
Summary
Detects inbound messages containing PDF attachments that trigger a YARA-based detection for signature reuse. The rule filters inbound messages by attachments with file_type set to pdf, explodes the file content, and runs a YARA scan to find matches. It specifically looks for any YARA match whose rule name is pdf_w9_signatures. When such a match is found, the event is flagged with medium severity under BEC/Fraud, aligning with PDF-related social engineering techniques used in fraud schemes. Detection methods include File analysis and YARA. This aims to detect attempts to reuse W-9 signatures embedded in PDFs to impersonate legitimate entities. Note potential false positives if legitimate PDFs contain similar patterns; consider tuning the YARA rule and corroborating with email context, attachment reputation, and downstream workload actions (quarantine, review).
Categories
- Network
- Endpoint
Data Sources
- File
Created: 2026-09-28