Analytics BIOC Informational

Email attachment(s) with potentially malicious MIME type

The email message contains an attachment(s) with a potentially malicious MIME type.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Defense Evasion (TA0005) Execution (TA0002)
ATT&CK techniques: Masquerading: Masquerade File Type (T1036.008) User Execution (T1204)
Attacker's goals:

Bypass security filters and deliver malicious content to users Deploy malicious attachments through emails to compromise systems, gain unauthorized access, or facilitate cyber threats.

Investigative actions:

Carefully analyze attachments for any indications of suspicious or malicious behavior. Scrutinize the attachments for any suspicious indications. Confirm whether the attachments were successfully delivered to the recipient's mailbox. If the attachments were delivered successfully, verify whether the recipient downloaded them.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Attachment(s) with potentially malicious MIME type unusual for the organization Informational
  • Attachment(s) with a potentially malicious MIME type that is unusual for the recipient Informational