Detection rules › Sublime MQL

Brand impersonation: ukr[.]net

Severity
medium
Type
rule
Source
github.com/sublime-security/sublime-rules

Impersonation of ukr[.]net. Originally reported by CERT-UA on 07 March, 2022, phishing emails impersonate ukr[.]net to steal user credentials. "Compromised mailboxes are used by the Russian Federation's special services to conduct cyber attacks on citizens of Ukraine."

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesCredential Phishing
Tactics and techniquesImpersonation: Brand, Social engineering

Event coverage

Rule body MQL

type.inbound
and (
  (
    // technique
    strings.ilike(sender.display_name, "ukr*net")
    and sender.email.domain.root_domain != "ukr.net"
  )
  or (
    // IOCs
    subject.subject == "Увага"
    and (
      sender.email.email in (
        "muthuprakash.b@tvsrubber.com",
        "rakesh.ict@msruas.ac.in",
        "omars@salecharter.net",
        "citi.in.pm@xerago.com",
        "qs@gsengint.com",
        "sec.ls@msruas.ac.in",
        "vaishnavi.kj@tvsrubber.com",
        "nshcorp@nshcorp.in",
        "purchase2@hitechelastomers.com",
        "productionbelgavi@hodekindia.com",
        "narayanababu.py.ph@msruas.ac.in",
        "roopa.tsld@msruas.ac.in",
        "in-nonciti.basupport@xerago.com",
        "info@empiink.com",
        "pooja.fa@msruas.ac.in",
        "babu.d@tvsrubber.com",
        "systeam@xerago.com",
        "dean.ds@msruas.ac.in",
      )
      or any(body.links, .href_url.domain.domain == "consumerspanel.frge.io")
    )
  )
)

Detection logic

Scope: inbound message.

Impersonation of ukr[.]net. Originally reported by CERT-UA on 07 March, 2022, phishing emails impersonate ukr[.]net to steal user credentials. "Compromised mailboxes are used by the Russian Federation's special services to conduct cyber attacks on citizens of Ukraine."

  1. inbound message
  2. any of:
    • all of:
      • sender.display_name matches 'ukr*net'
      • sender.email.domain.root_domain is not 'ukr.net'
    • all of:
      • subject.subject is 'Увага'
      • any of:
        • sender.email.email in ('muthuprakash.b@tvsrubber.com', 'rakesh.ict@msruas.ac.in', 'omars@salecharter.net', 'citi.in.pm@xerago.com', 'qs@gsengint.com', 'sec.ls@msruas.ac.in', 'vaishnavi.kj@tvsrubber.com', 'nshcorp@nshcorp.in', 'purchase2@hitechelastomers.com', 'productionbelgavi@hodekindia.com', 'narayanababu.py.ph@msruas.ac.in', 'roopa.tsld@msruas.ac.in', 'in-nonciti.basupport@xerago.com', 'info@empiink.com', 'pooja.fa@msruas.ac.in', 'babu.d@tvsrubber.com', 'systeam@xerago.com', 'dean.ds@msruas.ac.in')
        • any of body.links where:
          • .href_url.domain.domain is 'consumerspanel.frge.io'

Inspects: body.links, body.links[].href_url.domain.domain, sender.display_name, sender.email.domain.root_domain, sender.email.email, subject.subject, type.inbound. Sensors: strings.ilike.

Indicators matched (21)

FieldMatchValue
strings.ilikesubstringukr*net
subject.subjectequalsУвага
sender.email.emailmembermuthuprakash.b@tvsrubber.com
sender.email.emailmemberrakesh.ict@msruas.ac.in
sender.email.emailmemberomars@salecharter.net
sender.email.emailmemberciti.in.pm@xerago.com
sender.email.emailmemberqs@gsengint.com
sender.email.emailmembersec.ls@msruas.ac.in
sender.email.emailmembervaishnavi.kj@tvsrubber.com
sender.email.emailmembernshcorp@nshcorp.in
sender.email.emailmemberpurchase2@hitechelastomers.com
sender.email.emailmemberproductionbelgavi@hodekindia.com
9 more
sender.email.emailmembernarayanababu.py.ph@msruas.ac.in
sender.email.emailmemberroopa.tsld@msruas.ac.in
sender.email.emailmemberin-nonciti.basupport@xerago.com
sender.email.emailmemberinfo@empiink.com
sender.email.emailmemberpooja.fa@msruas.ac.in
sender.email.emailmemberbabu.d@tvsrubber.com
sender.email.emailmembersysteam@xerago.com
sender.email.emailmemberdean.ds@msruas.ac.in
body.links[].href_url.domain.domainequalsconsumerspanel.frge.io