
Summary
This rule flags inbound messages that instruct the recipient to copy or paste a URL into a web browser and then analyzes the surrounding text for a bare (non-hyperlinked) hostname. The trigger fires when a hostname extracted from the instruction window is not hyperlinked anywhere else in the message, does not match the sender's own domain, and is hosted on a known set of free subdomain providers. The technique is consistent with attempts to evade automated URL scanning by avoiding clickable hyperlinks. The detector locates a window spanning up to two lines around phrases like copy/ copied / paste/ pasted into the browser, extracts bare hostnames from that window, normalizes them to a domain, and checks the domain against the message’s linked domains and the sender’s domain. If the host is external, unlinked, and in a curated free-subdomain list, an alert is raised as Credential Phishing. The rule is associated with evasion, use of free subdomain hosting, and social engineering.
Categories
- Endpoint
Data Sources
- Domain Name
Created: 2026-09-30