
Summary
Detects inbound email whose Received header chain traverses IP space announced by Aeza Group LLC, a bulletproof hosting provider designated by OFAC on 2025-07-01. The rule lists IPv4 and IPv6 prefixes associated with Aeza’s ASNs (AS210644, AS216246) as of 2026-08-05 and employs a beta feature (beta.ip_in) to test whether any IPs in the mail’s Received header path fall within those prefixes. If a path IP matches any of the CIDRs, the rule fires an alert indicating potential abuse linked to OFAC-sanctioned infrastructure. The configuration explicitly notes the OFAC reference and uses a broad CIDR set to cover Aeza’s announced space. Detection targets inbound mail traffic by analyzing header IPs and the sender, relying on header analysis and sender analysis methods. The rule flags risks commonly associated with bulletproof hosting, including BEC/Fraud, credential phishing, and malware/ransomware campaigns. The beta feature is highlighted as experimental and subject to change. Attack types include BEC/Fraud, Credential Phishing, Malware/Ransomware; Tactics and techniques include Evading detection and Social engineering, underscoring the deceptive use of compromised or spoofed emails. The rule’s data source is Network Traffic, and the detection is framed around header- and sender-based evidence of IPs transiting Aeza Group’s sanctioned address space. References point to OFAC’s action page for context and verification.
Categories
- Network
Data Sources
- Network Traffic
Created: 2026-08-06