
Summary
This rule detects inbound emails where the subject contains the word 'reference' and at least one hyperlink in the body uses 'reference' as the link text, pointing to a domain registered less than 90 days ago (verified via WHOIS). The combination of a common business lure term with a recently created destination domain is a strong indicator of malicious intent, typical of credential phishing and business email compromise (BEC). The rule leverages content analysis (subject and link text), URL analysis (href_url.domain), and WHOIS (domain age) to identify such campaigns. It is labeled as medium severity and is designed to flag ongoing lure attempts while minimizing noise from legitimate communications. Potential false positives can occur when legitimate references are used with new domains or where legitimate references are present, so corroborating signals (sender reputation, historical domain usage, user alerts) should be considered for triage.
Categories
- Network
Data Sources
- Network Traffic
Created: 2026-09-29