• delivr.to Feed
Low Severity

Attachment: ZPAQ Archive (Unsolicited)

Labels

No labels.

Description

A ZPAQ archive file sent from an unsolicited, first time sender.

@delivr_to
Created Nov 27th, 2023 • Last updated Apr 22nd, 2024
Feed Source
delivr.to Feed
Source
type.inbound
and any(attachments,
  .file_extension == "zpaq" or 
  any(file.explode(.),
    .file_extension == "zpaq" or 
    any(.scan.yara.matches, 
      .name == "SUSP_ZPAQ_Archive_Nov23"
    )
  )
)
and (
    (
        not profile.by_sender_email().solicited
        and profile.by_sender_email().prevalence in ("new", "outlier")
    )
    or (
        profile.by_sender_email().any_messages_malicious_or_spam
        and not profile.by_sender_email().any_false_positives
    )
    or sender.email.domain.domain == "delivrto.me"
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started