Skip to content

Conversation

@JFarina5
Copy link
Member

Description

Detects single-page PDF attachments with suspicious metadata characteristics common in invoice scam campaigns, including ReportLab with default titles, OpenPDF with missing creators, or specific LibreOffice Draw versions, sent from free email providers or with missing recipients.

Associated hunts

@JFarina5 JFarina5 requested a review from a team as a code owner December 29, 2025 16:18
@JFarina5 JFarina5 added the in-test-rules PR is in our testing suite to collect telemetry label Dec 29, 2025
github-actions bot added a commit that referenced this pull request Dec 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant