Detection Method: Whois

Whois analysis retrieves and examines domain registration information from global Whois databases to spot suspicious or recently created domains that could indicate phishing attempts. This method helps you understand key domain details like the age, ownership, and registration patterns, which can be red flags for malicious activity.
Whois analysis can detect:
  • Newly registered domains that might have been set up just for phishing campaigns
  • Domains with suspicious registration patterns or incomplete Whois records
  • Mismatched registration details that don’t align with the claimed organization
  • Domains registered via privacy services to conceal true ownership
  • Domains with upcoming expiration dates, which could indicate temporary use
For example, established organizations often use domains that have been registered for long periods. So, if you get an email from a financial institution using a domain that was registered only a few days ago, that’s a huge red flag.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS voicemail lure with suspicious link
1h ago
Sep 16th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
22h ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Spam: Fake photo share
5d ago
Sep 11th, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
6d ago
Sep 10th, 2026
Sublime Security
Link: Fake video link from newly registered domain
8d ago
Sep 8th, 2026
Sublime Security
BEC: Wealth management lure from newly registered domain
8d ago
Sep 8th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
12d ago
Sep 4th, 2026
Sublime Security
Service abuse: Zoom Clips with suspicious reply-to address or links
15d ago
Sep 1st, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
16d ago
Aug 31st, 2026
Sublime Security
Service abuse: EventCreate links to newly registered domains
16d ago
Aug 31st, 2026
Sublime Security
Link: Recently registered .vu domain in lure
19d ago
Aug 28th, 2026
Sublime Security
Link: Document-themed link to newly registered domain
29d ago
Aug 18th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
30d ago
Aug 17th, 2026
Sublime Security
New link domain (<=10d) from untrusted sender
1mo ago
Aug 10th, 2026
Sublime Security
Spam: Large financial amount mention from newly registered sender domain
1mo ago
Aug 3rd, 2026
Sublime Security
Service abuse: Adobe message from newly registered domain
1mo ago
Jul 31st, 2026
Sublime Security
Brand impersonation: Microsoft fake sign-in alert
1mo ago
Jul 27th, 2026
Sublime Security
Impersonation: Suspected supplier impersonation with suspicious content
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Anthropic/Claude with newly registered domain
1mo ago
Jul 24th, 2026
Sublime Security