heroui logo

Attachment: Targeted DOCX with personalized recipient acknowledgement lure

Sublime Rules

View Source
Summary
Detects inbound emails with a DOCX attachment whose Word document contains specific patterns that indicate a personalized targeted lure. The DOCX must include a quarterly date reference (Q1–Q4 with a 2025–2029-like suffix), explicit strings STATUS and ACKNOWLEDGEMENT in WordML XML, and a personalized salutation where the recipient’s name (extracted from the XML) is embedded. The rule cross-references the embedded name against the recipient’s local-part or display_name to determine if the message is tailored to that recipient. When matched, it is classified as Credential Phishing via Social Engineering. Detection uses archive analysis to inspect DOCX contents, content/XML analysis to parse WordML, and file analysis to process attachments. Attack type: Credential Phishing. Techniques include social engineering and targeted lure deployment in email attachments.
Categories
  • Endpoint
  • Network
  • Application
Data Sources
  • File
Created: 2026-08-05