• delivr.to Feed
Low Severity

Attachment: AutoIt Script File (Unsolicited)

Labels

No labels.

Description

An AutoIt script file, either AU3 or A3X.

@delivr_to
Created Dec 15th, 2023 • Last updated Apr 22nd, 2024
Feed Source
delivr.to Feed
Source
type.inbound

and any(attachments,
    .file_extension in~ ("au3", "a3x")
    or (
        .file_extension in $file_extensions_common_archives
        and any(file.explode(.), .file_extension in~ ("au3", "a3x"))
    )
)

and (
    (
        not profile.by_sender_email().solicited
        and profile.by_sender_email().prevalence in ("new", "outlier")
    )
    or (
        profile.by_sender_email().any_messages_malicious_or_spam
        and not profile.by_sender_email().any_false_positives
    )
    or sender.email.domain.domain == "delivrto.me"
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started