
Summary
This rule detects inbound emails that carry .mobileconfig attachments tied to malicious profile distribution campaigns. It triggers when an email has any attachment with the .mobileconfig extension and either of two signals is present: (1) the parsed attachment text contains the specific malicious UUID 10a30957-e16b-30bf-c00f-48e1e9a85069, or (2) the attachment’s SHA-256 hash matches one of three known malicious hashes (783cdb7425fbc29f5e35801d38a4782040da7f50e74d78de4b56eaa532eda82a, ee8f15128560c2b2b4ee242026b2a2880ee604fe8489abb999ac43c969cfcdce, 8c0013f6ee4fe229f567469ed3f1bdaf2ee6a7a4b39a04ed28df38fa25287dfb). Malicious mobileconfig profiles lure users into installing a bogus update, often leveraging payment- or account-themed subject lines and spoofed or disposable sender domains. The detected artifact type is a file attachment, and the rule combines content analysis (searching the parsed text) with file analysis (extension and hash matching) and threat intelligence (reference to known bad hashes/UUID). Attacks are categorized as Credential Phishing with social engineering techniques. The rule is designed to be enforced at mail ingress or related network/endpoint gateways that inspect inbound messages for malicious configuration profiles.
Categories
- Network
- Endpoint
Data Sources
- File
Created: 2026-09-29