EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification

Detects PDF attachments containing a specific object hash (63bf167b66091a4bc53e8944a76f6b08) that may indicate malicious content or known threat indicators.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF Object Hash associated with a fake invoice and a W-9

Matching PDF Object Hash associated with a fake invoice followed by a W-9.

T1566.002T1534T1656T1036T1027
Sublimehigh

Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents

Matching PDF Object Hash associated with chrome -> export to pdf of a shared document related to Canada's Revenue Agency.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Attachment: PDF Object Hash with Blue File Icon

Detects PDF attachments containing a specific object hash (8638ef6bfe382a927aa12a18f2150757) associated with encrypted PDFs leading to cred phishing.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF proposal with credential theft indicators

PDF attachment with 'proposal' in filename contains sender or recipient domain, credential theft language detected via OCR, and includes a single URL link.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: PDF templated investment lure

Detects inbound messages carrying PDF attachments that match a YARA signature for a recurring templated lure using a blue and white design theme.

T1566.001T1204.002T1486T1566T1566.002+1
Sublimemedium

Attachment: PDF with a suspicious string and single URL

Detects single-page PDF attachments containing suspicious language such as 'View Document' or 'View PDF' along with exactly one URL, commonly used in credential theft attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: PDF with base64 JavaScript and eval functions

PDF attachment contains base64-encoded JavaScript variables with eval functions, indicating potential code obfuscation and execution techniques commonly used in malicious documents.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF with blurry lure image

Detects PDF attachments containing a blurry image used in credential phishing lures.

T1566T1566.001T1566.002T1598
Sublimemedium

Attachment: PDF with credential theft language and invalid reply-to domain

Detects PDF attachments containing high-confidence credential theft language that references the recipient's email address, combined with an invalid reply-to domain header.

T1566T1566.001T1566.002T1598
Sublimemedium

Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)

Detects messages with credential theft PDFs linking to free subdomains.

T1566T1566.001T1566.002T1598
Sublimemedium

Attachment: PDF with CVE-2026-34621 lures

Detects PDF attachments containing YARA signatures associated with CVE-2026-34621's observed lures.

T1566.001T1204.002T1486
Sublimehigh

Attachment: PDF with eCheckRun lures

Detects PDF attachments matching yara rules looking for attachments containing artifacts from related to fake financial/invoice themes, including eCheckRun lures. These are commonly used to trick users into believe they have received legitmate electronic payment messages.

T1566T1566.001T1566.002T1598
Sublimemedium

Attachment: PDF with embedded box-lure and javascript

Detects inbound messages containing a PDF attachment that matches YARA signatures looking for JavaScript functions or specific lure boxes that have been observed within malicious documents.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Attachment: PDF with embedded Javascript

PDF contains embedded Javascript.

T1566.001T1204.002T1486T1036T1027+1
Sublimemedium

Attachment: PDF with fake invoice using suspicious font sizing

PDF attachment contains a fake invoice with suspicious font size patterns and unique image sizes, typically used in fraudulent billing schemes.

T1566.002T1534T1656T1566.003T1598+1
Sublimemedium

Attachment: PDF with JSFck obfuscation

PDF attachment contains JavaScript obfuscated using JSFck encoding techniques. JSFck is a method of writing JavaScript code using only six characters: []()!+ which is often used to evade detection by security tools.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: PDF with link to DMG file download

This rule identifies PDF attachments that either link directly to a DMG file, link to a ZIP archive containing a DMG file, or link to an encrypted ZIP containing a DMG file. This technique has been observed delivering MetaStealer Malware.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: PDF with link to zip containing a wsf file

Detects a PDF attachment with a link to a ZIP file that contains a WSF file

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: PDF with localhost IP in EXIF title metadata

Detects inbound PDF attachments where the EXIF title metadata starts with '127.0.0.1', sent either to a self-addressed recipient or an invalid recipient domain. This technique may indicate automated or malicious document generation tools embedding localhost references in file metadata.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Attachment: PDF with Microsoft Purview message impersonation

Detects PDF attachments containing text that impersonates Microsoft Purview secure message notifications, potentially used to trick users into believing they have received legitimate secure communications from Microsoft services.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Attachment: PDF with multistage landing - ClickUp abuse

Detects PDF attachments containing ClickUp document links that either redirect to unavailable pages or contain embedded links leading to newly registered domains, free file hosts, URL shorteners, or verified credential theft pages.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Attachment: PDF with password in filename matching body text

Detects messages containing a single PDF attachment where the filename includes a numeric password that is explicitly referenced in the message body text.

T1566.001T1204.002T1486T1566T1566.002+4
Sublimemedium

Attachment: PDF with personal Microsoft OneNote URL

Detects PDF attachments containing a sharepoint URL referencing the senders personal OneNote.

T1566T1566.001T1566.002T1598
Sublimemedium
PreviousPage 9 of 53Next