EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Spam: Single recipient duplicated in cc

Detects spam emails where the 'To' and 'CC' fields match, using indicators such as short body length with spam keywords, unsolicited content, dmarc failures, fake threads, and suspicious links.

T1566T1566.002T1598.003T1598
Sublimemedium

Spam: SMTP & Proxy Communications in Email Body

An email containing SMTP and Proxy (socks5) command and control information within the body of the message.

T1566
Sublimemedium

Spam: Spoofed Outlook mailer with unsubscribe and reference ID footer

Flags inbound messages that spoof the Microsoft Outlook mailer header while containing an 'unsubscribe here' link followed by an alphanumeric reference ID pattern in the body text, a common tactic used to lend spam messages an air of legitimacy. Highly trusted sender domains are excluded from this rule when they pass DMARC authentication.

T1566T1598
Sublimelow

Spam: Suspicious toll-free phone number

Detects messages containing phone numbers 1 800-555-0199 or 1 800-555-0299 in the subject or body, which is reserved for use by the entertainment industry. Commonly used as a placeholder phone number in LLM-generated campaigns.

T1566T1598
Sublimelow

Spam: Unsolicited malformed PDF

This rule is designed to identify spam messages featuring a single malformed PDF attachment often leading to romance scam, pornographic, or dating websites. These emails typically contain short body text and intentionally distorted PDFs to avoid detection.

T1566T1036T1027
Sublimelow

Spam: Unsolicited WordPress account creation or password reset request

Detects messages containing WordPress password reset links where the login parameter does not match the recipient's email address. The rule triggers for unsolicited senders, previously malicious senders, or when DMARC authentication fails.

T1566T1598
Sublimelow

Spam: URL shortener with short body content and emojis

Detects spam from freemail senders, where the majority of the body is a URL shortener and emojis.

T1566
Sublimelow

Spam: Website errors solicitation

This rule detects messages claiming to have identified errors on a website. The messages typically offer to send pricing or information upon request.

T1566
Sublimelow

Spam/fraud: Predatory journal/research paper request

Detects messages related to academic research and publishing that contain suspicious patterns including character manipulation, flattering language, time pressure tactics, and domain registration anomalies. Focuses on unsolicited invitations for manuscript submissions, peer reviews, or editorial roles.

T1566.002T1534T1656T1566T1598+4
Sublimemedium

Spamhaus: Mail transiting a DROP listed network

Detects inbound mail whose Received-header IP path transits a netblock on the Spamhaus DROP (Don't Route Or Peer) list — hijacked or leased-to-criminals IP space Spamhaus recommends blocking outright. This is Spamhaus attribution, not a Sublime observation. Ranges refresh automatically from the Spamhaus feed; the Spamhaus copyright, list date, and terms URL are preserved in the rule source per Spamhaus's terms.

T1566.001T1204.002T1486T1566T1566.002+5
Sublimemedium

Spamhaus: Mail transiting an ASN-DROP listed network

Detects inbound mail whose Received-header IP path transits IP space announced by an autonomous system on the Spamhaus ASN-DROP list — ASNs Spamhaus assesses as controlled by, or knowingly providing service to, cybercriminals. This is Spamhaus attribution, not a Sublime observation. Ranges are resolved from the listed ASNs and refresh automatically; the Spamhaus copyright, list date, and terms URL are preserved in the rule source per Spamhaus's terms.

T1566.001T1204.002T1486T1566T1566.002+5
Sublimemedium

SPF temp error

Attackers can spoof domains that have no MX/SPF records, resulting in a DNS timeout. In O365 this fails closed (goes to spam), but in Gmail this fails open (lands in the inbox) and shows a red padlock Reproduce on Ubuntu 18.04: echo "test" | mail -s "Test" user@gmail.com -a"From: Support <support@nomxdomain.com>" Example headers: Received-SPF: temperror (google.com: error in processing during lookup of support@ltbit.com: DNS error) client-ip=<>; Authentication-Results: mx.google.com; spf=temperror (google.com: error in processing during lookup of support@nomxdomain.com: DNS error) smtp.mailfrom=support@nomxdomain.com

T1566T1598
Sublimemedium

Spoofable internal domain with suspicious signals

The sender is a known org domain and doesn't use a known org display name. SPF and DMARC verdicts are "none", which means the domain is spoofable. We then look for a combination of other suspicious signals such as a suspicious link or suspicious language. False Positives may occur with automated sending systems that send rich text emails, in which case we can add additional signals or exclude those.

T1566T1566.001T1566.002T1598
Sublimemedium

Stark Industries VM Servers: Suspicious Sender

A message originating from a VM server within the stark-industries.solutions infrastructure, which may indicate unauthorized use of their systems for malicious purposes.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimelow

Stripe invoice abuse

A fraudulent invoice/receipt found in the body of the message sent by exploiting Stripe's invoicing service. Callback Phishing is an attempt by an attacker to solicit the victim (recipient) to call a phone number. The resulting interaction could lead to a multitude of attacks ranging from Financial theft, Remote Access Trojan (RAT) Installation or Ransomware Deployment.

T1566.002T1534T1656T1566.003T1598
Sublimemedium

Subject and sender display name contains matching long alphanumeric string

Detects messages where both the subject line and sender display name contain identical alphanumeric strings that are between 32 and 64 characters, which may indicate automated generation or coordination between these fields for malicious purposes.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimelow

Subject: Suspicious bracketed reference

Detects messages with subject lines containing bracketed patterns that follow a specific format with repeated characters, numeric sequences, and structured tracking identifiers commonly used in malicious automated messaging systems.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Suspected cross-site scripting (XSS) found in subject

This rule detects Cross-Site Scripting (XSS) attempts within email subjects. It bypasses messages from highly trusted domains unless they fail authentication. However, the rule remains flexible, triggering even for trusted domains when emails are sent from Google Groups, ensuring thorough protection against potential threats while minimizing false positives.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Suspected lookalike domain with suspicious language

This rule identifies messages where links use typosquatting or lookalike domains similar to the sender domain, with at least one domain being either unregistered or recently registered (≤90 days). The messages must also contain indicators of business email compromise (BEC), credential theft, or abusive language patterns like financial terms or polite phrasing such as kindly. This layered approach targets phishing attempts combining domain deception with manipulative content

T1566.002T1534T1656T1036T1027+3
Sublimemedium

Suspected WordPress abuse with cross-site scripting (XSS) indicators

Detects inbound messages from likely compromised WordPress sites that exhibit indicators of cross-site scripting (XSS) attempts. The rule identifies potential script injection patterns within message bodies and/or subjects containing multiple suspicious JavaScript-related keywords or indicators.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimehigh

Suspicious attachment with unscannable Cloudflare link

A PDF or Office document contains suspicious URLs that lead to Cloudflare-protected pages with turnstile CAPTCHA gates. The sender uses deceptive display names and subjects indicating urgency or authority.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Suspicious attachment: Duplicate decoy PDF files

This rule identifies messages that contain duplicate PDF attachments, defined as either having identical filenames or matching MD5 hash values. Furthermore, the PDF files in question must lack any readable text and must not include hyperlinks.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious display name: Gmail sender with engaging language

Detects Gmail senders using display names with suspicious language patterns commonly associated with social engineering tactics, including urgency indicators, contact requests, and verification prompts.

T1566.002T1534T1656T1566T1566.001+1
Sublimelow

Suspicious DocuSign share from new domain

DocuSign shares with new reply-to addresses have been seen in recent attacks.

T1566.002T1534T1656T1566T1566.001+4
Sublimehigh
PreviousPage 50 of 53Next