Skip to content

Conversation

@D-Bolton
Copy link
Member

@D-Bolton D-Bolton commented Nov 4, 2025

Description

Detects messages sent via Microsoft CDO for Windows 2000 or PHPMailer that contain HTML paragraph elements with transparent text or hidden content styling, commonly used to evade content analysis.

Associated samples

Associated hunts

@D-Bolton D-Bolton requested a review from a team as a code owner November 4, 2025 18:44
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 4, 2025
github-actions bot added a commit that referenced this pull request Nov 4, 2025
github-actions bot added a commit that referenced this pull request Nov 5, 2025
@D-Bolton D-Bolton added review-needed Indicates that a PR is waiting for review and removed review-needed Indicates that a PR is waiting for review labels Nov 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant