EXPLORE DETECTIONS
Open redirect: amaterasu-for-website-5.com
Detects messages containing amaterasu-for-website-5.com redirect links that use the url parameter to redirect users to malicious sites. This has been observed in phishing campaigns.
Open redirect: api.spently.com
Message contains use of the api.spently.com redirect. This has been exploited in the wild.
Open redirect: Artisteer
Message contains use of the Artisteer open redirect, but the sender is not Artisteer. This has been exploited in the wild.
Open redirect: artkaderne
Message contains use of an open redirect on artkaderne.dk. This has been exploited in the wild.
Open Redirect: asemailmgmteu.com
Message contains use of the asemailmgmteu.com open redirect. This has been exploited in the wild.
Open redirect: astroarts.co.jp
Message contains use of the astroarts.co.jp redirect. This has been exploited in the wild.
Open redirect: Atdmt
Message contains use of the Atdmt (Facebook) open redirect.
Open redirect: Avast
Detects emails containing links to avast.com leveraging an open redirect
Open redirect: bananaguide.com
Message contains use of the bananaguide.com redirect with url parameter. This has been exploited in the wild.
Open redirect: bangkoksync.com
Message contains use of the bangkoksync.com open redirect. This has been exploited in the wild.
Open redirect: bestdeals.today
Message contains use of the bestdeals.today open redirect. This has been exploited in the wild.
Open redirect: Bitrix24 URL Path
Message contains use of the Bitrix24 redirect. This has been exploited in the wild for phishing.
Open redirect: BMW USA
Message contains use of BMW USA's open redirect but the sender is not BMW.
Open redirect: bubblelife.com
Message contains use of the bubblelife.com redirect. This has been exploited in the wild.
Open redirect: buildingengines.com
Detects messages containing buildingengines.com redirect links that use the _redirectTo parameter to redirect users to malicious sites. This has been observed in phishing campaigns.
Open redirect: business.google.com website_shared URL Param
Detects messages containing an open redirect in business.google.com's website_shared/launch_bw.html endpoint with the 'f' parameter. This has been exploited in phishing campaigns to redirect users to malicious sites.
Open redirect: Cartoon Network
This rule detects the use of Cartoon Network's Denmark domain as an open redirect.
Open redirect: chkc.com.hk
Message contains use of the chkc.com.hk open redirect. This has been exploited in the wild.
Open redirect: City of Calgary
Message contains use of calgary.ca's open redirect but the sender is not the City of Calgary.
Open redirect: Club-OS
Message contains use of the Club-OS open redirect. This has been exploited in the wild.
Open redirect: convertcart.com
Message contains use of the convertcart.com redirect. This has been exploited in the wild.
Open redirect: Dell
Message contains use of the Dell open redirect, but the sender is not Dell.
Open redirect: designsori.com
Message contains use of the designsori.com open redirect. This has been exploited in the wild.
Open redirect: Diesel.az
Detects inbound messages containing links that abuse Diesel.az's open redirect functionality at '/az/redirect', where the 'url' query parameter points to an external domain. The rule flags messages where the sender is not from diesel.az and the redirect destination leads outside of the diesel.az domain.