Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
MalwareBazaar: Malicious attachment hash (trusted reporters)
4d ago
Mar 26th, 2026
Sublime Security
Link: Non-standard port 8443 in display URL
4d ago
Mar 26th, 2026
Sublime Security
Lookalike sender domain (untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
Attachment: ZIP file with CVE-2026-0866 exploit
10d ago
Mar 20th, 2026
Sublime Security
Link: Free file hosting with undisclosed recipients
11d ago
Mar 19th, 2026
Sublime Security
Link: PDF display text with fake copyright claim template
12d ago
Mar 18th, 2026
Sublime Security
Link: IPv4-mapped IPv6 address obfuscation
13d ago
Mar 17th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
13d ago
Mar 17th, 2026
Sublime Security
Link: Obfuscation via userinfo with suspicious indicators
17d ago
Mar 13th, 2026
Sublime Security
Link: Commonly Abused Web Service redirecting to ZIP file
20d ago
Mar 10th, 2026
Sublime Security
Link: Mixed case HTTPS protocol
21d ago
Mar 9th, 2026
Sublime Security
Link: Direct download of executable file
28d ago
Mar 2nd, 2026
Sublime Security
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
28d ago
Mar 2nd, 2026
Sublime Security
Link: Multistage landing - ClickUp abuse
1mo ago
Feb 27th, 2026
Sublime Security
Link: URL redirecting to blob URL
1mo ago
Feb 24th, 2026
Sublime Security
Attachment: PDF with password in filename matching body text
1mo ago
Feb 19th, 2026
Sublime Security
Link: Direct MSI download from low reputation domain
1mo ago
Feb 19th, 2026
Sublime Security
Russia return-path TLD (untrusted sender)
1mo ago
Feb 13th, 2026
Sublime Security
File sharing link from suspicious sender domain
1mo ago
Feb 13th, 2026
Sublime Security
Attachment: Self-sender PDF with minimal content and view prompt
1mo ago
Feb 12th, 2026
Sublime Security