Skip to content

Create attachment_pdf_cred_theft_invalid_reply_to.yml#4327

Merged
D-Bolton merged 5 commits intomainfrom
daniel.fn.ESC-10200.FN---EXTERNAL]-#AllStaff-Ticket_ID-78216-2
Apr 10, 2026
Merged

Create attachment_pdf_cred_theft_invalid_reply_to.yml#4327
D-Bolton merged 5 commits intomainfrom
daniel.fn.ESC-10200.FN---EXTERNAL]-#AllStaff-Ticket_ID-78216-2

Conversation

@D-Bolton
Copy link
Copy Markdown
Member

@D-Bolton D-Bolton commented Apr 8, 2026

Description

Detects PDF attachments containing high-confidence credential theft language that references the recipient's email address, combined with an invalid reply-to domain header.

Associated samples

Associated hunts

@D-Bolton D-Bolton marked this pull request as ready for review April 8, 2026 18:21
@D-Bolton D-Bolton requested a review from a team April 8, 2026 18:21
@D-Bolton D-Bolton requested a review from a team as a code owner April 8, 2026 18:21
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 8, 2026
github-actions bot added a commit that referenced this pull request Apr 8, 2026
github-actions bot added a commit that referenced this pull request Apr 8, 2026
…th credential theft language and invalid reply-to domain
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…ith credential theft language and invalid reply-to domain
github-actions bot added a commit that referenced this pull request Apr 9, 2026
… with credential theft language and invalid reply-to domain
github-actions bot added a commit that referenced this pull request Apr 9, 2026
…l theft language and invalid reply-to domain
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 9, 2026
…F with credential theft language and invalid reply-to domain
github-actions bot added a commit that referenced this pull request Apr 9, 2026
… with credential theft language and invalid reply-to domain
github-actions bot added a commit that referenced this pull request Apr 9, 2026
…l theft language and invalid reply-to domain
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 9, 2026
…F with credential theft language and invalid reply-to domain
Comment thread detection-rules/attachment_pdf_cred_theft_invalid_reply_to.yml Outdated
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
@D-Bolton D-Bolton requested a review from zoomequipd April 10, 2026 19:41
github-actions bot added a commit that referenced this pull request Apr 10, 2026
…l theft language and invalid reply-to domain
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 10, 2026
…F with credential theft language and invalid reply-to domain
github-actions bot added a commit that referenced this pull request Apr 10, 2026
… with credential theft language and invalid reply-to domain
@D-Bolton D-Bolton added this pull request to the merge queue Apr 10, 2026
Merged via the queue into main with commit 30d7c87 Apr 10, 2026
3 checks passed
@D-Bolton D-Bolton deleted the daniel.fn.ESC-10200.FN---EXTERNAL]-#AllStaff-Ticket_ID-78216-2 branch April 10, 2026 19:55
github-actions bot added a commit that referenced this pull request Apr 10, 2026
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 10, 2026
github-actions bot added a commit that referenced this pull request Apr 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants