EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

PayPal invoice abuse

A fraudulent invoice/receipt found in the body of the message sent by exploiting Paypal's invoicing service. Callback Phishing is an attempt by an attacker to solicit the victim (recipient) to call a phone number. The resulting interaction could lead to a multitude of attacks ranging from Financial theft, Remote Access Trojan (RAT) Installation or Ransomware Deployment.

T1566.002T1534T1656T1566.003T1598+3
Sublimemedium

PDF attachment with Google (AE) redirecting to a php or zip file

Detects a PDF attachment with a link that contains a Google.ae redirect URL.

T1566.001T1204.002T1486
Sublimehigh

PhaaS: Impact Solutions (Impact Vector Suite)

Identifies the use of the Impact Solutions PhaaS. Impact Vector Suite is a full-spectrum payload delivery platform, engineered for stealth-optimized execution across all major deployment vectors.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

PHP Mailer with common phishing attachments

Mail coming from a PHP Mailer user agent that includes attachments with commonly used names in phishing campaigns

T1566T1566.001T1566.002T1598
Sublimemedium

Potential prompt injection attack in body HTML

Detects messages containing references to major AI tools (like Gemini, Copilot, ChatGPT, or Claude) in non-standard HTML elements.

T1566.003T1598T1566T1566.001T1566.002+7
Sublimehigh

Privatelayer VPS in Headers

The message was sent using a Privatelayer VPS, a provider known to be used for phishing.

Sublimelow

Proofpoint Security Awareness phishing simulation

Identifies phishing simulations sent by Proofpoint and excludes the message from live analysis.

Sublime

Punycode sender domain

The sender's domain contains punycode, a technique used by attackers to impersonate legitimate domains.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

QR code to auto-download of a suspicious file type (unsolicited)

A QR code in the body of the email downloads a suspicious file type (or embedded file) such as an LNK, JS, or VBA. Recursively explodes auto-downloaded files within archives to detect these file types.

T1566.001T1204.002T1486T1036T1027+2
Sublimehigh

QR Code with suspicious indicators

This rule flags messages with QR codes in attachments when there are three or fewer attachments. If no attachments are present, the rule captures a screenshot of the message for analysis. Additional triggers include: sender's name containing the recipient's SLD, recipient's email mentioned in the body, an empty message body, a suspicious subject, or undisclosed recipients.

T1566T1566.001T1566.002T1598
Sublimehigh

Reconnaissance: All recipients cc/bcc'd or undisclosed

Recon messages, a form of deliverability testing, are used to validate whether a recipient address is valid or not, potentially preceding an attack. All recipients are bcc'd or undisclosed, with no links or attachments, and a short body and subject from an unknown sender.

Sublimelow

Reconnaissance: Email address harvesting attempt

Detects potential email harvesting or credential phishing attempts where short messages contain email addresses in the body text. These messages often try to extract contact information or validate email addresses for future attacks.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Reconnaissance: Empty message from uncommon sender

Detects incoming messages that are completely empty, containing no subject line, message body content, or file attachments. Such messages may be used for reconnaissance, delivery confirmation, or as part of multi-stage attacks.

T1566T1036T1027T1598
Sublimelow

Reconnaissance: Empty subject with mismatched reply-to from new sender

Message with no subject line from a new sender where the reply-to address differs from the sender address, potentially indicating header manipulation or impersonation tactics.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Reconnaissance: Fake real estate inquiry with empty body

Detects inbound messages with no body content — neither plain text nor HTML — but an unusually long subject line containing real estate inquiry language. The subject lines impersonate prospective home buyers asking about specific property listings or seeking a trusted local real estate agent, often mentioning relocation. These messages are designed to establish contact with real estate professionals as a precursor to fraud.

T1566.002T1534T1656T1566T1598
Sublimemedium

Reconnaissance: Hotel booking reply-to redirect

Detects messages impersonating hotel booking inquiries by identifying common hotel-related language patterns from senders where the reply-to is a free email provider and differs from the sender domain in an effort to validate whether a recipient address is valid or not, potentially preceding an attack.

T1566.002T1534T1656T1566T1598
Sublimemedium

Reconnaissance: Large unknown recipient list

Recon messages, a form of deliverability testing, are used to validate whether a recipient address is valid or not, potentially preceding an attack. There's a large number of recipients that are unknown to the organization, no links or attachments, and a short body and subject from an unknown sender.

Sublimelow

Reconnaissance: Short generic greeting message

Detects potential reconnaissance messages with very short, generic content like 'Hi' or 'Hello' from external senders. These messages are often used to validate email addresses and test deliverability before launching larger attacks.

T1566.002T1534T1656T1566.003T1598+1
Sublimemedium

Recruitee Infrastructure Abuse

Identifies inbound messages from Recruitee domains containing recruitment-related topics and application links, where the sender has limited prior history. The URLs in these messages either point to recently registered domains or appear as standalone links with application-focused text.

T1566.002T1534T1656T1566T1566.001+2
Sublimehigh

Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment

RFQ/RFP scams involve fraudulent emails posing as legitimate requests for quotations or purchases, often sent by scammers impersonating reputable organizations. These scams aim to deceive recipients into providing sensitive information or conducting unauthorized transactions, often leading to financial loss, or data leakage.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern

RFQ/RFP scams involve fraudulent emails posing as legitimate requests for quotations or purchases, often sent by scammers impersonating reputable organizations. These scams aim to deceive recipients into providing sensitive information or conducting unauthorized transactions, often leading to financial loss, or data leakage.

T1566.002T1534T1656T1036T1027
Sublimemedium

Rootlayer VPS in Headers

The message was sent using a Rootlayer VPS, a provider known to be used for phishing.

Sublimelow

Russia return-path TLD (untrusted sender)

The return-path header is a .ru TLD from an untrusted sender.

T1566.002T1534T1656T1566T1566.001+3
Sublimelow

Salesforce infrastructure abuse

Identifies messages that resemble credential theft, originating from Salesforce. Salesforce infrastrcture abuse has been observed recently to send phishing attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium
PreviousPage 43 of 53Next