Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

Detects messages with HTML content generated by Microsoft tools (MSHTML) or specific CSS styling patterns, where links contain the recipient's email address in URL parameters, paths, or fragments. This targeting technique is commonly used to personalize malicious content and bypass security filters.

This actually derived out of samples from telegram API abuse/usage using link analysis draft rule here

Associated samples

Associated hunts

@MSAdministrator MSAdministrator self-assigned this Dec 22, 2025
@MSAdministrator MSAdministrator requested a review from a team as a code owner December 22, 2025 22:01
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Dec 22, 2025
github-actions bot added a commit that referenced this pull request Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant