heroui logo

Subject and sender display name contains matching long alphanumeric string

Sublime Rules

View Source
Summary
This detection rule identifies instances where both the subject line of an email and the display name of the sender contain identical long alphanumeric strings, specifically strings ranging from 32 to 64 characters in length. This consistency between the two fields can suggest that the email content is either automatically generated or that there is coordinated manipulation being employed to enhance the plausibility of the email, often associated with malicious intents such as phishing or dissemination of malware. By employing regex extraction techniques, the rule scans the subject line for such patterns and checks if the sender's display name matches these strings. Given that both fields align in this manner, it serves as an indicator for further scrutiny, reflecting potential attempts at social engineering or evasion tactics typical of cyber threats involving malware or credential phishing campaigns. This rule reports on low severity, emphasizing reliance on content and header analysis to detect these patterns.
Categories
  • Cloud
  • Web
  • Identity Management
  • On-Premise
  • Endpoint
Data Sources
  • Application Log
  • Network Traffic
Created: 2025-12-09