heroui logo

Attachment: Encrypted ZIP containing VHDX file

Sublime Rules

View Source
Summary
Detects inbound ZIP attachments that are encrypted and contain VHDX files. The rule targets potential evasion and malware delivery by identifying encrypted archives (ZIP) that house VHDX disk images, which can be used to bypass security controls or introduce malicious payloads. It leverages archive analysis to inspect encrypted archives and file analysis to verify the presence of .vhdx files inside the archive, triggering on matching attachments.
Categories
  • Endpoint
Data Sources
  • File
Created: 2026-04-04