type.inbound
and any(attachments,
any(file.explode(.),
.file_extension == "7z" and
any(.scan.yara.matches,
.name == "SUSP_NESTED_7ZIP_Feb25"
)
)
)
and (
not profile.by_sender_email().solicited
or sender.email.domain.domain == "delivrto.me"
)
Playground
Test against your own EMLs or sample data.