Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

Detects messages containing two attachments where one is a PowerPoint file with suspicious character substitution in the filename ('Empl0yment' using zero instead of 'o') and body text claiming an employment contract has been updated.

Associated samples

Associated hunts

@MSAdministrator MSAdministrator requested a review from a team as a code owner January 23, 2026 19:23
@MSAdministrator
Copy link
Member Author

This is related to #3696

@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 23, 2026
github-actions bot added a commit that referenced this pull request Jan 23, 2026
@MSAdministrator MSAdministrator self-assigned this Jan 24, 2026
@MSAdministrator MSAdministrator added the review-needed Indicates that a PR is waiting for review label Jan 24, 2026
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
github-actions bot added a commit that referenced this pull request Jan 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants