Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

Detects PDF attachments containing URLs with ULID/UUID patterns in /app/ structures combined with social engineering keywords like 'SECURE', 'REVIEW', or 'ACCESS' from suspicious senders. The URLs target non-legitimate file sharing domains and end with action-oriented endpoints.

Associated samples

Associated hunts

@MSAdministrator MSAdministrator requested a review from a team as a code owner December 22, 2025 22:31
@MSAdministrator MSAdministrator self-assigned this Dec 22, 2025
@MSAdministrator MSAdministrator added the in-test-rules PR is in our testing suite to collect telemetry label Dec 22, 2025
github-actions bot added a commit that referenced this pull request Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant