Because 35% of phishing emails do not ask for URL clicking, they ask for direct reply or interaction with the attachments.
Translated version:
Dear recipient:
I sent you this letter a month ago, but I haven't heard from you. I'm not sure if you received it, so I sent it again. First of all, I'm Mrs. Kristalina Georgieva, manager of a President of the International Monetary Fund.
In fact, we explore all the obstacles and problems around. Your incomplete transaction and your inability to pay the fees Transfer fees that were charged for previous transfer options, visit our confirmation page 38 °53′56′′S 77°2′39′′W.
We are the Board of Directors, the World Bank and the International Monetary Fund International Monetary Fund (IMF) in Washington, DC, together with the Department of United States Treasury Department and certain other investigative agencies Relevant here in the United States of America, we ordered To our foreign payments unit, United Bank of Africa Lome Togo to issue you a VISA card where $ 1.5 million of your fund for a larger withdrawal of your fund.
During our research, we found that s Consternation that your payment has been delayed by corrupt employees Bankers who were trying to divert their funds to their private accounts. And today we inform you that your fund has been credited to the card. VISA from UBA Bank and is also ready for delivery. Now Contact the director of UBA Bank, his name is Mr. Uzoka Kennedy, Email: ( www.ubabankheadoffice1@gmail.com ) To tell you how to get an ATM VISA CARD.
Sincerely,
Mrs. Kristalina Georgieva
Translated version:
Dear customer:
A pix transaction was requested, in the amount of R$ 1,220.00 for Simone De Araujo Souza. For security measures, we blocked this operation.
To authorise this transaction, Reply I Authorise
If you do not recognise this transaction, call 0800-000-3973 and talk to a digital manager from the NUBANK security sector. Request the cancellation of unrecognised operations and the protection of your account.
Security protocol: 5742792323
Translated version:
To the Debtor, Donizetti Aparecido Gregorio Junior 50754003884 Rua Guariri 84 Casa 2 Vila Sao Carlos CEP 08.599-510 Itaquaquecetuba-SP Deadline for payment until 12/22/2022, after the deadline the title will be negative and sent for protest.
There is a debit in the amount of R$ 288.98 in the system, this debit refers to the SINGLE ASSOCIATIVE FEE - (Single Payment), the original amount of the debit was R$ 249.00 but as it was not paid at maturity, it was forwarded to the Legal Department and generated the costs.
According to the Creditor, the association took place on the day of the opening of the company where he was asked if he would like to join the Association of Companies of Itaquaquecetuba and the request was accepted, so this amount is really due.
Payment must be made through Pix using the QR Code that appears in the notification or through the Copy and Paste Pix Code, below is the Pix Copy and Paste, just copy and paste into your bank's PIX environment!
00020126890014BR.GOV.BCB.PIX0116pix@srcex.adv.br0247DONIZETTI APARECIDO GREGORIO JUNIOR 507540038845204000053039865406288.985802BR5913EXTRAJUDICIAL6008BRASILIA6216051258924155250563047D83
Attention!! The non-payment of the debt by the deadline MAY result in the cancellation of the registration.
Sincerely,
Rodrigo Silva
Notarial Service And Extrajudicial Reg Of Titles
We use the following prompt for identity recognition with Llama2:
"Step 1: Identify phrases that claim the identity of the sender (brand name or relation to the recipient such as colleague).
Step 2: Identify the call-to-action phrases.
Step 3: Identify the phrases that suggest the relation of sender to the recipient."
We find Llama has False Negative problem:
FN reason 1: misses call-to-action phrases
FN reason 2: reaches the generation limit during Step 1.
While increasing the generation limit could mitigate this issue, it would also lead to higher runtime costs. Notably, with the current limit of 50 tokens, the runtime cost is already 1.9 seconds.
Response by Llama:
Step 1: ['Administrator@no-reply.com']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['WeTransfer']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['Administrator@monkey.org', 'The Email Team']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['WeTransfer', 'WeTransfer']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['Email Server']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['monkey.org support']. Step 2: []. Step 3: []
Response by Llama:
Step 1: ['Wells Fargo', 'Wells Fargo Online', 'Wells Fargo Advisors', 'Wells Fargo Advisors Financial Network, LLC', 'Wells Fargo Bank, N"
Response by Llama:
Step 1: ['Huntington Bank', 'Huntington National Bank', 'Huntington Bancshares Incorporated', 'The Huntington logo', 'The Huntington logoHuntington
GPT lacks access to up-to-date, curated lists of official email addresses—particularly for smaller or niche organizations—so it will often infer that any semantically similar address (e.g., editorial.controleng@gmail.com) is legitimate, yet reject a real but differently formatted address (e.g., ia_rsv@trip.com)