Yara-Rules/rules

[BUG] email/bank_rule.yar is problematic

kprkpr opened this issue · 1 comments

Describe the bug
This bank_rule detects all that has the "davivienda" name, but this is the name of a real bank https://www.davivienda.com/
Then, all mail that says something about paying to this bank or similar, would be banned, and it happened at my work..

Maybe this rule is too much aggresive and can be joined with other parameters to know that is spam or so, or not has sense
Thanks!

You are right that rule is to open, even though it was used to identify phishing. I'll move it to the deprecated folder.