EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Spam: Attendee list solicitation

This rule detects messages claiming to have the attendee list from a specific event, they may list various information such as the number of contacts, the demographic and sample contacts. The messages typically offer to send pricing information upon request.

T1566
Sublimelow

Spam: BlackBaud infrastructure abuse

Malvertising campaign has been observed abusing a compromised account with BlackBaud. These campaigns have been leveraging brands like Disney+, Netflix, Paramount+, Peacock, UPS, and impersonating the likeness of Elon Musk.

T1566T1036T1027T1566.002T1598.003+1
Sublimemedium

Spam: Campaign with excessive display-text and keywords found

Detects affiliate marketing spam where any link contains display-text greater than 3000 chars and specific values found.

T1566
Sublimelow

Spam: Campaign with excessive space/char obfuscation and free file hosted link

This rule detects mass spam campaigns using excessive space padding with links utilizing free file hosting.

T1566
Sublimelow

Spam: Cold outreach from Cloudflare-hosted newly registered domain

Flags inbound messages from sender domains that were registered fewer than 365 days ago and use exactly two Cloudflare name servers with subdomains ending in '.ns'. The rule further requires that the subject or body text be classified as B2B cold outreach by the NLU model, indicating abuse of Cloudflare's free DNS infrastructure to rapidly stand up new domains for outreach-style spam.

T1566T1036T1027T1598
Sublimelow

Spam: Commonly observed formatting of unauthorized free giveaways

Detects commonly observed formatting of unauthorized giveaways, free tools, and products by multiple different brands.

T1566T1566.002T1598.003T1598
Sublimelow

Spam: Cryptocurrency airdrop/giveaway

Detects messages promoting cryptocurrency airdrops, token claims, or wallet-related rewards.

T1566T1598T1566.002T1598.003
Sublimelow

Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)

The default Microsoft Exchange Online sender domain, onmicrosoft.com, is commonly used to send unwanted and malicious email. Enable this rule in your environment if receiving email from the onmicrosoft.com domain is unexpected behaviour.

T1566.003T1598T1566T1566.001T1566.002+1
Sublimelow

Spam: Fake dating profile notification

Detects dating-themed messages from free email providers containing links with the recipient's email address embedded in URL parameters, combined with suspicious language or topics in the message body.

T1566T1598
Sublimelow

Spam: Fake photo share

Message contains pretexting language about sharing photos ("found these photos and thought you'd like them", "remember these photos?") and a link with a newly registered domain. Fake threads and plain text bodies have been seen in the wild, indicating active evasion techniques.

T1566T1036T1027T1598
Sublimelow

Spam: Firebase password reset from suspicious sender

Detects Firebase password reset messages from suspicious or new senders that may be attempting to abuse the Firebase authentication service.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Spam: Ghostwriting services scam with manipulative language

Detects unsolicited messages promoting ghostwriting or book publishing services that use manipulative language patterns commonly seen in scams, such as offering complimentary samples, expressing fascination with the recipient's achievements, or requesting personal information under the guise of writing assistance.

T1566T1598
Sublimemedium

Spam: Item giveaway spam template

This detection rule matches on observed html templates impersonating multiple popular brands used to deliver spam. Often the lure leverages a theme of item giveaways or a chance to win an item for completing a survey.

T1566
Sublimelow

Spam: Large financial amount mention from newly registered sender domain

Detects inbound messages from domains less than 180 days old that solicit investment interest from named organizations or individuals on behalf of a purported private family office. Senders use financial-sounding names and rotate first names and target company names while keeping the subject line structure nearly identical. The outreach is designed to appear as a legitimate investment inquiry to bait a response.

T1566.002T1534T1656T1566T1598
Sublimemedium

Spam: Link to blob.core.windows.net from new domain (<30d)

This rule detects messages containing a link to blob.core.windows.net from a sender domain less than 30 days old. There is a single recipient present, but the recipient is a random email address, and not someone at the organization.

T1566
Sublimemedium

Spam: Mastercard promotional content with image-based body

Detects messages promoting untrustworthy Mastercard credit cards that contain both financial communications and promotional content topics, with the message body primarily consisting of image content rather than text. Excludes legitimate payment-related Mastercard communications and applies additional scrutiny to high-trust sender domains that fail DMARC authentication.

T1566T1566.001T1566.002T1598T1598.003
Sublimelow

Spam: New job cold outreach from unsolicited sender

Detects unsolicited messages congratulating recipients on new jobs or roles that contain unsubscribe links, calendar booking links, or exhibit B2B cold outreach characteristics from senders who have not been previously contacted.

T1566
Sublimelow

Spam: New link domain (<=10d) and emojis

Detects spam from freemail senders, where the linked domain is less than 10 days old and emojis present.

T1566
Sublimemedium

Spam: Personalized subject and greetings via Salesforce Marketing Cloud

Detects messages sent through Salesforce Marketing Cloud infrastructure that contain a fake previous email thread, where both the current and previous threads start with the same greeting pattern extracted from the subject line.

T1566T1598
Sublimelow

Spam: Sendersrv.com with financial communications and unsubscribe language

Detects messages from sendersrv.com infrastructure containing unsubscribe language and financial communication topics, indicating potential abuse of the bulk email service for unauthorized financial solicitations.

T1566T1036T1027T1598
Sublimemedium

Spam: Sexually explicit content with emoji in subject from freemail provider

Detects messages from free email providers that contain sexually explicit content and include emojis in the subject line.

T1566T1598
Sublimelow

Spam: Sexually explicit Google Drive share

Detects suspicious Google Drive Share which containing inappropriate content or suspicious patterns. The rule looks for reports from non-organizational domains that contain emojis or explicit keywords within the report.

T1566T1598
Sublimelow

Spam: Sexually explicit Google group invitation

Detects suspicious Google Groups invitations containing inappropriate content or suspicious patterns. The rule looks for invites from non-organizational domains that contain random alphanumeric strings, explicit keywords, or suspicious call-to-action phrases in the group names or descriptions.

T1566T1598
Sublimelow

Spam: Sexually explicit Looker Studio report

Detects suspicious Looker Studio Reports which containing inappropriate content or suspicious patterns. The rule looks for reports from non-organizational domains that contain emojis or explicit keywords within the report.

T1566T1598
Sublimelow
PreviousPage 49 of 53Next