Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

Detects messages containing attachments or content that reference known fake identities used in FC Barcelona scams, including fake lawyer Michael Gerardus Hermanus Demon and sports agents with the surname Giuffrida. The rule examines EXIF metadata, OCR text from attachments, and message body content for these specific identity markers.

Reference
Another Reference

Associated samples

Associated hunts

@MSAdministrator MSAdministrator self-assigned this Jan 21, 2026
@MSAdministrator MSAdministrator requested a review from a team as a code owner January 21, 2026 01:32
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 21, 2026
@github-actions github-actions bot removed the in-test-rules PR is in our testing suite to collect telemetry label Jan 21, 2026
github-actions bot added a commit that referenced this pull request Jan 21, 2026
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant