• Sublime Core Feed
Medium Severity

Attachment: Embedded VBScript in MHT file (unsolicited)

Labels

Malware/Ransomware
Evasion
Scripting
Archive analysis
File analysis
HTML analysis
Sender analysis

Description

MHT files can be used to run VBScript, which can run malicious code.

References

Sublime Security
Created Aug 17th, 2023 • Last updated Oct 4th, 2023
Feed Source
Sublime Core Feed
Source
GitHub
type.inbound
and any(attachments,
        (.file_extension =~ "mht" or .file_extension in~ $file_extensions_common_archives)

        // ensure there's an mht file (if it's in an archive)
        and any(file.explode(.), .file_extension =~ "mht")
        and any(file.explode(.), any(.scan.html.scripts, .language == "VBScript"))
)
and (
  not profile.by_sender().solicited
  or (
    profile.by_sender().any_messages_malicious_or_spam
    and not profile.by_sender().any_false_positives
  )
)
MQL Console
View MQL Guide

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Get Started