
Evasion: Credential phishing with newly registered domain redirecting to Wikipedia
Sublime Rules
View SourceSummary
This rule flags credential phishing attempts embedded in inbound messages that contain natural language understanding (NLU) detected cred_theft intent in the message body, combined with a link pointing to a newly registered domain (registered within the last 30 days) that resolves via link analysis to Wikipedia. It targets evasion of link-analysis systems by steering users toward a benign-looking redirect destination. The detection requires: (1) inbound message text analyzed by an NLU classifier with an intent named cred_theft and a confidence level not 'low'; (2) at least one link in the message whose domain age is <30 days per WHOIS data; and (3) the link's effective URL, after link-analysis, equals https://www.wikipedia.org/. When all conditions are met, the rule triggers a credential phishing alert with evasion/social engineering characteristics.
Categories
- Network
- Web
- Endpoint
Data Sources
- Web Credential
- Network Traffic
Created: 2026-10-02