diff --git a/detection-rules/impersonation_amazon.yml b/detection-rules/impersonation_amazon.yml index f4ef7367cd7..961920a4aef 100644 --- a/detection-rules/impersonation_amazon.yml +++ b/detection-rules/impersonation_amazon.yml @@ -16,7 +16,7 @@ source: | ) and ( regex.icontains(sender.display_name, - '\b[aaa๐ฐa๏ฝ๐‘Ž๐—ฎ๐•’๐–†๐“ช๐šŠ๐žชะฐษ‘ฮฑ๐”ž๐’‚๐˜ข๐›‚โบ๐’ถ๐™–๐œถ๐›ผ๐š๐–บ]maz[o0]n\s?(pay|marketplace|\.com)|แตƒโคปแถป' + '\b[aaa๐ฐa๏ฝ๐‘Ž๐—ฎ๐•’๐–†๐“ช๐šŠ๐žชะฐษ‘ฮฑ๐”ž๐’‚๐˜ข๐›‚โบ๐’ถ๐™–๐œถ๐›ผ๐š๐–บ]maz[o0]n\s?(pay|marketplace|\.com|\.\w{2}\b|\.co\.\w{2})|แตƒโคปแถป' ) or strings.ilevenshtein(sender.display_name, 'amazon.com') <= 1 or strings.ilevenshtein(sender.display_name, 'amazon pay') <= 1