Browse Rules

Search and filter across all detection sources

229 rules

yara unknown yara

PDF_Embedded_Exe [maldocs]

yara unknown yara

XDP_embedded_PDF [maldocs]

sublime medium mql

Attachment: PDF Object Hash with Blue File Icon

Detects PDF attachments containing a specific object hash (8638ef6bfe382a927aa12a18f2150757) associated with encrypted PDFs leading to cred phishing.

yara unknown yara

blackhole2_pdf [exploit_kits]

BlackHole2 Exploit Kit Detection

yara unknown yara

phoenix_pdf [exploit_kits]

Phoenix Exploit Kit Detection

yara unknown yara

phoenix_pdf2 [exploit_kits]

Phoenix Exploit Kit Detection

yara unknown yara

phoenix_pdf3 [exploit_kits]

Phoenix Exploit Kit Detection

sublime medium mql

Attachment: PDF with quote lure

Detects PDF attachments containing quote-themed lure content.

sublime medium mql

Attachment: PDF with blurry lure image

Detects PDF attachments containing a blurry image used in credential phishing lures.

sublime medium mql

Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification

Detects PDF attachments containing a specific object hash (63bf167b66091a4bc53e8944a76f6b08) that may indicate malicious content or known threat indicators.

sublime high mql

Attachment: Soda PDF producer with encryption themes

Detects an observed TTP of using Soda PDF (which offers a free trial) to produce PDFs which OCR output contains references to encryption and mentions a PDF. The PDF contains a single link which has been observed linking to a credential phishing page.

signature-base unknown yara

Docm_in_PDF [yara]

Detects an embedded DOCM in PDF combined with OpenAction

signature-base unknown yara

SUSP_Bad_PDF [yara]

Detects PDF that embeds code to steal NTLM hashes

sublime medium mql

Attachment: PDF with suspicious internal object reference identifier

Detects inbound messages containing PDF attachments with a specific internal object reference identifier pattern, which may indicate a crafted or malicious PDF file.

sublime high mql

Attachment: PDF with CVE-2026-34621 lures

Detects PDF attachments containing YARA signatures associated with CVE-2026-34621's observed lures.

signature-base unknown yara

WaterBug_wipbot_2013_core_PDF [yara]

Symantec Waterbug Attack - Trojan.Wipbot 2014 core PDF

yara unknown yara

WaterBug_wipbot_2013_core_PDF [malware]

Symantec Waterbug Attack - Trojan.Wipbot 2014 core PDF

sublime medium mql

Attachment: PDF with personal Microsoft OneNote URL

Detects PDF attachments containing a sharepoint URL referencing the senders personal OneNote.

sublime medium mql

Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents

Matching PDF Object Hash associated with chrome -> export to pdf of a shared document related to Canada's Revenue Agency.

sagan medium other

[FILE-BLUEDOT] PDF Downloaded a suspicious source

[FILE-BLUEDOT] PDF Downloaded a suspicious source

sublime high mql

Attachment: PDF with specific author metadata

Detects inbound messages containing PDF attachments where the EXIF metadata indicates the author or creator is 'Shelby Porter'.

sublime medium mql

Attachment: QuickBooks PDF lure

Detects inbound messages containing PDF attachments that match YARA signatures identifying QuickBooks-themed lure content.

sublime low mql

Attachment: PDF with ReportLab library and default metadata

Detects PDF attachments generated using the ReportLab PDF Library with default anonymous metadata values, including untitled document, anonymous creator/author, and unspecified subject. This combination of characteristics is commonly associated with automated PDF generation tools used in malicious activities.

sagan medium other

[FILE-GEOIP] PDF Downloaded from outside HOME_COUNTRY

[FILE-GEOIP] PDF Downloaded from outside HOME_COUNTRY

sekoia unknown yara

apt_apt29_wineloader_malicious_pdf [yara_rules]

Detects malicious PDF used by APT29 to drop Wineloader