EXPLORE
← Back to Explore
sublimelowRule

Rootlayer VPS in Headers

The message was sent using a Rootlayer VPS, a provider known to be used for phishing.

Detection Query

type.inbound 
and any(headers.domains, .domain == "hosted-by.rootlayer.net" )

Author

ajpc500

Data Sources

Email MessagesEmail HeadersEmail Attachments

Platforms

email

Tags

Suspicious headers
Raw Content
name: "Rootlayer VPS in Headers"
description: |
  The message was sent using a Rootlayer VPS, a provider known to be used for phishing.
type: "rule"
severity: "low"
authors:
  - twitter: "ajpc500"
source: |
  type.inbound 
  and any(headers.domains, .domain == "hosted-by.rootlayer.net" )
tags:
  - "Suspicious headers"