
Summary
Detects inbound messages containing an .msg attachment that itself contains an embedded email. The embedded message is crafted to enable financial fraud (BEC) by combining payment-related lure language (ACH/wire transfers, remittance, invoices, or urgency-based payment discounts) with a link to a domain registered within the last 30 days. The embedded message must satisfy a 2-of-conditions pattern: two or more indicators from (a) payment/financial terms (ACH, wire transfer, remittance, invoice), (b) invoice-related language (e.g., "invoice"), (c) urgency-based payment phrases (e.g., "payment discount", "by today", "end of day"), or (d) an ML/NLU cue such as a topic named "Request to View Invoice". Additionally, the embedded message references a newly registered domain by including a URL that resolves to a domain with Whois days_old < 30. The rule combines file/content analysis with URL analysis and Whois/NLU to detect potential fraud payloads evading detection by hiding them inside forwarded/attached messages. Attack type: BEC/Fraud. Tactics: Social engineering, Evasion. Detection methods: File analysis, Content analysis, URL analysis, Whois, Natural Language Understanding.
Categories
- Endpoint
Data Sources
- File
- Network Traffic
- Domain Name
Created: 2026-09-26