Detection Method: YARA

YARA detection scans email messages, attachments, and extracted content for known malware, phishing patterns, or suspicious code. This detection method uses the YARA pattern matching language, which lets your security team create specific signatures based on known malicious patterns, both textual and binary.
YARA detection can identify:
  • Known malware families based on their distinctive code patterns
  • Obfuscated scripts or executables using encoding techniques
  • Common phishing templates with structural similarities
  • Suspicious binary patterns that may indicate malicious functionality
  • Custom threats targeting specific organizations with tailored YARA rules
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF With SAI Global ISO9001 Logo
5d ago
Apr 15th, 2026
Sublime Security
Attachment: PDF with split QR code
5d ago
Apr 15th, 2026
Sublime Security
Attachment: ZIP file with CVE-2026-0866 exploit
1mo ago
Mar 20th, 2026
Sublime Security
Attachment: PDF contains W9 or invoice YARA signatures
1mo ago
Mar 18th, 2026
Sublime Security
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
2mo ago
Jan 28th, 2026
Sublime Security
Attachment: Password-protected PDF with fake document indicators
2mo ago
Jan 21st, 2026
Sublime Security
Link to auto-download of a suspicious file type (unsolicited)
3mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file with excessive padding and suspicious patterns
3mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file with reference to recipient and suspicious patterns
3mo ago
Jan 12th, 2026
Sublime Security
Attachment: Malicious OneNote commands
3mo ago
Jan 12th, 2026
@Kyle_Parrish_
Attachment: WinRAR CVE-2025-8088 exploitation
3mo ago
Jan 12th, 2026
Sublime Security
Link to auto-downloaded disk image in encrypted zip
3mo ago
Jan 12th, 2026
@ajpc500
Attachment: EML with Encrypted ZIP
3mo ago
Jan 12th, 2026
Sublime Security
Encrypted Microsoft Office files from untrusted sender
8mo ago
Aug 5th, 2025
Sublime Security
Attachment: DocX embedded binary
8mo ago
Aug 5th, 2025
Sublime Security
Attachment with unscannable encrypted zip (unsolicited)
9mo ago
Jul 16th, 2025
Sublime Security
Link to auto-downloaded DMG in encrypted zip
9mo ago
Jul 16th, 2025
Sublime Security
Attachment: Malformed OLE file
2y ago
Nov 25th, 2024
Sublime Security
Attachment: JavaScript file with suspicious base64-encoded executable
2y ago
Apr 1st, 2024
Sublime Security
Attachment: HTML smuggling with embedded base64-encoded executable
2y ago
Mar 25th, 2024
Sublime Security