heroui logo

Observed IOC: Malicious attachment SHA-256 hashes

Sublime Rules

View Source
Summary
Observes inbound messages containing attachments and compares the attachment file’s SHA-256 hash against an automatically managed IOC list of known malicious files. The rule follows the pipeline’s hash-of-hash convention (SHA-256 of the file hash). It leverages attachment analysis and content analysis to detect malicious payloads. Severity is high and aligned with Malware/Ransomware and Credential Phishing intents; associated tactics include Social engineering and Evasion. Note: IOC list is auto-managed by the IOC pipeline and currently reports no active IOCs, resulting in the rule being temporarily disabled (false in source).
Categories
  • Network
  • Endpoint
Data Sources
  • File
Created: 2026-08-29