heroui logo

Attachment: PDF Object Hash - Generic MSFT lure

Sublime Rules

View Source
Summary
Technical summary: This rule detects inbound emails containing PDF attachments whose embedded PDF object hash matches a known hash associated with generic Microsoft lure campaigns. It fires on type.inbound events where there is any attachment with file_type == "pdf" and, for the exploded file, the scan.pdf_obj_hash.object_hash equals fc52ac1737c442a200c7392061766221. Detection uses file analysis to extract PDF object hashes and compare them against the specified value. The rule targets credential phishing attempts delivered via malicious PDFs and leverages a fixed hash match to flag known lure variants. Severity is medium. Domain is set to Endpoint and Network to reflect both the host processing the email and the network ingress context. Data source is File, reflecting attachment/file content analysis. Keywords emphasize PDF object-hash matching and phishing context.
Categories
  • Endpoint
  • Network
Data Sources
  • File
Created: 2026-10-02