heroui logo

Attachment: PDF Grant Payment lure with embedded link

Sublime Rules

View Source
Summary
This rule detects inbound emails that carry a PDF attachment referencing a Grant Payment Development RFP or bid solicitation and contain an embedded URL intended to redirect to a credential-harvesting or malicious landing page presented as bid documentation. Detection requires three conditions: (1) an inbound message with a PDF attachment, (2) the PDF’s extracted text includes the phrase 'Grant Payment Development', and (3) at least one embedded URL is present within the file. This combination is characteristic of credential-phishing lures targeting education-sector accounts (often from compromised or spoofed domains). The rule uses file analysis to inspect the PDF content, content analysis to confirm the specific phrase, and URL analysis to verify embedded links. When triggered, it reflects a credential-phishing tactic that leverages social engineering via document-centric lure. Mitigation considerations include scanning and quarantining such messages, validating sender authenticity (SPF/DKIM/DMARC), and blocking or sinkholing embedded URLs associated with credential-harvesting sites.
Categories
  • Endpoint
  • Network
Data Sources
  • File
Created: 2026-08-27