heroui logo

Link: Recently registered .vu domain in lure

Sublime Rules

View Source
Summary
Flags inbound messages that include hyperlinks to a .vu domain registered within the last 90 days. The rule targets social-engineering campaigns where malicious content is hosted on freshly registered domains to evade reputation-based detections. It examines inbound messages (type.inbound) and any links in the body, checking that the href_url.domain.tld equals vu, the domain is valid, and the domain age from Whois is under 90 days (network.whois(.href_url.domain).days_old < 90). Observed lures span fake DocuSign contract requests, billing notices, calendar invites, party invitations, and bidding requests. The detection relies on URL analysis and Whois data to identify new, suspicious domains used in phishing campaigns. Severity is low, categorized as Attack surface reduction. Detected signals map to Credential Phishing, BEC/Fraud, and Spam, with tactics including Social engineering and Impersonation: Brand.
Categories
  • Network
Data Sources
  • Network Traffic
Created: 2026-08-29