|
1 | | -name: "PR# 4307 - Link: Spanish tax document lure with suspicious domains" |
2 | | -description: "Detects messages containing Spanish tax document language that link to suspicious domains including URL shorteners, free file hosts, or newly registered domains." |
| 1 | +name: "PR# 4307 - Link: Tax document lure (Multi-Language) with suspicious domains" |
| 2 | +description: "Detects messages in various languages containing tax document phrases that link to suspicious domains including URL shorteners, free file hosts, or newly registered domains." |
3 | 3 | type: "rule" |
4 | 4 | severity: "high" |
5 | 5 | source: | |
6 | 6 | type.inbound |
7 | 7 | and 0 < length(body.links) < 15 |
8 | 8 | and length(recipients.to) == 1 |
9 | 9 | and recipients.to[0].email.domain.valid |
10 | | - // spanish tax document phrases |
11 | | - and regex.icontains(body.current_thread.text, |
12 | | - '(?:Acessar Documento|Documento Fiscal|documento tributario|documento de impuestos|comprobante fiscal|constancia fiscal|declaración de impuestos|formulario fiscal|documentación fiscal|registro fiscal|certificado fiscal)' |
| 10 | + and ( |
| 11 | + // italian tax document phrases |
| 12 | + regex.icontains(body.current_thread.text, |
| 13 | + '(?:documento fiscale|documento tributario|documento delle imposte|modulo fiscale|dichiarazione dei redditi|documentazione fiscale|certificato fiscale|ricevuta fiscale|prova fiscale|atto fiscale|registro fiscale|pratica fiscale|carta fiscale|carte fiscali)' |
| 14 | + ) |
| 15 | + // italian tax document phrases |
| 16 | + or regex.icontains(body.current_thread.text, |
| 17 | + '(?:Steuerdokument|Steuerunterlage|Steuerdokumente|Steuerformular|Steuerbescheid|Steuererklärung|Steuerunterlagen|Steuerbeleg|Steuernachweis|steuerliche Unterlagen|Finanzamtsunterlagen|Abgabenunterlagen|Steuerpapier|Steuerpapiere)' |
| 18 | + ) |
| 19 | + // french tax document phrases |
| 20 | + or regex.icontains(body.current_thread.text, |
| 21 | + '(?:document fiscal|document d\x27impôt|document d\x27impôts|document fiscal officiel|formulaire fiscal|déclaration d\x27impôt|déclaration d\x27impôts|déclaration fiscale|documents fiscaux|documentation fiscale|justificatif fiscal|attestation fiscale|certificat fiscal|avis d\x27imposition|avis fiscal)' |
| 22 | + ) |
| 23 | + // portuguese tax document phrases |
| 24 | + or regex.icontains(body.current_thread.text, |
| 25 | + '(?:documento fiscal|documento tributário|documento de imposto|documento de impostos|formulário fiscal|declaração de imposto|declaração de impostos|declaração fiscal|documentação fiscal|comprovante fiscal|certidão fiscal|certificado fiscal|registro fiscal|comprovativo fiscal)' |
| 26 | + ) |
| 27 | + // spanish tax document phrases |
| 28 | + or regex.icontains(body.current_thread.text, |
| 29 | + '(?:Acessar Documento|Documento Fiscal|documento tributario|documento de impuestos|comprobante fiscal|constancia fiscal|declaración de impuestos|formulario fiscal|documentación fiscal|registro fiscal|certificado fiscal)' |
| 30 | + ) |
| 31 | + // turkish tax document phrases |
| 32 | + or regex.icontains(body.current_thread.text, |
| 33 | + '(?:vergi belgesi|vergi belgeleri|vergi dokümanı|vergi dokümanları|vergi evrakı|vergi evrakları|vergi beyannamesi|vergi formu|vergi makbuzu|mali belge|mali evrak|vergi kaydı|vergi kayıt belgesi)' |
| 34 | + ) |
| 35 | + // chinese tax document phrases |
| 36 | + or regex.icontains(body.current_thread.text, |
| 37 | + '(?:税务文件|税务资料|税务证明|纳税文件|纳税资料|纳税证明|税务表格|税表|报税文件|报税资料|报税表格|税单|完税证明|完税文件|稅務文件|稅務資料|稅務證明|納稅文件|納稅資料|納稅證明|稅務表格|稅表|報稅文件|報稅資料|報稅表格|稅單|完稅證明|完稅文件)' |
| 38 | + ) |
| 39 | + // korean tax document phrases |
| 40 | + or regex.icontains(body.current_thread.text, |
| 41 | + '(?:税务文件|税务资料|税务证明|纳税文件|纳税资料|纳税证明|税务表格|税表|报税文件|报税资料|报税表格|税单|完税证明|完税文件|稅務文件|稅務資料|稅務證明|納稅文件|納稅資料|納稅證明|稅務表格|稅表|報稅文件|報稅資料|報稅表格|稅單|完稅證明|完稅文件)' |
| 42 | + ) |
| 43 | + // japanese tax document phrases |
| 44 | + or regex.icontains(body.current_thread.text, |
| 45 | + '(?:税務書類|税務文書|税務資料|納税書類|納税文書|納税資料|税申告書|納税申告書|税務申告書|税務フォーム|税務証明書|納税証明書|課税証明書|税関連書類)' |
| 46 | + ) |
| 47 | + // thai tax document phrases |
| 48 | + or regex.icontains(body.current_thread.text, |
| 49 | + '(?:เอกสารภาษี|เอกสารด้านภาษี|เอกสารทางภาษี|เอกสารสรรพากร|แบบฟอร์มภาษี|แบบแสดงรายการภาษี|เอกสารยื่นภาษี|เอกสารการยื่นภาษี|เอกสารชำระภาษี|หลักฐานภาษี|หลักฐานการเสียภาษี|หนังสือรับรองภาษี|หนังสือรับรองการหักภาษี ณ ที่จ่าย|ใบเสร็จภาษี|ใบกำกับภาษี)' |
| 50 | + ) |
| 51 | + // english (uk) tax document phrases |
| 52 | + or regex.icontains(body.current_thread.text, |
| 53 | + '(?:tax (?:paperwork|document|form|return|record|certificate|statement|notice)s?|HMRC (?:form|letter|document)s?)' |
| 54 | + ) |
13 | 55 | ) |
| 56 | + |
14 | 57 | // suspicious domains |
15 | 58 | and any(body.links, |
16 | 59 | .parser == 'hyperlink' |
|
0 commit comments