heroui logo

Attachment: PDF with specific blurred lure

Sublime Rules

View Source
Summary
Detects inbound messages containing PDF attachments that match a YARA signature for a specific blurred credential-phishing lure. The rule targets inbound content, filters for attachments with file_type == "pdf", explodes nested file structures, and checks for YARA matches with the signature name pdf_blurred_cred_phish_lure. If a PDF attachment matches the signature, it raises a medium-severity alert indicating a potential credential-phishing attempt using a blurred document lure. The detection combines file analysis with YARA signature matching to identify targeted phishing content in inbound messages.
Categories
  • Network
  • Endpoint
Data Sources
  • File
Created: 2026-10-02