EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: QR code with encoded recipient targeting and redirect indicators

Detects QR codes in attachments that contain the recipient's email address (either plaintext or base64 encoded) and redirect through suspicious URI structures commonly associated with Kratos/SneakyLog redirection services.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: QR code with recipient targeting and special characters

Detects messages with QR code in attachments containing special characters in the path that include the recipient's email address in either the URL path or fragment, potentially encoded in base64. The URLs have a simple path structure and may end with suspicious patterns.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: QR code with suspicious URL patterns in EML file

Detects EML attachments containing QR codes that link to URLs with suspicious patterns, including specific alphanumeric combinations in subdomains and paths, or special characters followed by encoded terminators. These patterns are commonly used to evade detection in credential theft attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: QR code with userinfo portion

Detects inbound messages that contain image or document attachments with QR codes containing embedded usernames, passwords, or excessively padded URLs. This technique is used to bypass traditional text-based detection methods.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: QuickBooks PDF lure

Detects inbound messages containing PDF attachments that match YARA signatures identifying QuickBooks-themed lure content.

T1566.002T1534T1656T1566.001T1204.002+4
Sublimemedium

Attachment: RDP connection file

Recursively scans files and archives to detect RDP connection files. Coercing a target user into connecting to an attacker-owned RDP server can expose elements of their host and potentially lead to compromise.

T1566.001T1204.002T1486T1566T1566.002+1
Sublimemedium

Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender

This rule identifies messages with an RFC822 attachment contains language indicative of suspicious file-sharing activity. It checks both the original sender and the nested sender against highly trusted domains. The original message is unsolicited, and has not been previously flagged as a false positive.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: RFP/RFQ impersonating government entities

Attached RFP/RFQ impersonates a U.S. government department or entity to commit fraudulent transactions.

T1566.002T1534T1656T1598.003T1566+1
Sublimehigh

Attachment: Risk assessment PDF with inline image

Detects inbound messages containing a PDF attachment whose file name matches a 'risk assessment' naming pattern with an alphanumeric code, alongside an inline image attachment referenced via content ID in the HTML body. Messages from highly trusted sender domains that pass DMARC authentication are excluded.

T1566.001T1204.002T1486T1566T1598
Sublimehigh

Attachment: Romance scam with image lure and advance-fee or suspicious link indicators

Detects inbound messages that are not replies, forwards, or mailing list communications, and contain image attachments (JPG or PNG) alongside body text classified as romantic or sexually explicit in nature. The messages either include links to known redirector or free hosting domains (such as geno.link or sites.google.com), or exhibit advance-fee fraud intent while routing replies to a free email provider despite originating from a corporate-looking sender domain. Senders observed span spoofed government and business addresses as well as free webmail accounts, with subject lines using romantic or personal connection lures.

T1566.002T1534T1656T1566T1598
Sublimemedium

Attachment: RTF file with suspicious link

This rule detects RTF attachments directly attached or within an archive, containing an external link to a suspicious low reputation domain.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: RTF with embedded content

RTF files can contain embedded content similar to OLE files (Microsoft Office documents.)

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: RTF with link to free-hosted Cloudflare Pages

Detects inbound emails that contain an RTF attachment. The rule extracts embedded content from the RTF file and inspects any URLs found within it, following redirects and analyzing the final destination page's links. It flags cases where those links point to domains hosted on the free Cloudflare Pages service (pages.dev), a common tactic used to host malicious or deceptive content while evading detection.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: Self-sender PDF with minimal content and view prompt

Detects messages where the sender and recipient are the same address with a PDF attachment containing only 'VIEW PDF' text and a standardized body message requesting to view the attachment.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: SFX archive containing commands

Attachment is an SFX archive that contains commands that will execute when opened. This can be used to run malicious commands, and has been observed in the wild.

T1566.001T1204.002T1486T1036T1027+1
Sublimemedium

Attachment: Single-page PDF with S3-hosted HTML link

Detects inbound messages containing a single-page PDF attachment that includes exactly one URL, which links directly to an HTML file hosted on an Amazon S3 bucket. This technique is commonly used to redirect recipients to credential harvesting pages while leveraging trusted cloud infrastructure to evade detection.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: Small text file with link containing recipient email address

Attach text file is less than 1000 bytes and contains a recipients email address. Seen in the wild carrying credential phishing links.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: Soda PDF producer with encryption themes

Detects an observed TTP of using Soda PDF (which offers a free trial) to produce PDFs which OCR output contains references to encryption and mentions a PDF. The PDF contains a single link which has been observed linking to a credential phishing page.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: Suspicious employee policy update document lure

Inbound message containing subject line and attachments related to handbook, compensation, or policy updates. Attachments are limited to Microsoft Word documents and match similar update-related terminology. This pattern has been observed used to delivery credential phishing via QR codes.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: Suspicious PDF created with headless browser

Detects PDF documents containing a table of contents that were generated using HeadlessChrome, Chromium with Skia/PDF, or QT with empty metadata fields - common characteristics of automated malicious document creation.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: Suspicious VBA macro

Detects any VBA macro attachment that scores above a low confidence threshold in the Sublime Macro Classifier.

Sublime

Attachment: SVG file execution

Detects file execution attempts in SVG files. ActiveXObject is used to invoke WScript.Shell and run a program.

T1566.001T1204.002T1486T1059
Sublimehigh

Attachment: SVG file with HTML entity encoded href attributes

Detects SVG file attachments containing href attributes with three or more consecutive HTML numeric entity references, a technique used to obfuscate malicious URLs and evade security scanning.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimemedium

Attachment: SVG file with hyperlinks and cursor styling

Detects inbound messages containing SVG attachments that include clickable hyperlink elements and CSS pointer cursor styling, which may be used to deceive recipients into clicking malicious links disguised as legitimate images.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium
PreviousPage 11 of 53Next