Skip to content

Commit

Permalink
New Rule: Link to auto-downloaded DMG in archive (#1063)
Browse files Browse the repository at this point in the history
Co-authored-by: ID Generator <[email protected]>
  • Loading branch information
morriscode and ID Generator authored Nov 30, 2023
1 parent 2edd3f9 commit 6b083c2
Showing 1 changed file with 48 additions and 0 deletions.
48 changes: 48 additions & 0 deletions detection-rules/link_download_dmg_in_archive.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
name: "Link to auto-downloaded DMG in archive"
description: "A link in the body of the message downloads an archive containing a DMG file. The message is not from a common or trusted sender and is unsolicited."
type: "rule"
severity: "medium"
source: |
type.inbound
and any(body.links,
any(beta.linkanalysis(.).files_downloaded,
.file_extension in~ $file_extensions_common_archives
and any(file.explode(.), .file_extension == "dmg")
)
)
and (
(
profile.by_sender().prevalence != "common"
and not profile.by_sender().solicited
)
or (
profile.by_sender().any_messages_malicious_or_spam
and not profile.by_sender().any_false_positives
)
)
// negate highly trusted sender domains unless they fail DMARC authentication
and (
(
sender.email.domain.root_domain in $high_trust_sender_root_domains
and (
any(distinct(headers.hops, .authentication_results.dmarc is not null),
strings.ilike(.authentication_results.dmarc, "*fail")
)
)
)
or sender.email.domain.root_domain not in $high_trust_sender_root_domains
)
tags:
- "Attack surface reduction"
attack_types:
- "Malware/Ransomware"
tactics_and_techniques:
- "Evasion"
detection_methods:
- "Archive analysis"
- "File analysis"
- "Sender analysis"
- "URL analysis"
id: "dc04cdd8-6023-578b-a0d5-c59f4b76cacd"

0 comments on commit 6b083c2

Please sign in to comment.