EXPLORE

EXPLORE DETECTIONS

🔍
8,011 detections found

Attachment: HTML file contains exclusively Javascript

Attached HTML file does not contain any HTML other than a <script> block.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts

Detects messages with HTML attachments containing multiple 'const' declarations while excluding legitimate Gmail messages. This is evidence of potential code injection or obfuscation techniques.

T1566.001T1204.002T1486T1566T1566.002+4
Sublimehigh

Attachment: HTML file with excessive padding and suspicious patterns

Attached HTML file contains excessive line breaks and suspicious Javascript patterns.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: HTML file with reference to recipient and suspicious patterns

Attached HTML file (or HTML file within an attached email) contains references to the recipients email address, indicative of credential phishing, and suspicious Javascript patterns.

T1566T1566.001T1566.002T1598T1059
Sublimehigh

Attachment: HTML smuggling - QR Code with suspicious links

This rule detects messages with HTML attachments containing QR codes

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: HTML smuggling 'body onload' linking to suspicious destination

Potential HTML Smuggling. This rule inspects HTML attachments that contain a single link and leveraging an HTML body onload event. The linked domain must be in the URLhaus trusted repoters list, or have a suspicious TLD.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling 'body onload' with high entropy and suspicious text

Potential HTML Smuggling. This rule inspects HTML attachments that contain "body unload", high entropy, and suspicious text.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling Microsoft sign in

Scans HTML files to detect HTML smuggling techniques impersonating a Microsoft login page.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Attachment: HTML smuggling with atob and high entropy

Recursively scans files and archives to detect HTML smuggling techniques using Javascript atob functions.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimehigh

Attachment: HTML smuggling with atob and high entropy via calendar invite

Scans calendar invites (.ics files) to detect HTML smuggling techniques.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with auto-downloaded file

HTML attachments containing files that are automatically downloaded with Javascript.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimehigh

Attachment: HTML smuggling with base64 encoded JavaScript function

This rule identifies attachments that either have an HTML extension, lack any file extension, or possess an unrecognized file type and are employing Base64 encoding to conceal JavaScript functions within HTML script tags with little to no other content. Such obfuscation tactics have been frequently observed in credential phishing campaigns.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimehigh

Attachment: HTML smuggling with base64 encoded ZIP file

Detects HTML attachments containing base64-encoded ZIP or Office files alongside JavaScript decoding functions such as atob, fromCharCode, or base64. This technique is commonly used to evade security controls by hiding malicious files within HTML content that are decoded and executed client-side.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

Attachment: HTML smuggling with concatenation obfuscation

Recursively scans files and archives to detect HTML smuggling techniques.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with decimal encoding

Potential HTML smuggling attack based on large blocks of decimal encoding. Attackers often use decimal encoding as an obfuscation technique to bypass traditional email security measures.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with embedded base64 streamed file download

HTML attachments containing base64-encoded files that are downloaded via embedded hyperlinks. This TTP is used by attackers to bypass email and web filters since the file is not downloaded from an external source. Recently observed delivering Qakbot.

T1566.001T1204.002T1486T1059T1566+1
Sublimehigh

Attachment: HTML smuggling with embedded base64-encoded executable

HTML attachmemt contains a base-64 encoded executable.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: HTML smuggling with embedded base64-encoded ISO

HTML attachment contains a base-64 encoded ISO. This is a known TTP for multiple threat actors.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: HTML smuggling with eval and atob

Recursively scans files and archives to detect HTML smuggling techniques.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with eval and atob via calendar invite

Scans calendar invites (.ics files) to detect HTML smuggling techniques.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with excessive line break obfuscation

Credential Phishing attacks have been observed using excessive line breaks to obfuscate javascript functions within html files.

T1566T1566.001T1566.002T1598T1204.002+5
Sublimehigh

Attachment: HTML smuggling with excessive string concatenation and suspicious patterns

Attached HTML file contains excessive string concatenation, a recipient's email address, and an indicator of HTML smuggling. This pattern has been seen in the wild in an attempt to obfuscate the file's contents.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Attachment: HTML smuggling with fromCharCode and other signals

Recursively scans files and archives to detect HTML smuggling techniques.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: HTML smuggling with hex strings

Recursively scans files and archives to detect HTML smuggling using hex-encoded string content.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium
PreviousPage 14 of 334Next