
Summary
This rule detects inbound emails that contain a hyperlink whose visible display text exactly matches the abbreviated term 'unsb'. It targets social engineering tactics commonly used in spam and business email compromise (BEC) by presenting a legitimate-looking link while obscuring the true destination. Detection relies on content analysis of the email body to identify links and URL analysis to inspect the hyperlink text. When a match is found, the message is flagged for further inspection or mitigation. The rule is labeled as low severity, reflecting its placement as one of several phishing/social engineering signals rather than a definitive malware indicator. Operators should consider supplemental controls such as mail filtering, sender authentication (DKIM/SPF/DMARC), and user education to reduce exposure to this pattern.
Categories
- Endpoint
Data Sources
- File
Created: 2026-09-08