Sublime Security high experimental mql

Attachment with macro calling executable

Recursively scans files and archives to detect embedded VBA files with an encoded hex string referencing an exe. This may be an attempt to heavily obfuscate an execution through Microsoft document.

View Source

Detection Logic

type.inbound
and any(attachments,
        (
          .file_extension in~ $file_extensions_macros
          or .file_extension in~ $file_extensions_common_archives
          or (
            .file_extension is null
            and .file_type == "unknown"
            and .content_type == "application/octet-stream"
            and .size < 100000000
          )
        )
        and any(file.explode(.), any(.scan.vba.hex, strings.ilike(., "*exe*")))
)

Field Validations

Loading…

Comments (0)

Loading comments...