
Service abuse: Self-service platform redirecting to newly registered suspicious domain
Sublime Rules
View SourceSummary
Detects inbound messages containing links to self-service account creation platforms that ultimately redirect to newly registered domains (less than 30 days old) using suspicious top-level domains. The rule triggers when a message body contains a link whose root domain is in the known self-service platform list, and any redirected chain leads to a final domain that is under 30 days old and uses a flagged suspicious TLD. It leverages URL/link analysis to follow redirects, WHOIS to determine domain age, and HTML analysis to inspect the linked content. This combination indicates credential phishing that abuses legitimate services to host malicious landing pages, enabling lateral movement or evasion of simple URL filters. The rule is aligned with attack surface reduction and targets credential phishing techniques that employ evasion strategies such as out-of-band pivoting."
Categories
- Endpoint
- Network
- Web
Data Sources
- Network Traffic
- Domain Name
- Application Log
Created: 2026-09-11