OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Others

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This is the Trend Micro detection for cousin domain tactics in a fraudulent email message. A cousin or lookalike domain is a domain that looks deceptively similar to a legitimate target domain. Cousin domains are often used in phishing or business email compromise (BEC) attacks to steal sensitive or confidential information from users. Cousin domains are usually created by replacing one or more characters or adding or removing an extra character in the domain name.

Without careful inspection of the domains, users may not notice the trick and think that an email message is sent from a legitimate domain being forged.

  SOLUTION

Minimum Scan Engine: 9.850

NOTES:

If your Trend Micro product detects an email with this detection name, it is recommended to delete or quarantine it. Never open attachments or click on URLs in email messages under this detection. Never follow instructions in messages detected as this threat, or in any message from an unknown source.


Did this description help? Tell us how we did.