-
Notifications
You must be signed in to change notification settings - Fork 50
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create impersonation_benefits_enrollment.yml #2130
base: main
Are you sure you want to change the base?
Conversation
/update-test-rules |
Create impersonation_benefits_enrollment.yml by @aidenmitchell #2130 Source SHA 50c11df Triggered by @aidenmitchell
/update-test-rules |
Create impersonation_benefits_enrollment.yml by @aidenmitchell #2130 Source SHA d2b2e55 Triggered by @aidenmitchell
/update-test-rules |
Create impersonation_benefits_enrollment.yml by @aidenmitchell #2130 Source SHA 9b89fd8 Triggered by @aidenmitchell
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
found a few samples in the wild using malicious attachments with empty/benign subjects and message body.
- https://platform.sublime.security/messages/f28905d065c6a8ac54109c8c850d2a24e27a27fc651061abf5c135e23c51ec15 (body.current_text comes back as null)
- https://platform.sublime.security/messages/b84df9f811c52dea9327dceccb98fc7b0f455bd6013df933bb5ec19d826bcdf1
- https://platform.sublime.security/messages/4139cb3009eba87cf128840f2fc25b7d5389df72fc025f9b8578ae4d1f19a8f6
- https://platform.sublime.security/messages/688d19813d7d760f44100fe7480b1d80db36879cc3a474497077d3a193f1f82d
- https://platform.sublime.security/messages/e09bc9481c23dce2455a4c499bef4648b401bf7ad09c3bc1dbf615c415cc219d
@peterdj45 is going to open a PR against this PR for these changes, makes for an easier time in GH... lol |
Co-authored-by: Aiden Mitchell <me@aidenmitchell.ca>
/update-test-rules |
Create impersonation_benefits_enrollment.yml by @aidenmitchell #2130 Source SHA df9c68a Triggered by @aidenmitchell
Description
Detects messages about benefit enrollment periods and healthcare selections from external senders that contain urgent language or requests for action. Excludes legitimate HR communications, marketing mailers, and trusted sender domains with valid authentication.
Associated samples