EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment

Detects macro-enabled Office documents (docx and similar extensions) that contain images with text mimicking Microsoft SharePoint file-sharing notifications. The embedded images reference SharePoint collaboration language such as invitations to edit or references to Microsoft 365 access controls, designed to deceive recipients into trusting the attachment.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimehigh

Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK

Detects embedded Shell.Explorer.1 COM objects containing LNK files within various file types.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: MS OOXML file created by Administrator with zero edit time

Detects inbound PowerPoint (.pptx) and other MS OOXML attachments where the file creator is listed as 'Administrator' and the total edit time is zero minutes, while missing the 'TitlesOfParts' metadata field. This pattern may indicate programmatically generated or suspicious presentation files.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: MSI installer file

Recursively scans files and archives to detect MSI installer files. Coercing a target user to run an MSI can be used as part of an 'IT Support' or 'software update' social engineering attack. Execution of the delivered MSI could enable the attacker to execute malicious code on the target user's host.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: Office document loads remote document template

Recursively scans archives and Office documents to detect remote document template injection.

T1566.001T1204.002T1486
Sublimemedium

Attachment: Office document with VSTO add-in

Recursively scans files and archives to detect Office documents with VSTO Add-ins.

T1566.001T1204.002T1486T1059
Sublimehigh

Attachment: Office file contains OLE relationship to credential phishing page

Office file OLE relationship link is a credential page, or contains credential phishing language.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: Office file with credential phishing URLs

Detects Office documents containing embedded URLs that redirect to credential phishing pages. The rule filters out standard XML namespace and schema URLs commonly found in legitimate Office documents, then analyzes remaining URLs for malicious content using machine learning link analysis.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: Office file with document sharing and browser instruction lures

Detects macro-enabled attachments containing document sharing language (sent, shared, forwarded) combined with browser interaction instructions (copy, right-click) or common email disclaimers. These tactics are often used to trick users into enabling macros or following malicious instructions.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: Office file with suspicious function calls or downloaded file path

Attached Office file contains suspicious function calls or known malicious file path pattern.

T1566.001T1204.002T1486T1036T1027+1
Sublimehigh

Attachment: OLE external relationship containing file scheme link to executable filetype

This rule identifies attachments containing file scheme links pointing to executable file types, a common indicator of malware distribution. It applies to various suspicious file extensions and archive formats, aiming to prevent the initiation and execution of malicious software.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: OLE external relationship containing file scheme link to IP address

This rule identifies attachments containing file scheme links pointing to IP Addresses, a common indicator of malware distribution. It applies to various suspicious file extensions and archive formats, aiming to prevent the initiation and execution of malicious software. The rule negates firing on IP addresses governed by RFC1918 or privately allocated space.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: Password-protected PDF with fake document indicators

Detects PDF attachments that are password protected and matching YARA signatures looking for specific content observed in previous activity.

T1566.001T1204.002T1486T1566T1566.002+4
Sublimemedium

Attachment: PDF Attachment with links to workers.dev

Detects inbound messages containing PDF attachments with fewer than 5 pages that, when analyzed, contain URLs pointing to workers.dev subdomains. This pattern indicates potential abuse of Cloudflare Workers infrastructure to host malicious content delivered via PDF documents.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Attachment: PDF bid/proposal lure with credential theft indicators

Detects single-page PDF attachments containing bid, proposal, RFP, RFQ, or quotation-related lures combined with high-confidence credential theft language or suspicious domains. The rule examines various locations including PDF URLs, OCR content, file names, subject lines, and message body for these indicators.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Attachment: PDF contains W9 or invoice YARA signatures

PDF attachment contains YARA signatures commonly associated with fraudulent W9 tax forms or invoice documents, which are frequently used in social engineering attacks to steal sensitive information or facilitate business email compromise.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link

Detects inbound emails containing PDF attachments whose embedded metadata (creator/producer fields) indicates generation by wkhtmltopdf or Qt-based tools, both commonly used in malicious PDF creation. The rule extracts and OCRs the PDF content, then applies NLU classification to confirm credential theft intent. It further inspects URLs embedded in the PDF for suspicious patterns, such as very short paths or OAuth redirect parameters, which are often abused for credential phishing redirection.

T1566T1566.001T1566.002T1598
Sublimehigh

Attachment: PDF file with embedded content

Threat actors may embed files within PDF documents, including macro-enabled documents, in an attempt to bypass security controls and social engineer a recipient into running malicious code.

T1566.001T1204.002T1486
Sublimehigh

Attachment: PDF file with link to fake Bitcoin exchange

Fraudulent message containing a PDF notification of unclaimed Bitcoin assets. The PDF file contains a link to a fake Cryptocurrency portal. Attempting to withdraw funds prompts the user to enter payment information.

T1566.002T1534T1656T1598.003T1566+1
Sublimelow

Attachment: PDF file with low reputation link to ZIP file (unsolicited)

Detects messages with PDF attachments linking directly to zip files from unsolicited senders.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)

Detects messages with PDF attachments linking directly to suspicious filetypes on hosts with low reputation from unsolicited senders.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF file with recipient domain and ATT eCheckRun pattern

Detects PDF attachments with filenames containing the recipient's domain, potentially indicating targeted financial document spoofing.

T1566.002T1534T1656T1566T1598
Sublimemedium

Attachment: PDF generated with wkhtmltopdf tool and default title

Detects PDF attachments that were generated using the wkhtmltopdf conversion tool, which converts HTML/CSS to PDF. This tool is commonly used by attackers to create legitimate-looking PDF documents from web content for social engineering purposes.

T1566.002T1534T1656T1566.003T1598+6
Sublimelow

Attachment: PDF Grant Payment lure with embedded link

Inbound messages carrying a PDF attachment that references a 'Grant Payment Development' RFP or bid solicitation, often sent from compromised or spoofed education-sector (.k12, .esc) accounts. The PDF contains an embedded URL, consistent with a redirect to a credential-harvesting or malicious landing page disguised as bid documentation.

T1566T1566.001T1566.002T1598
Sublimehigh
PreviousPage 8 of 53Next