Skip to content

Commit 8e6d176

Browse files
Update observed IOC rules - 2026-06-19 (#4704)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
1 parent c2959c1 commit 8e6d176

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

detection-rules/observed_malicious_sender_domains.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,10 @@ source: |
77
// Managed by automated IOC system
88
type.inbound
99
and hash.sha256(sender.email.domain.domain) in (
10-
'28b686d3c7b091ebdda1373f58a16635f4dacaaa748d0a4f2175273a09662770' // Malicious Sender - Multiple Lures spaning multiple days
10+
'28b686d3c7b091ebdda1373f58a16635f4dacaaa748d0a4f2175273a09662770', // Malicious Sender - Multiple Lures spaning multiple days
11+
'485e31e6b5bb45a44e24eb69ce3daafc6ea335b5d387e80684298a5397358840', // Observed compromised account
12+
'6a6070cb3594362b3c54d21006450be34222dc578acbc97b357f946d8d564471', // Observed compromised account
13+
'7606728ae9565e84698ddba62e40a35865ec7edbd5ca7710d8a7182768dc439d' // Observed compromised account
1114
)
1215
1316
attack_types:

detection-rules/observed_malicious_sender_emails.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,10 +8,8 @@ source: |
88
type.inbound
99
and hash.sha256(sender.email.email) in (
1010
'4ee49251788e4434160029e76e7c168432a1d5df45177b8c113a60562b2f4743', // Observed malicious sender
11-
'7affbe4b711761fcbeea34fafe0df6d217463064e60510e12af92b57dbfbf186', // Observed malicious sender
1211
'8030cd12e522cf160c85171bfaee999d095e79bd66815d4604f5e4406a1c566c', // Observed malicious sender - multiple cred phish lures
13-
'b2051a0fd6b19df331f4ee71671c8a6fc621544fb046574edd8233a585247d0a', // Observed malicious sender
14-
'd3193407cf75baf52783c7bfc1929e7c968cd71d113c12cba0b4b31e68dce8ff' // Observed malicious sender
12+
'b2051a0fd6b19df331f4ee71671c8a6fc621544fb046574edd8233a585247d0a' // Observed malicious sender
1513
)
1614
1715
attack_types:

0 commit comments

Comments
 (0)