social-engineering-filename-lure
The practice of naming a malicious file with a theme that exploits the victim's professional context or urgency — invoices, payments, shipping documents, purchase orders, HR notices, IT updates — to increase the likelihood of execution. Often combined with double-extension-masquerade or version-info-masquerade to further lower suspicion.
Common Themes
- Banking / payment proof (
Proof_of_payment,Bank_Advice,Invoice) - Logistics / shipping (
DHL,FedEx,Shipping_Documents) - Procurement (
PO,Purchase_Order,Quotation) - HR / payroll (
Payslip,Holiday_Notice,Contract) - IT / security (
Update,Patch,Security_Notice)
Observed in
- unclassified-dotnet — payment-cancelled, DHL shipping, purchase-order, and Indonesian banking-slip (
Slip_Pembayaran.exe) lures. ^[/intel/analyses/b094a2b61576904f86948cebe5b0d49198f0da3b6a851574f9fede93bef28285.html] - unclassified-dotnet-chess-engine —
160820242003464366.pdf.exe— Czech chess-game lure distributing a signed .NET bitboard engine. ^[/intel/analyses/7d18d78c5cd6a14d0d70d5454d54b178860dc4b74cd0212c0f9e533368ecaf01.html] - brooter —
SALES_INQUIRY.pdf.exe— procurement-themed lure distributing a Russian Delphi brute-forcing tool. ^[/intel/analyses/b04aa5d0ede5653b20f6db6d6df0020e396dfe8688f2c4712cff6dccce2002d4.html]