heroui logo

Brand impersonation: ConstructConnect

Sublime Rules

View Source
Summary
Technical summary: This inbound-rule targets brand impersonation of the ConstructConnect platform to facilitate credential phishing. It triggers when an email has a single recipient and either the sender equals the recipient (self-sent) or the recipient domain is invalid. The message must contain between 1 and 9 links in the current thread. For any link, the rule looks for a mismatch where the link’s root_domain is not constructconnect.com, yet an aggressive link-analysis pass on that link shows that the external domain has accessed resources whose domain.root_domain is constructconnect.com and whose path contains logo or favicon.ico. In other words, the rule detects scenarios where an attacker links to an external site but leverages assets (logo or favicon) hosted on constructconnect.com to make the phishing page appear legitimate. Detection relies on sender analysis and URL analysis to reduce false positives and surface potential brand spoofing and social engineering attempts. The rule is categorized as high severity and aligned with credential phishing behaviors and brand impersonation techniques.
Categories
  • Web
Data Sources
  • User Account
  • Domain Name
  • Network Traffic
Created: 2026-10-06