Skip to content

Create rule: Generic Financial Document Template#4498

Open
missingn0pe wants to merge 2 commits into
mainfrom
missingn0pe.fn.ESC-13584.new_rule_generic_financials_template
Open

Create rule: Generic Financial Document Template#4498
missingn0pe wants to merge 2 commits into
mainfrom
missingn0pe.fn.ESC-13584.new_rule_generic_financials_template

Conversation

@missingn0pe
Copy link
Copy Markdown
Member

Description

Detects messages with generic 'dear sir/madam' greetings that reference payment releases & timelines, contain links with suspicious hosting or open redirects, and exhibit unusual recipient patterns such as self-sending or missing recipients.

Associated samples

- Sample 1

Associated hunts

- Hunt 1 (Shared Samples)
- Hunt 2 (Multi-hunt)

Detects messages with generic 'dear sir/madam' greetings that reference payment releases & timelines, contain links with suspicious hosting or open redirects, and exhibit unusual recipient patterns such as self-sending or missing recipients.
@missingn0pe missingn0pe requested a review from a team May 15, 2026 22:31
@missingn0pe missingn0pe requested a review from a team as a code owner May 15, 2026 22:31
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 15, 2026
github-actions Bot added a commit that referenced this pull request May 15, 2026
github-actions Bot added a commit that referenced this pull request May 15, 2026
…ncial document and suspicious hosting template
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 19, 2026
…ancial document and suspicious hosting template
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant