Browse Rules

Search and filter across all detection sources

28 rules

sublime high mql

Attachment with high risk VBA macro (unsolicited)

Potentially malicious attachment containing a VBA macro. Oletools categorizes the macro risk as 'high'.

sublime high mql

Suspicious VBA macros from untrusted sender

Detects any VBA macro attachment that scores above a medium confidence threshold in the Sublime Macro Classifier.

sublime medium mql

Attachment with auto-executing macro (unsolicited)

Attachment from an unsolicited sender contains a macro that will auto-execute when the file is opened. Macros are a common phishing technique used to deploy malware.

sublime medium mql

Attachment with auto-opening VBA macro (unsolicited)

Recursively scans files and archives to detect embedded VBA files with an auto open exec.

sublime high mql

Attachment soliciting user to enable macros

Recursively scans files and archives to detect documents that ask the user to enable macros, including if that text appears within an embedded image.

sublime medium mql

Attachment: Macro files containing MHT content

Detects macro-enabled files that contain embedded MHT (MIME HTML) content, which is commonly used to hide malicious code through file format manipulation.

sublime high mql

Attachment with VBA macros from employee impersonation (unsolicited)

Attachment contains a VBA macro from a sender your organization has never sent an email to. Sender is using a display name that matches the display name of someone in your organization. VBA macros are a common phishing technique used to deploy malware.

sublime high mql

Attachment: Archive contains DLL-loading macro

An attacker could send a trusted and signed document that references an untrusted DLL file, which will be loaded by the signed document.

sublime high mql

Attachment: Excel file with document sharing lure created by Go Excelize

Detects Excel macro files created with the Go Excelize library containing document sharing language such as 'sent document', 'shared file', or 'REVIEW DOCUMENT'. These files are often used as lures to trick users into enabling macros or downloading malicious content.

sublime high mql

Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation

Macro references the ShellBrowserWindow COM object which can be used to spawn new processes from Explorer.exe rather than as a child process of the Office application. This can be useful for a threat actor attempting to evade security controls.

sagan medium other

[CROWDSTRIKE] Machine Learning Analysis Blocked - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

[CROWDSTRIKE] Machine Learning Analysis Blocked - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

sagan medium other

[CROWDSTRIKE] Machine Learning Analysis Detected - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

[CROWDSTRIKE] Machine Learning Analysis Detected - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

sagan medium other

[CROWDSTRIKE] Machine Learning Analysis Killed - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

[CROWDSTRIKE] Machine Learning Analysis Killed - Office File With Macro Written To File System Meets File Analysis ML High-Confidence Malware Threshold

sublime high mql

Attachment: Office file with document sharing and browser instruction lures

Detects macro-enabled attachments containing document sharing language (sent, shared, forwarded) combined with browser interaction instructions (copy, right-click) or common email disclaimers. These tactics are often used to trick users into enabling macros or following malicious instructions.

sublime medium mql

Attachment: USDA bid invitation impersonation

Detects messages claiming to be from USDA containing bid invitations with macro-enabled attachments or PDFs. Validates USDA-related content through OCR and natural language analysis.

sublime medium mql

Link to Google Apps Script macro (unsolicited)

Message contains a Google Apps Script macro link. App Scripts can run arbitrary code, including redirecting the user to a malicious web page.

sublime medium mql

Link to Google Apps Script macro via comment tagging

Message contains a Google Apps Script macro link invoked from a comment on Google Slides|Docs. App Scripts can run arbitrary code, including redirecting the user to a malicious web page.

sublime high mql

Attachment with macro calling executable

Recursively scans files and archives to detect embedded VBA files with an encoded hex string referencing an exe. This may be an attempt to heavily obfuscate an execution through Microsoft document.

sublime high mql

Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment

Detects macro-enabled Office documents (docx and similar extensions) that contain images with text mimicking Microsoft SharePoint file-sharing notifications. The embedded images reference SharePoint collaboration language such as invitations to edit or references to Microsoft 365 access controls, designed to deceive recipients into trusting the attachment.

sagan critical other

[CROWDSTRIKE] An Office file with a macro written to the file system meets the File Analysis ML algorithm's medium-confidence threshold for malware.

[CROWDSTRIKE] An Office file with a macro written to the file system meets the File Analysis ML algorithm's medium-confidence threshold for malware.

sublime high mql

Attachment: Potential sandbox evasion in Office file

Scans attached files with known Office file extension, and alerts on the presence of strings indicative of sandbox evasion checks. Malicious code may carry out checks against the local host (e.g. running processes, disk size, domain-joined status) before running its final payload.

sublime high mql

Attachment: QR code link with base64-encoded recipient address

Detects when an image or macro attachment contains QR codes that, when scanned, lead to URLs containing the recipient's email address. This tactic is used to uniquely track or target specific recipients and serve tailored credential phishing pages.

sublime medium mql

Attachment: Encrypted Microsoft Office file (unsolicited)

Encrypted OLE2 (eg Microsoft Office) attachment from an unsolicited sender. Attachment encryption is a common technique used to bypass malware scanning products. Use if receiving encrypted attachments is not normal behavior in your environment.

sublime high mql

Attachment: Excel file with suspicious template identifier

Detects Excel attachments containing a specific template identifier (TM16390866) in the EXIF metadata, which may indicate malicious or suspicious document templates being used to distribute harmful content.

sublime high mql

Attachment: PDF file with embedded content

Threat actors may embed files within PDF documents, including macro-enabled documents, in an attempt to bypass security controls and social engineer a recipient into running malicious code.