
Summary
Detects inbound PDF attachments that embed URLs with query strings encoded in a base64-like token, decodes to a single empty-valued parameter, and triggers on PDFs in inbound traffic. Specifically, it targets PDFs where an embedded URL has a path of '/' and a query string matching an 8-character base64-like pattern ([A-Fa-f0-9+/]{8}). After decoding, the rule requires exactly one decoded query_param and all decoded values to be empty strings, indicating an evasion technique used to conceal a credential-phishing link within the PDF. The rule leverages file- and URL-analysis on inbound attachments to surface this pattern.
Categories
- Endpoint
Data Sources
- File
Created: 2026-10-06