heroui logo

Impersonation: HR administrative center PDF password lure

Sublime Rules

View Source
Summary
Technical summary: This inbound rule detects phishing messages impersonating a companyHR administrative center, often referencing payroll, policy, or compliance updates, and leveraging a password‑protected PDF attachment. It triggers when either of two patterns is found: 1) the message body includes placeholders {COMPANYNAME} and {PDFKEY}, and the subject base contains a numeric token {NUMBER10} or the sender's display name includes the company name, a random 25-character string, or a numeric token; or 2) the body contains a password‑lure phrase matching your_.{1,20}-pdf password => (case‑insensitive) or the subject contains hr administrative center-\d, and the sender's display name includes three or more combining diacritical marks or matches a pattern like |-1\d{8,}. The rule uses content analysis, header analysis, and sender analysis to flag such messages, classifies as Credential Phishing, and notes impersonation, PDF usage, social engineering, and evasion techniques as tactics. The intended effect is to intercept messages attempting to lure recipients into decrypting a PDF to obtain credentials, while attackers may rely on lookalike domains or compromised infrastructure and obfuscated sender names to evade filters.
Categories
  • Web
Data Sources
  • File
  • Domain Name
Created: 2026-08-29