EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: ICS file with non-Gregorian calendar scale

Detects ICS calendar attachments that use a non-standard calendar scale other than GREGORIAN, which may indicate malicious calendar files attempting to exploit calendar parsing vulnerabilities or bypass security filters.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: ICS invite meeting lure

Detects inbound messages carrying an .ics calendar attachment that impersonate meeting invites, referencing dial-in details such as PIN resets, local numbers, or conference IDs. These messages include a tracked link redirecting through the sender's own domain (e.g. /ls/click) and use generic, template-style subject lines like 'Management Progress Meeting' or 'Project Closeout Report', often appended with a machine-generated timestamp. The sending domains are typically unrelated or compromised businesses rather than legitimate meeting platforms, and the pattern is consistent with a phishing kit automating fake meeting invitations to harvest clicks or credentials.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Attachment: ICS voicemail lure with suspicious link

Detects inbound emails containing an ICS calendar attachment whose event description mimics a voicemail notification (e.g., 'new voicemail', 'listen to your voicemail') and includes a link pointing to a free file hosting service, self-service creation platform, URL shortener, suspicious TLD, or a domain registered within the last 90 days. Excludes messages from high-trust sender domains that pass DMARC authentication.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: ICS with embedded document

ICS invite contains an embedded document.

T1566.001T1204.002T1486T1036T1027
Sublimelow

Attachment: ICS with embedded Javascript in SVG file

Detects incoming messages containing ICS attachments with embedded SVG files that contain malicious JavaScript code, including base64-encoded content and potentially harmful event handlers. The rule specifically watches for onload events, location redirects, error handlers, and iframe elements with base64 data URIs.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Attachment: ICS with employee policy review lure

Detects ICS calendar attachments containing references to 'policy review' and 'secure access' terminology, which may be used in social engineering attacks to prompt users to take action under the guise of compliance or security requirements.

T1566T1566.001T1566.002T1598T1534+3
Sublimehigh

Attachment: Identity Confirmation With Document Unlock Code

Detects short inbound messages referencing an attached document that requires the recipient to confirm their identity and enter a code to unlock it, sent within an active thread context.

T1566T1566.001T1566.002T1598T1027+1
Sublimemedium

Attachment: Image-only docx/pptx callback phishing

Detects inbound emails with docx or pptx attachments that contain no text but exactly one embedded image, a common tactic to evade text-based scanning by presenting content as a picture. The rule then inspects any extracted text from the image for a combination of callback phishing lures—such as references to subscriptions, invoices, refunds, or antivirus renewals alongside phone numbers or dollar amounts—paired with impersonation of well-known brands like PayPal, McAfee, Norton, or Best Buy, indicating a fraudulent phone-based scam attempt.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Attachment: Invoice and W-9 PDFs with suspicious creators

Detects messages containing two PDF attachments where one has invoice-related naming patterns and another contains W-9 tax form indicators, commonly used in business email compromise attacks targeting financial processes.

T1566.002T1534T1656T1566T1598+1
Sublimehigh

Attachment: JavaScript file with suspicious base64-encoded executable

JavaScript attachment or compressed JavaScript file containing a base64 encoded executable.

T1566.001T1204.002T1486T1036T1027+1
Sublimehigh

Attachment: JPEG with gd-jpeg creator and suspicious file name

Detects inbound messages containing a single JPEG attachment with specific filename patterns and EXIF metadata indicating creation by gd-jpeg v1.0. This has been observed being used to produce company logos used within phishing messages.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: Legal themed message or PDF with suspicious indicators

Detects messages with short body content or emoji containing PDF attachments from suspicious creators that include legal and compliance language with embedded malicious links, URL shorteners, or newly registered domains.

T1566T1566.001T1566.002T1598T1486+5
Sublimemedium

Attachment: Link file with UNC path

Attached link file contains a UNC path. This can be used to relay NTLM password hashes; Windows will attempt to authenticate against the path even without the file being opened.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: Link to Doubleclick.net open redirect

Doubleclick.net link in a document leveraging an open redirect.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Attachment: LNK file

Recursively scans files and archives to detect LNK connection files. LNK files can be weaponised to execute arbitrary commands including unpacking and running executable content embedded within the file itself.

T1566.001T1204.002T1486
Sublimehigh

Attachment: LNK with embedded content

Emotet has been observed to embed executable content within an LNK file to deliver and execute VBScript when launched. Similar research has demonstrated how this concept may be applied to deliver and launch an embedded executable via PowerShell.

T1566.001T1204.002T1486T1190T1203+1
Sublimehigh

Attachment: Macro files containing MHT content

Detects macro-enabled files that contain embedded MHT (MIME HTML) content, which is commonly used to hide malicious code through file format manipulation.

T1566.001T1204.002T1486T1566T1566.002+5
Sublimemedium

Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation

Macro references the ShellBrowserWindow COM object which can be used to spawn new processes from Explorer.exe rather than as a child process of the Office application. This can be useful for a threat actor attempting to evade security controls.

T1566.001T1204.002T1486T1059.005T1059
Sublimehigh

Attachment: Malformed OLE file

Attached OLE file (typically a Microsoft Office document) is malformed, possibly to evade traditional scanners and filters.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: Malicious OneNote commands

Scans for OneNote attachments that contain suspicious commands that may indicate malicious activity.

T1566.001T1204.002T1486T1059
Sublimehigh

Attachment: Malicious zip file matching zipline campaign

Detects inbound ZIP attachments containing content that matches observed artifacts from a ZipLine campaign reported on by Telekom Security.

T1566.001T1204.002T1486
Sublimemedium

Attachment: Microsoft 365 credential phishing

Looks for messages with an image attachment that contains words related to Microsoft, Office365, and passwords.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Attachment: Microsoft impersonation via PDF with link and suspicious language

Attached PDF contains a Microsoft-affilated logo, suspicious language or keywords, and a link. Known malware delivery method.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links

Detects inbound messages containing EML attachments with embedded links targeting Microsoft OAuth authentication flows. The rule identifies suspicious Microsoft login URLs with specific query parameters indicating credential harvesting attempts, including offline access permissions, read/write scopes, and reprocessing endpoints. Links are detected within EML body content, embedded PDF/HTML attachments, and ICS calendar files.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimehigh
PreviousPage 7 of 53Next