Suspicious request for financial information

Email is from a suspicious sender and contains a request for financial information, such as AR reports.

Sublime rule (View on GitHub)

  1name: "Suspicious request for financial information"
  2description: "Email is from a suspicious sender and contains a request for financial information, such as AR reports."
  3type: "rule"
  4severity: "high"
  5source: |
  6  type.inbound
  7  and length(attachments) <= 1
  8  and length(recipients.to) <= 2
  9  // suspicious sender
 10  and (
 11    (
 12      length(headers.reply_to) > 0
 13      and all(headers.reply_to,
 14              .email.domain.root_domain != sender.email.domain.root_domain
 15              and .email.domain.root_domain not in $org_domains
 16      )
 17    )
 18    or sender.email.domain.root_domain in $free_email_providers
 19    or profile.by_sender().days_known < 3
 20  )
 21  // specific financial language
 22  and (
 23    (
 24      regex.icontains(subject.subject,
 25                      '\b(Aged|Age?ing) (Payables|Receivables|Report)',
 26                      'reconcill?iation (report|statement).*(issued (settlement|advice)s?)|billing records?'
 27      )
 28      or regex.imatch(subject.base, 'outstanding due invoices')
 29    )
 30    or (
 31      regex.icontains(body.current_thread.text,
 32                      '\b(Aged|Age?ing) (?:Collection|Payables|Receivables|Report)',
 33                      '(latest|updated|recent) (\bAR\b|\b\AP\b|\bAR\b \& \bAP\b|accounts?) (?:Aging|Payables|Receivables|Reports)',
 34                      '(shared?|send|forward|provide).*remittance (advice|receipts?|statements?)'
 35      )
 36      or strings.icontains(body.current_thread.text,
 37                           "copy of a current statement",
 38                           "unpaid and due invoices"
 39      )
 40      or (
 41        strings.icontains(body.current_thread.text, "please send all past due")
 42        and strings.icontains(body.current_thread.text, "current invoices")
 43      )
 44    )
 45    // suspicious link display text
 46    or (
 47      any(body.links,
 48          regex.icontains(.display_text,
 49                          '(Payment|Remittance|Settlement|Transfer) ?Batch',
 50          )
 51      )
 52    )
 53    // suspicious sender display name
 54    or (
 55      regex.icontains(sender.display_name,
 56                      'Accounts? (?:Payable (?:Dep(\.|t\.?|artment)|e?Receipt)|(Co[[:punct:]]?ordinator|Admin|Manager|Payee))'
 57      )
 58      // sender email listed as a recipient or recipients undisclosed/null
 59      and (
 60        (
 61          sender.email.email in map(recipients.to, .email.email)
 62          or (length(recipients.to) == 0 or length(recipients.to) is null)
 63        )
 64        // non-benign nlu intent
 65        or any(ml.nlu_classifier(body.current_thread.text).intents,
 66               .name != "benign"
 67        )
 68      )
 69    )
 70    or (
 71      any(ml.nlu_classifier(body.current_thread.text).intents,
 72          .name == "cred_theft" and .confidence == "high"
 73      )
 74      and any(ml.nlu_classifier(body.current_thread.text).entities,
 75              .name == "financial" and .text =~ "remittance"
 76      )
 77    )
 78  )
 79  // negate resume related/job inquiry outreach
 80  and not (
 81    any(ml.nlu_classifier(body.current_thread.text).topics,
 82        .name == "Professional and Career Development" and .confidence == "high"
 83    )
 84    and any(ml.nlu_classifier(body.current_thread.text).intents,
 85            .name == "benign" and .confidence != "low"
 86    )
 87  )
 88  and not (
 89    sender.email.domain.root_domain in $high_trust_sender_root_domains
 90    and coalesce(headers.auth_summary.dmarc.pass, false)
 91  )
 92  and not profile.by_sender().any_messages_benign  
 93
 94attack_types:
 95  - "BEC/Fraud"
 96tactics_and_techniques:
 97  - "Free email provider"
 98  - "Impersonation: Employee"
 99  - "Impersonation: VIP"
100  - "Social engineering"
101detection_methods:
102  - "Content analysis"
103  - "Header analysis"
104  - "Sender analysis"
105id: "4ebdaa4d-4db2-56c6-9a6c-220ad49b7681"
to-top