
Summary
Detects inbound emails that carry an encrypted PDF attachment where the cracked password is disclosed in the email body, paired with a small number of embedded URLs that are flagged for credential theft risk. The rule requires: (1) an encrypted PDF attachment with a non-null cracked_password in the PDF metadata and a match to the password present in the email body, (2) the attachment’s URLs count is limited (≤3), and (3) at least one of those URLs either points to a domain registered within the last 90 days (via WHOIS) or triggers an ML/NLU-based cred_theft signal from a link analysis of the rendered link text with an aggressive configuration. The rule leverages file analysis to inspect PDFs, content analysis on the email body, WHOIS/domain age checks, URL analysis, and Natural Language Understanding to evaluate link intents. It is categorized for Credential Phishing with associated techniques around PDF use, encryption, evasion, and social engineering, and flagged with detection methods including file, content, WHOIS, URL analysis, and NLU for comprehensive correlation of encrypted credential-themed phishing attempts."
Categories
- Endpoint
- Network
Data Sources
- File
- Domain Name
- Network Traffic
Created: 2026-10-08