
Summary
This rule detects inbound messages that deliver PDF attachments which match a specific YARA signature named quickbooks_pdf_payment_lure. It targets scenarios where an inbound message contains a PDF, expands nested file content, and applies a YARA scan to identify QuickBooks-themed payment lure content. A match indicates potential brand impersonation and social engineering aimed at BEC/fraud or delivering malware, using PDF-based lure content to deceive QuickBooks users. The detection relies on YARA-based file analysis of attachments to flag these lures.
Categories
- Endpoint
Data Sources
- File
Created: 2026-08-21