Detection Method: File analysis

File analysis breaks down and inspects file contents, formats, and embedded elements to uncover hidden threats. This method goes beyond basic file attributes, deeply examining the inner structure of files to find potentially malicious content that looks legitimate on the surface.
File analysis helps detect:
  • Malicious macros in Office documents (Word, Excel, PowerPoint)
  • Obfuscated scripts hidden in PDFs or other document types
  • Executable code disguised in non-executable files
  • Hidden text content using encoding or steganography
  • Suspicious metadata or file properties suggesting tampering
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with split QR code
5d ago
Apr 15th, 2026
Sublime Security
Attachment: PDF With SAI Global ISO9001 Logo
5d ago
Apr 15th, 2026
Sublime Security
Brand impersonation: Amazon with suspicious attachment
6d ago
Apr 14th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
6d ago
Apr 14th, 2026
Sublime Security
Attachment: Compensation review lure with QR code
6d ago
Apr 14th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
10d ago
Apr 10th, 2026
Sublime Security
Attachment: PDF with credential theft language and invalid reply-to domain
10d ago
Apr 10th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
11d ago
Apr 9th, 2026
Sublime Security
Attachment: Calendar invite with Google redirect and invoice request
12d ago
Apr 8th, 2026
Sublime Security
Attachment: Encrypted ZIP containing VHDX file
17d ago
Apr 3rd, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
17d ago
Apr 3rd, 2026
Sublime Security
Attachment: Cold outreach with invitation subject and not attachment
17d ago
Apr 3rd, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
19d ago
Apr 1st, 2026
Sublime Security
Attachment: EML with QR code redirecting to Cloudflare challenges
19d ago
Apr 1st, 2026
Sublime Security
Brand Impersonation: PayPal
21d ago
Mar 30th, 2026
Sublime Security
Attachment: PDF bid/proposal lure with credential theft indicators
24d ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
24d ago
Mar 27th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash (trusted reporters)
25d ago
Mar 26th, 2026
Sublime Security
Attachment: ZIP file with CVE-2026-0866 exploit
1mo ago
Mar 20th, 2026
Sublime Security
Attachment: PDF contains W9 or invoice YARA signatures
1mo ago
Mar 18th, 2026
Sublime Security