Skip to content

Comments

Create headers_mailer_contains_hidden_content.yml#3474

Closed
D-Bolton wants to merge 3 commits intomainfrom
Headers--Microsoft-CDO-or-PHPMailer-with-hidden-content
Closed

Create headers_mailer_contains_hidden_content.yml#3474
D-Bolton wants to merge 3 commits intomainfrom
Headers--Microsoft-CDO-or-PHPMailer-with-hidden-content

Conversation

@D-Bolton
Copy link
Member

@D-Bolton D-Bolton commented Nov 4, 2025

Description

Detects messages sent via Microsoft CDO for Windows 2000 or PHPMailer that contain HTML paragraph elements with transparent text or hidden content styling, commonly used to evade content analysis.

Associated samples

Associated hunts

@D-Bolton D-Bolton requested a review from a team as a code owner November 4, 2025 18:44
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 4, 2025
github-actions bot added a commit that referenced this pull request Nov 4, 2025
github-actions bot added a commit that referenced this pull request Nov 5, 2025
@D-Bolton D-Bolton added review-needed Indicates that a PR is waiting for review and removed review-needed Indicates that a PR is waiting for review labels Nov 5, 2025
@D-Bolton
Copy link
Member Author

I'm no longer pursuing this detection.

@D-Bolton D-Bolton closed this Nov 20, 2025
@D-Bolton D-Bolton removed the in-test-rules PR is in our testing suite to collect telemetry label Nov 20, 2025
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant