heroui logo

Attachment: PDF Object Hash - Encrypted PDF with blue doc icon

Sublime Rules

View Source
Summary
This rule detects inbound messages that include a PDF attachment with a PDF object structure matching a known malicious object hash (24012ed37455f6b8581bae5c6fed0a6f). It filters on attachments with file_type == "pdf" and then inspects the PDF content by exploding the file structure to access the embedded PDF object hash (scan.pdf_obj_hash.object_hash). If the hash equals the specified value, the rule raises a detection. The detection method is File analysis and the rule is categorized under Credential Phishing with a PDF tactic/technique. The intended lure is a PDF with a blue document icon. The alert is rated medium severity. Practically, this targets inbound phishing attempts attempting to deliver a malicious PDF and relies on a known object-hash signature; operators should be aware of potential false positives if legitimate PDFs reuse similarly structured object components, though object-hash matching is relatively specific to a given PDF structure.
Categories
  • Application
Data Sources
  • File
Created: 2026-10-09