EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Brand impersonation: Sharepoint

Body, attached images or pdf contains a Sharepoint logo. The message contains a link and credential theft language.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Sharepoint fake file share

This rule detects messages impersonating a Sharepoint file sharing email where no links point to known Microsoft domains.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimemedium

Brand impersonation: SharePoint PDF attachment with credential theft language

PDF attachment contains SharePoint logo and high-confidence credential theft language detected via OCR analysis. The attachment includes URLs and originates from an unsolicited or low-reputation sender, excluding legitimate SharePoint file sharing notifications.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Brand Impersonation: Shein

Detects suspicious Shein-branded communications using display name impersonation, logo detection, and deceptive content analysis. Includes checks for security/authentication topics, secure messages, notifications, and promotional content like fake surveys or giveaways. Excludes legitimate Shein domains with proper authentication and known trusted senders.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Silicon Valley Bank

Detects emails that impersonate Silicon Valley Bank

T1566T1566.001T1566.002T1598T1598.003+1
Sublimemedium

Brand impersonation: SiriusXM

Impersonation of the broadcasting corporation SiriusXM.

T1566.003T1598T1566T1566.001T1566.002+1
Sublimemedium

Brand impersonation: Social Security Administration

Detects messages impersonating the Social Security Administration (SSA) through various indicators including display names, subjects, body content, attachments, and HTML titles. The rule identifies SSA references, confusable characters, statement notifications, and credential theft language while excluding legitimate government communications.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Brand impersonation: SoFi

Detects messages impersonating SoFi by analyzing sender display name, domain, body content including specific address references and phone numbers, while excluding legitimate SoFi communications with proper DMARC authentication.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Spotify

Impersonation of Spotify.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimelow

Brand impersonation: Square

Impersonation of Square, typically containing security-related language, secure message notifications, or credential theft indicators from unauthorized senders.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Squarespace

Detects impersonation of Squarespace through sender display name or subject line similarity, where the sender is not from legitimate Squarespace domains or fails authentication checks.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: State Farm

Detects messages impersonating State Farm insurance company through display name spoofing or similar variations, excluding legitimate communications from verified State Farm domains with proper DMARC authentication.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Stellar Development Foundation (SDF)

Attack impersonating Stellar Development Foundation (SDF).

T1566T1566.001T1566.002T1598T1598.003
Sublimelow

Brand Impersonation: Stripe

Impersonation of Stripe, usually for credential theft.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimehigh

Brand impersonation: Stripe notification

Campaigns have been observed sending templated Stripe notification emails with the call-to-action button link replaced, clicking through to a malicious credential phishing page.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Brand impersonation: Sublime Security

Possible attempt to impersonate Sublime Security executives.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimehigh

Brand impersonation: Survey request with credential theft indicators

Detects messages containing credential theft language disguised as survey requests from promotional content, targeting organizations from untrusted or spoofed high-trust domains.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: TikTok

Detects messages impersonating TikTok through similar display names or logo detection, combined with security-themed content and authentication failures. Excludes legitimate TikTok communications and trusted senders.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Toronto-Dominion Bank

Impersonation of TD Bank or TD Canada Trust using display name spoofing or logo detection, combined with suspicious content related to security authentication or credential theft from unauthorized senders.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Trust Wallet

Detects inbound messages containing links where the sender impersonates Trust Wallet through display name manipulation and suspicious language, while not being from legitimate Trust Wallet domains. The rule checks for credential theft patterns and validates sender authentication.

T1566.002T1534T1656T1566T1566.001+2
Sublimehigh

Brand impersonation: TurboTax

Impersonation of the TurboTax service from Intuit. Most commonly seen around US tax season (Q1).

T1566T1566.001T1566.002T1598T1598.003+1
Sublimelow

Brand impersonation: Twitter

Impersonation of Twitter.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimemedium

Brand impersonation: UK government Home Office

Detects messages impersonating UK government agencies (Home Office, UK Visas and Immigration, gov.uk) that contain links not leading to legitimate gov.uk domains or show credential theft language, from senders not authenticated as official government domains.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Brand impersonation: ukr[.]net

Impersonation of ukr[.]net. Originally reported by CERT-UA on 07 March, 2022, phishing emails impersonate ukr[.]net to steal user credentials. "Compromised mailboxes are used by the Russian Federation's special services to conduct cyber attacks on citizens of Ukraine."

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium
PreviousPage 19 of 53Next