Skip to content

Update impersonation_fake_copyright_infringement_notice_from_unsolicited_sender.yml#4690

Merged
JFarina5 merged 2 commits into
mainfrom
JFarina5.FN.ESC-15259.impersonation.fake.copyright.infring
Jun 24, 2026
Merged

Update impersonation_fake_copyright_infringement_notice_from_unsolicited_sender.yml#4690
JFarina5 merged 2 commits into
mainfrom
JFarina5.FN.ESC-15259.impersonation.fake.copyright.infring

Conversation

@JFarina5

@JFarina5 JFarina5 commented Jun 17, 2026

Copy link
Copy Markdown
Member

Description

Observed samples without links in the body, taking out logic requiring a link to capture additional samples

Associated samples

Associated hunts

@JFarina5 JFarina5 requested a review from a team June 17, 2026 15:47
@JFarina5 JFarina5 requested a review from a team as a code owner June 17, 2026 15:47
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jun 17, 2026
github-actions Bot added a commit that referenced this pull request Jun 17, 2026
github-actions Bot added a commit that referenced this pull request Jun 17, 2026
…al firm with copyright infringement notice
@JFarina5

Copy link
Copy Markdown
Member Author

Pretty minor change, but results are looking good. Hunt in description has been updated, marking r4r.

@JFarina5 JFarina5 added the review-needed Indicates that a PR is waiting for review label Jun 23, 2026

@zoomequipd zoomequipd left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do all the net new samples include QR codes?
Would it make sense to instead add an or statement for something like
or beta.scan_qr(file.message_screenshot()).found

@zoomequipd zoomequipd self-assigned this Jun 23, 2026
@JFarina5

Copy link
Copy Markdown
Member Author

Do all the net new samples include QR codes? Would it make sense to instead add an or statement for something like or beta.scan_qr(file.message_screenshot()).found

Yep, based on hunt results, looks like they all utilize a QR code rather than a direct link. Looks like roughly the same results based on this hunt, but we miss this sample due to the QR code not being attached and missing in the body.

…ted_sender.yml

Updating to keep link length logic and look for QR codes specifically
github-actions Bot added a commit that referenced this pull request Jun 24, 2026
@JFarina5 JFarina5 added this pull request to the merge queue Jun 24, 2026
Merged via the queue into main with commit 97de323 Jun 24, 2026
5 checks passed
@JFarina5 JFarina5 deleted the JFarina5.FN.ESC-15259.impersonation.fake.copyright.infring branch June 24, 2026 14:25
github-actions Bot added a commit that referenced this pull request Jun 24, 2026
github-actions Bot added a commit that referenced this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants