Analytics BIOC Informational

Email contains URL delivering high-risk file type

Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)
Detector tags: Malicious URLs
Attacker's goals:

To bypass attachment-based blocking by delivering malware or exploiting payloads via URLs pointing to file types commonly blocked by email vendors.

Investigative actions:

Review the URLs and determine if they host executable or script-based content. Check threat intelligence sources for reputation or known associations with malware. Investigate whether any users clicked the URL or downloaded the file. Analyze the file content using sandbox or static analysis tools.

Test period:
N/A (single event)
Deduplication:
1 Hour 30 Minutes
1 variation:
  • External email with URL delivers blocked file types Low (parent: Informational)