Skip to content

Conversation

@IndiaAce
Copy link
Member

Description

This rule detects impersonation attempts through fake file sharing notifications that exhibit specific HTML structures and themes related to procurement. It identifies various suspicious elements such as AI generation comments and tracking pixels.

Associated samples

Associated hunts

This rule detects impersonation attempts through fake file sharing notifications that exhibit specific HTML structures and themes related to procurement. It identifies various suspicious elements such as AI generation comments and tracking pixels.
@IndiaAce IndiaAce requested a review from a team as a code owner January 22, 2026 13:05
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 22, 2026
github-actions bot added a commit that referenced this pull request Jan 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant