
Summary
This rule aims to detect potentially fraudulent dating profiles communicated via email, particularly through free email service providers. It identifies messages that not only come from such providers but also exhibit characteristics typical of spam. The detection mechanism involves checking specific criteria, including the absence of a prior email reply (by verifying that 'references' in headers are empty) and analyzing the email body for links containing the recipient's email as a query parameter. The rule pays close attention to the content of the emails, employing a Natural Language Understanding (NLU) classifier to find entities and topics aligned with dating-related terms (e.g., 'Date', 'Dating', 'Girls', 'Love') or attributes categorized under 'Romance'. If the conditions are satisfied, the message could be flagged as potential spam, allowing for appropriate user alerts or filtering actions. The overall goal of the rule is to help users recognize and avoid possible deceptive communications stemming from common traits of romance scams, particularly through well-known email platforms that foster anonymity for the sender.
Categories
- Web
- Cloud
- Identity Management
Data Sources
- User Account
- Web Credential
- Logon Session
- Network Traffic
- Application Log
Created: 2025-12-03