EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: PDF with QR code containing recipient-specific credential theft content

Detects PDF attachments containing QR codes that include the recipient's email address (either plaintext or base64 encoded) combined with credential theft language detected through natural language processing. This technique personalizes the attack by incorporating the target's email into the QR code URL while using PDF content to establish credibility.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: PDF with quote lure

Detects PDF attachments containing quote-themed lure content.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Attachment: PDF with recipient email in link

Detects PDF attachments that contain the recipient's domain in the filename and include a link personalized with the recipient's email address, either in the URL directly, encoded in base64, or within a QR code.

T1566T1566.001T1566.002T1598T1027+1
Sublimehigh

Attachment: PDF with ReportLab library and default metadata

Detects PDF attachments generated using the ReportLab PDF Library with default anonymous metadata values, including untitled document, anonymous creator/author, and unspecified subject. This combination of characteristics is commonly associated with automated PDF generation tools used in malicious activities.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Attachment: PDF With SAI Global ISO9001 Logo

Detects PDF attachments containing embedded SAI Global ISO9001 logos, which may indicate brand impersonation or fraudulent certification claims.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Attachment: PDF with secure document acknowledgment prompt

Detects PDF attachments matching yara rules looking for fake secure document prompts, including acknowledgment-style lures and suspicious image sizing.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Attachment: PDF with self-service platform links with self sender or blank recipients

Detects single-page PDF attachments containing links to self-service content creation platforms, sent to either the sender's own email address or an invalid email domain. This pattern may indicate testing of malicious content or preparation for distribution.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Attachment: PDF with specific author metadata

Detects inbound messages containing PDF attachments where the EXIF metadata indicates the author or creator is 'Shelby Porter'.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: PDF with specific W-9 lure

Detects PDF attachments containing W-9 related lures. This one is looking for signatures that have been observed across multiple samples.

T1566.002T1534T1656T1566T1598
Sublimemedium

Attachment: PDF with split QR code

Detects PDF attachments containing split QR codes positioned close together, a technique used to evade detection while maintaining QR code functionality for credential theft.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: PDF with suspicious document view lure

Detects PDF attachments containing a title box designed to lure recipients into viewing a document, a common social engineering technique used to direct users to malicious content.

T1566.001T1204.002T1486T1566T1598
Sublimemedium

Attachment: PDF with suspicious HeadlessChrome metadata

Detects PDF attachments created by HeadlessChrome with suspicious characteristics, including MD5-formatted HTML filenames or blank titles with Windows Skia/PDF producer, excluding legitimate Google Docs files.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Attachment: PDF with suspicious internal object reference identifier

Detects inbound messages containing PDF attachments with a specific internal object reference identifier pattern, which may indicate a crafted or malicious PDF file.

T1566.002T1534T1656
Sublimemedium

Attachment: PDF with suspicious language and redirect to suspicious file type

Attached PDF contains credential theft language, and links to an open redirect to a suspicious file type. This has been observed in-the-wild as a Qakbot technique.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimehigh

Attachment: PDF with suspicious link and action-oriented language

Detects PDF attachments containing a single link that leads to pages with language prompting users to view, review, or read documents, accounts, or business-related content such as bids, proposals, agreements, or contracts.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: PDF with suspicious view document characteristics

PDF attachment contains suspicious characteristics commonly associated with document viewing lures, as detected by YARA pattern matching.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Attachment: PDF with View RFP Document lure with external link

Detects inbound emails containing a PDF attachment that references a 'VIEW RFP DOCUMENT' lure and embeds a URL pointing to a domain that differs from the sender's domain, a pattern consistent with document-based social engineering used to redirect recipients to attacker-controlled infrastructure.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: PDF with W-9 form indicators

Detects inbound messages containing PDF attachments that match structural or signature patterns consistent with specific W-9 tax lure activity sets.

T1566.002T1534T1656T1566T1598+1
Sublimehigh

Attachment: Potential sandbox evasion in Office file

Scans attached files with known Office file extension, and alerts on the presence of strings indicative of sandbox evasion checks. Malicious code may carry out checks against the local host (e.g. running processes, disk size, domain-joined status) before running its final payload.

T1566.001T1204.002T1486T1036T1027+1
Sublimehigh

Attachment: PowerPoint with suspicious hyperlink

Attached PowerPoint contains a suspicious hyperlink that can execute arbitrary code.

T1566.001T1204.002T1486T1036T1027+1
Sublimehigh

Attachment: PowerShell content

Recursively scans files and archives to detect PowerShell content. While scripts are often blocked by mail filtering, alternative file formats and archived content may be employed to bypass such controls.

T1566.001T1204.002T1486T1059
Sublimehigh

Attachment: Python generated PDF with link

The PDF attachment was created with a Python-based script and contains one or more links. These techniques were used by PikaBot, among others.

T1036T1027
Sublimemedium

Attachment: QR code link with base64-encoded recipient address

Detects when an image or macro attachment contains QR codes that, when scanned, lead to URLs containing the recipient's email address. This tactic is used to uniquely track or target specific recipients and serve tailored credential phishing pages.

T1566T1566.001T1566.002T1598T1036+3
Sublimehigh

Attachment: QR code with credential phishing indicators

Detects messages with between 1-3 attachments containing a QR code with suspicious credential theft indicators, such as: LinkAnalysis credential phishing conclusion, decoded QR code url traverses suspicious infrastructure, the final destination is in URLhaus, decoded URL downloads a zip or executable, leverages URL shorteners, known QR abused openredirects, and more.

T1566T1566.001T1566.002T1598
Sublimemedium
PreviousPage 10 of 53Next