender analysis"
88  - "URL analysis"
89id: "25a84d1c-9578-53e3-98a7-ca9b43abb28b"
to-top