heroui logo

Attachment: Embedded MSG file with payment lure and newly registered domain

Sublime Rules

View Source
Summary
Detects inbound messages containing an .msg attachment that itself contains an embedded email. The embedded message is crafted to enable financial fraud (BEC) by combining payment-related lure language (ACH/wire transfers, remittance, invoices, or urgency-based payment discounts) with a link to a domain registered within the last 30 days. The embedded message must satisfy a 2-of-conditions pattern: two or more indicators from (a) payment/financial terms (ACH, wire transfer, remittance, invoice), (b) invoice-related language (e.g., "invoice"), (c) urgency-based payment phrases (e.g., "payment discount", "by today", "end of day"), or (d) an ML/NLU cue such as a topic named "Request to View Invoice". Additionally, the embedded message references a newly registered domain by including a URL that resolves to a domain with Whois days_old < 30. The rule combines file/content analysis with URL analysis and Whois/NLU to detect potential fraud payloads evading detection by hiding them inside forwarded/attached messages. Attack type: BEC/Fraud. Tactics: Social engineering, Evasion. Detection methods: File analysis, Content analysis, URL analysis, Whois, Natural Language Understanding.
Categories
  • Endpoint
Data Sources
  • File
  • Network Traffic
  • Domain Name
Created: 2026-09-26