Email attachment with a potentially malicious file extension
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour 30 Minutes
Required Data
Microsoft 365 Emails
Detection Modules
ATT&CK Tactic
Initial Access (TA0001), Execution (TA0002)
ATT&CK Technique
Phishing (T1566), User Execution (T1204)
Severity
Informational
Description
The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature.
Attacker's Goals
Trick users into clicking on malicious attachments
Deploy malicious attachments through emails to compromise systems, gain unauthorized access, or facilitate cyber threats.
Investigative actions
Check the file types and investigate the legitimacy of files intended to be sent via email.
Scrutinize the attachments for any suspicious indications.
Confirm whether the attachments were successfully delivered to the recipient's mailbox.
If the attachments were delivered successfully, verify whether the recipient downloaded them.
Check the email address for any unusual spellings.
Check the email address for any missing letters.
Verify the sender's domain to confirm its legitimacy.
Examine the sender's IP address and reputation.
Verify whether the sender's IP address has appeared in different log sources before.
Verify if the sender's IP address is identifiable.
Variations
Was this helpful?
