Skip to content

Conversation

@D-Bolton
Copy link
Member

@D-Bolton D-Bolton commented Dec 2, 2025

Description

Detects messages where both the subject line and sender display name contain identical 32-character alphanumeric strings, which may indicate automated generation or coordination between these fields for malicious purposes.

Associated samples

Associated hunts


@D-Bolton D-Bolton marked this pull request as ready for review December 2, 2025 22:21
@D-Bolton D-Bolton requested a review from a team as a code owner December 2, 2025 22:21
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Dec 2, 2025
github-actions bot added a commit that referenced this pull request Dec 2, 2025
github-actions bot added a commit that referenced this pull request Dec 3, 2025
github-actions bot added a commit that referenced this pull request Dec 3, 2025
@D-Bolton D-Bolton added the review-needed Indicates that a PR is waiting for review label Dec 3, 2025
@zoomequipd zoomequipd self-requested a review December 4, 2025 16:08
@@ -0,0 +1,37 @@
name: "Subject and sender display name contain matching 32-character alphanumeric string"
description: "Detects messages where both the subject line and sender display name contain identical 32-character alphanumeric strings, which may indicate automated generation or coordination between these fields for malicious purposes."
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

consider updating the description to include this matches only where with cred_theft intent or containing a unicode Right-To-Left Mark

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated description.

D-Bolton and others added 3 commits December 4, 2025 14:58
…e.yml

Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
…e.yml

Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
github-actions bot added a commit that referenced this pull request Dec 4, 2025
github-actions bot added a commit that referenced this pull request Dec 4, 2025
@D-Bolton D-Bolton requested a review from zoomequipd December 5, 2025 16:16
github-actions bot added a commit that referenced this pull request Dec 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants