For the complete documentation index, see llms.txt. This page is also available as Markdown.

Email contains URL delivering high-risk file type

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Hour 30 Minutes

Required Data

Microsoft 365 Emails

Detection Modules

Email

Detector Tags

Malicious URLs

ATT&CK Tactic

Execution (TA0002), Credential Access (TA0006)

ATT&CK Technique

User Execution (T1204), Brute Force: Password Cracking (T1110.002)

Severity

Informational

Description

Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery.

Attacker's Goals

To bypass attachment-based blocking by delivering malware or exploiting payloads via URLs pointing to file types commonly blocked by email vendors.

Investigative actions

  • Review the URLs and determine if they host executable or script-based content.

  • Check threat intelligence sources for reputation or known associations with malware.

  • Investigate whether any users clicked the URL or downloaded the file.

  • Analyze the file content using sandbox or static analysis tools.

Variations

External email with URL delivers blocked file types

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Credential Access (TA0006)

ATT&CK Technique

User Execution (T1204), Brute Force: Password Cracking (T1110.002)

Severity

Low

Description

Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery.

Attacker's Goals

To bypass attachment-based blocking by delivering malware or exploiting payloads via URLs pointing to file types commonly blocked by email vendors.

Investigative actions

  • Review the URLs and determine if they host executable or script-based content.

  • Check threat intelligence sources for reputation or known associations with malware.

  • Investigate whether any users clicked the URL or downloaded the file.

  • Analyze the file content using sandbox or static analysis tools.

Was this helpful?