
Summary
This rule flags inbound emails from free webmail senders that use personalized, legitimate-looking invoice/order lures. It requires the recipient's email local-part to be present and for at least one attachment filename to be structured with a date-like prefix (starting with 202), followed by an underscored recipient identifier and an alphanumeric code. The filename must also contain the recipient's local-part delimited by underscores and include exactly two underscores in total, with the file extension present. The pattern is checked case-insensitively to detect attachments whose names appear as individualized invoices or receipts tailored to the target. The detection relies on file/attachment analysis, content inspection, and sender context to identify social-engineering attempts using free-webmail channels and brand impersonation.
Categories
- Web
- Endpoint
Data Sources
- File
Created: 2026-09-28