Medium Severity

Link: Newly registered suspicious domain with single-character HTML filename

Description

Detects inbound emails containing links where the URL path ends in a single-character HTML filename, the domain uses a suspicious top-level domain, and the domain was registered fewer than 30 days ago. This combination of indicators is commonly associated with rapidly deployed phishing kits hosted on freshly registered infrastructure.

References

No references.

Sublime Security
Created Sep 25th, 2026 • Last updated Sep 25th, 2026
Source
type.inbound
and any(body.current_thread.links,
        regex.icontains(.href_url.path, '/[^/]\.html')
        and .href_url.domain.tld in $suspicious_tlds
        and network.whois(.href_url.domain).days_old < 30
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started