Suspicious request for financial information
Email is from a suspicious sender and contains a request for financial information, such as AR reports.
Sublime rule (View on GitHub)
1name: "Suspicious request for financial information"
2description: "Email is from a suspicious sender and contains a request for financial information, such as AR reports."
3type: "rule"
4severity: "high"
5source: |
6 type.inbound
7 and length(attachments) <= 1
8 and length(recipients.to) <= 2
9 // suspicious sender
10 and (
11 (
12 length(headers.reply_to) > 0
13 and all(headers.reply_to,
14 .email.domain.root_domain != sender.email.domain.root_domain
15 and .email.domain.root_domain not in $org_domains
16 )
17 )
18 or sender.email.domain.root_domain in $free_email_providers
19 or profile.by_sender().days_known < 3
20 )
21 // specific financial language
22 and (
23 (
24 regex.icontains(subject.subject,
25 '\b(Aged|Age?ing) (Payables|Receivables|Report)',
26 'reconcill?iation (report|statement).*(issued (settlement|advice)s?)|billing records?'
27 )
28 or regex.imatch(subject.base, 'outstanding due invoices')
29 )
30 or (
31 regex.icontains(body.current_thread.text,
32 '\b(Aged|Age?ing) (?:Collection|Payables|Receivables|Report)',
33 '(latest|updated|recent) (\bAR\b|\b\AP\b|\bAR\b \& \bAP\b|accounts?) (?:Aging|Payables|Receivables|Reports)',
34 '(shared?|send|forward|provide).*remittance (advice|receipts?|statements?)'
35 )
36 or strings.icontains(body.current_thread.text,
37 "copy of a current statement",
38 "unpaid and due invoices"
39 )
40 or (
41 strings.icontains(body.current_thread.text, "please send all past due")
42 and strings.icontains(body.current_thread.text, "current invoices")
43 )
44 )
45 // suspicious link display text
46 or (
47 any(body.links,
48 regex.icontains(.display_text,
49 '(Payment|Remittance|Settlement|Transfer) ?Batch',
50 )
51 )
52 )
53 // suspicious sender display name
54 or (
55 regex.icontains(sender.display_name,
56 'Accounts? (?:Payable (?:Dep(\.|t\.?|artment)|e?Receipt)|(Co[[:punct:]]?ordinator|Admin|Manager|Payee))'
57 )
58 // sender email listed as a recipient or recipients undisclosed/null
59 and (
60 (
61 sender.email.email in map(recipients.to, .email.email)
62 or (length(recipients.to) == 0 or length(recipients.to) is null)
63 )
64 // non-benign nlu intent
65 or any(ml.nlu_classifier(body.current_thread.text).intents,
66 .name != "benign"
67 )
68 )
69 )
70 or (
71 any(ml.nlu_classifier(body.current_thread.text).intents,
72 .name == "cred_theft" and .confidence == "high"
73 )
74 and any(ml.nlu_classifier(body.current_thread.text).entities,
75 .name == "financial" and .text =~ "remittance"
76 )
77 )
78 )
79 // negate resume related/job inquiry outreach
80 and not (
81 any(ml.nlu_classifier(body.current_thread.text).topics,
82 .name == "Professional and Career Development" and .confidence == "high"
83 )
84 and any(ml.nlu_classifier(body.current_thread.text).intents,
85 .name == "benign" and .confidence != "low"
86 )
87 )
88 and not (
89 sender.email.domain.root_domain in $high_trust_sender_root_domains
90 and coalesce(headers.auth_summary.dmarc.pass, false)
91 )
92 and not profile.by_sender().any_messages_benign
93
94attack_types:
95 - "BEC/Fraud"
96tactics_and_techniques:
97 - "Free email provider"
98 - "Impersonation: Employee"
99 - "Impersonation: VIP"
100 - "Social engineering"
101detection_methods:
102 - "Content analysis"
103 - "Header analysis"
104 - "Sender analysis"
105id: "4ebdaa4d-4db2-56c6-9a6c-220ad49b7681"