Skip to content

Create link_self_sender_doc_lure_external_domain.yml#4510

Open
MSAdministrator wants to merge 2 commits into
mainfrom
msadministrator.fp.ESC-13746.link_self_sender_doc_lure_external_domain
Open

Create link_self_sender_doc_lure_external_domain.yml#4510
MSAdministrator wants to merge 2 commits into
mainfrom
msadministrator.fp.ESC-13746.link_self_sender_doc_lure_external_domain

Conversation

@MSAdministrator
Copy link
Copy Markdown
Member

@MSAdministrator MSAdministrator commented May 19, 2026

Description

Detects self-addressed messages from authenticated business email accounts containing document-sharing language and links to external domains. These messages often indicate compromised account testing where attackers validate phishing infrastructure before targeting external recipients. The combination of DMARC authentication, document lure patterns, external links, and ML-detected credential theft intent suggests an attacker is using a legitimate compromised account to test their phishing campaign.

Associated samples

Associated hunts

@MSAdministrator MSAdministrator requested a review from a team May 19, 2026 21:11
@MSAdministrator MSAdministrator requested a review from a team as a code owner May 19, 2026 21:11
github-actions Bot added a commit that referenced this pull request May 19, 2026
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 19, 2026
github-actions Bot added a commit that referenced this pull request May 19, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant