
Summary
This rule detects inbound messages that carry PDF attachments and match a predefined YARA signature named pdf_red_adobe_lure, identifying Adobe-themed lure content used for credential phishing. It triggers when the event type is inbound and an attachment exists with file_type "pdf". The rule then expands (file.explode) the file and evaluates the YARA scan for a match, specifically checking for a detection named pdf_red_adobe_lure. When such a match is found, it flags the message as suspicious, indicating a potential credential-phishing attempt embedded in a PDF. The intent is to surface socially engineered documents that imitate Adobe-related content to deceive recipients into revealing credentials. The rule relies on YARA-based file analysis of attachments and is categorized under Credential Phishing with tactics around PDF handling and social engineering. False positives may arise if legitimate PDFs inadvertently trigger the signature, so triage should consider sender context and attachment content. Recommended responses include inspecting the attachment in a sandbox, quarantining suspicious messages, and user awareness training to recognize lure patterns.
Categories
- Endpoint
Data Sources
- File
Created: 2026-10-09