← Back to Explore
sublimelowRule
Rootlayer VPS in Headers
The message was sent using a Rootlayer VPS, a provider known to be used for phishing.
Detection Query
type.inbound
and any(headers.domains, .domain == "hosted-by.rootlayer.net" )
Author
ajpc500
Data Sources
Email MessagesEmail HeadersEmail Attachments
Platforms
email
Tags
Suspicious headers
Raw Content
name: "Rootlayer VPS in Headers"
description: |
The message was sent using a Rootlayer VPS, a provider known to be used for phishing.
type: "rule"
severity: "low"
authors:
- twitter: "ajpc500"
source: |
type.inbound
and any(headers.domains, .domain == "hosted-by.rootlayer.net" )
tags:
- "Suspicious headers"