Detection Method: YARA

YARA detection scans email messages, attachments, and extracted content for known malware, phishing patterns, or suspicious code. This detection method uses the YARA pattern matching language, which lets your security team create specific signatures based on known malicious patterns, both textual and binary.
YARA detection can identify:
  • Known malware families based on their distinctive code patterns
  • Obfuscated scripts or executables using encoding techniques
  • Common phishing templates with structural similarities
  • Suspicious binary patterns that may indicate malicious functionality
  • Custom threats targeting specific organizations with tailored YARA rules
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ZIP file with CVE-2026-0866 exploit
10d ago
Mar 20th, 2026
Sublime Security
Attachment: PDF contains W9 or invoice YARA signatures
12d ago
Mar 18th, 2026
Sublime Security
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
2mo ago
Jan 28th, 2026
Sublime Security
Attachment: Password-protected PDF with fake document indicators
2mo ago
Jan 21st, 2026
Sublime Security
Link to auto-download of a suspicious file type (unsolicited)
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file with excessive padding and suspicious patterns
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file with reference to recipient and suspicious patterns
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: Malicious OneNote commands
2mo ago
Jan 12th, 2026
@Kyle_Parrish_
Attachment: WinRAR CVE-2025-8088 exploitation
2mo ago
Jan 12th, 2026
Sublime Security
Link to auto-downloaded disk image in encrypted zip
2mo ago
Jan 12th, 2026
@ajpc500
Attachment: EML with Encrypted ZIP
2mo ago
Jan 12th, 2026
Sublime Security
Encrypted Microsoft Office files from untrusted sender
7mo ago
Aug 5th, 2025
Sublime Security
Attachment: DocX embedded binary
7mo ago
Aug 5th, 2025
Sublime Security
Attachment with unscannable encrypted zip (unsolicited)
8mo ago
Jul 16th, 2025
Sublime Security
Link to auto-downloaded DMG in encrypted zip
8mo ago
Jul 16th, 2025
Sublime Security
Attachment: Malformed OLE file
2y ago
Nov 25th, 2024
Sublime Security
Attachment: JavaScript file with suspicious base64-encoded executable
2y ago
Apr 1st, 2024
Sublime Security
Attachment: HTML smuggling with embedded base64-encoded executable
2y ago
Mar 25th, 2024
Sublime Security
Attachment: Archive with embedded EXE file
2y ago
Feb 27th, 2024
Sublime Security
Attachment: RTF with embedded content
2y ago
Feb 26th, 2024
@amitchell516