Skip to content

Refactor keywords in Cloud service with credential theft language#4527

Open
cybher0808 wants to merge 2 commits into
mainfrom
cybher0808.fn.esc-13941.cloudservice
Open

Refactor keywords in Cloud service with credential theft language#4527
cybher0808 wants to merge 2 commits into
mainfrom
cybher0808.fn.esc-13941.cloudservice

Conversation

@cybher0808
Copy link
Copy Markdown
Member

@cybher0808 cybher0808 commented May 21, 2026

Description

Finding additional keywords that also contains a string text - "Cloud+"

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team May 21, 2026 23:00
@cybher0808 cybher0808 requested a review from a team as a code owner May 21, 2026 23:00
@cybher0808 cybher0808 self-assigned this May 21, 2026
@cybher0808 cybher0808 added the in-test-rules PR is in our testing suite to collect telemetry label May 21, 2026
github-actions Bot added a commit that referenced this pull request May 21, 2026
…: Cloud branding service with credential theft language
github-actions Bot added a commit that referenced this pull request May 21, 2026
@cybher0808
Copy link
Copy Markdown
Member Author

cybher0808 commented May 22, 2026

Telemetry looks sweet with about 99.82% of malicious/FN's.

  • There is 1 email labeled benign from this hunt that looks weird or is it just me??? -
    This email - the end of the email looks compared the rest of the emails from this sender. See my notes in ESC for further details.

Marking for R4R for feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant