EXPLORE DETECTIONS
Spam: Single recipient duplicated in cc
Detects spam emails where the 'To' and 'CC' fields match, using indicators such as short body length with spam keywords, unsolicited content, dmarc failures, fake threads, and suspicious links.
Spam: SMTP & Proxy Communications in Email Body
An email containing SMTP and Proxy (socks5) command and control information within the body of the message.
Spam: Spoofed Outlook mailer with unsubscribe and reference ID footer
Flags inbound messages that spoof the Microsoft Outlook mailer header while containing an 'unsubscribe here' link followed by an alphanumeric reference ID pattern in the body text, a common tactic used to lend spam messages an air of legitimacy. Highly trusted sender domains are excluded from this rule when they pass DMARC authentication.
Spam: Suspicious toll-free phone number
Detects messages containing phone numbers 1 800-555-0199 or 1 800-555-0299 in the subject or body, which is reserved for use by the entertainment industry. Commonly used as a placeholder phone number in LLM-generated campaigns.
Spam: Unsolicited malformed PDF
This rule is designed to identify spam messages featuring a single malformed PDF attachment often leading to romance scam, pornographic, or dating websites. These emails typically contain short body text and intentionally distorted PDFs to avoid detection.
Spam: Unsolicited WordPress account creation or password reset request
Detects messages containing WordPress password reset links where the login parameter does not match the recipient's email address. The rule triggers for unsolicited senders, previously malicious senders, or when DMARC authentication fails.
Spam: URL shortener with short body content and emojis
Detects spam from freemail senders, where the majority of the body is a URL shortener and emojis.
Spam: Website errors solicitation
This rule detects messages claiming to have identified errors on a website. The messages typically offer to send pricing or information upon request.
Spam/fraud: Predatory journal/research paper request
Detects messages related to academic research and publishing that contain suspicious patterns including character manipulation, flattering language, time pressure tactics, and domain registration anomalies. Focuses on unsolicited invitations for manuscript submissions, peer reviews, or editorial roles.
Spamhaus: Mail transiting a DROP listed network
Detects inbound mail whose Received-header IP path transits a netblock on the Spamhaus DROP (Don't Route Or Peer) list — hijacked or leased-to-criminals IP space Spamhaus recommends blocking outright. This is Spamhaus attribution, not a Sublime observation. Ranges refresh automatically from the Spamhaus feed; the Spamhaus copyright, list date, and terms URL are preserved in the rule source per Spamhaus's terms.
Spamhaus: Mail transiting an ASN-DROP listed network
Detects inbound mail whose Received-header IP path transits IP space announced by an autonomous system on the Spamhaus ASN-DROP list — ASNs Spamhaus assesses as controlled by, or knowingly providing service to, cybercriminals. This is Spamhaus attribution, not a Sublime observation. Ranges are resolved from the listed ASNs and refresh automatically; the Spamhaus copyright, list date, and terms URL are preserved in the rule source per Spamhaus's terms.
SPF temp error
Attackers can spoof domains that have no MX/SPF records, resulting in a DNS timeout. In O365 this fails closed (goes to spam), but in Gmail this fails open (lands in the inbox) and shows a red padlock Reproduce on Ubuntu 18.04: echo "test" | mail -s "Test" user@gmail.com -a"From: Support <support@nomxdomain.com>" Example headers: Received-SPF: temperror (google.com: error in processing during lookup of support@ltbit.com: DNS error) client-ip=<>; Authentication-Results: mx.google.com; spf=temperror (google.com: error in processing during lookup of support@nomxdomain.com: DNS error) smtp.mailfrom=support@nomxdomain.com
Spoofable internal domain with suspicious signals
The sender is a known org domain and doesn't use a known org display name. SPF and DMARC verdicts are "none", which means the domain is spoofable. We then look for a combination of other suspicious signals such as a suspicious link or suspicious language. False Positives may occur with automated sending systems that send rich text emails, in which case we can add additional signals or exclude those.
Stark Industries VM Servers: Suspicious Sender
A message originating from a VM server within the stark-industries.solutions infrastructure, which may indicate unauthorized use of their systems for malicious purposes.
Stripe invoice abuse
A fraudulent invoice/receipt found in the body of the message sent by exploiting Stripe's invoicing service. Callback Phishing is an attempt by an attacker to solicit the victim (recipient) to call a phone number. The resulting interaction could lead to a multitude of attacks ranging from Financial theft, Remote Access Trojan (RAT) Installation or Ransomware Deployment.
Subject and sender display name contains matching long alphanumeric string
Detects messages where both the subject line and sender display name contain identical alphanumeric strings that are between 32 and 64 characters, which may indicate automated generation or coordination between these fields for malicious purposes.
Subject: Suspicious bracketed reference
Detects messages with subject lines containing bracketed patterns that follow a specific format with repeated characters, numeric sequences, and structured tracking identifiers commonly used in malicious automated messaging systems.
Suspected cross-site scripting (XSS) found in subject
This rule detects Cross-Site Scripting (XSS) attempts within email subjects. It bypasses messages from highly trusted domains unless they fail authentication. However, the rule remains flexible, triggering even for trusted domains when emails are sent from Google Groups, ensuring thorough protection against potential threats while minimizing false positives.
Suspected lookalike domain with suspicious language
This rule identifies messages where links use typosquatting or lookalike domains similar to the sender domain, with at least one domain being either unregistered or recently registered (≤90 days). The messages must also contain indicators of business email compromise (BEC), credential theft, or abusive language patterns like financial terms or polite phrasing such as kindly. This layered approach targets phishing attempts combining domain deception with manipulative content
Suspected WordPress abuse with cross-site scripting (XSS) indicators
Detects inbound messages from likely compromised WordPress sites that exhibit indicators of cross-site scripting (XSS) attempts. The rule identifies potential script injection patterns within message bodies and/or subjects containing multiple suspicious JavaScript-related keywords or indicators.
Suspicious attachment with unscannable Cloudflare link
A PDF or Office document contains suspicious URLs that lead to Cloudflare-protected pages with turnstile CAPTCHA gates. The sender uses deceptive display names and subjects indicating urgency or authority.
Suspicious attachment: Duplicate decoy PDF files
This rule identifies messages that contain duplicate PDF attachments, defined as either having identical filenames or matching MD5 hash values. Furthermore, the PDF files in question must lack any readable text and must not include hyperlinks.
Suspicious display name: Gmail sender with engaging language
Detects Gmail senders using display names with suspicious language patterns commonly associated with social engineering tactics, including urgency indicators, contact requests, and verification prompts.
Suspicious DocuSign share from new domain
DocuSign shares with new reply-to addresses have been seen in recent attacks.