EXPLORE DETECTIONS
Open redirect: k-mil.net
Message contains use of the k-mil.net open redirect. This has been exploited in the wild.
Open redirect: Klaviyo
Message contains use of the Klaviyo (kmail-lists.com) open redirect, but the link display text does not match known permutations. This has been exploited in the wild.
Open redirect: labcluster.com
Message contains use of the cm.labcluster.com/go.aspx redirect. This has been exploited in the wild for phishing.
Open redirect: LearningApps
Message contains use of the LearningApps open redirect. This has been exploited in the wild.
Open redirect: Linkedin
Detects emails containing links using Linkedin '/slink?code=xxxxx' open redirect where the email has not come from Linkedin.com
Open redirect: LinkedIn Redirect
Message contains use of a LinkedIn Redirect. The redirect contains a 3 second delay before redirecting the browser. This redirection has been abused by threat actors in the wild.
Open redirect: listing.ca
Message contains use of the listing.ca redirect. This has been exploited in the wild.
Open redirect: magic4media.com
Message contains use of the magic4media.com open redirect. This has been exploited in the wild.
Open redirect: magiccity.ne.jp
Message contains use of the magiccity.ne.jp redirect. This has been exploited in the wild.
Open redirect: magneticmarketing.com
Message contains use of the magneticmarketing.com open redirect. This has been exploited in the wild.
Open redirect: mail.spiceworks.com
Message contains use of the mail.spiceworks.com redirect. This has been exploited in the wild.
Open redirect: Mailtrack Korea
Detects messages containing links to mailtrack.ksd.or.kr tracking service that redirect to external domains, potentially bypassing security controls through the legitimate Korean mail tracking infrastructure.
Open redirect: marketing.edinburghairport.com
Message contains use of a marketing.edinburghairport.com redirect. This redirection has been abused by threat actors in the wild.
Open redirect: McGill University
Message contains use of McGill University's open redirect but the sender is not McGill University.
Open redirect: Medium
Message contains use of the Medium open redirect. This has been exploited in the wild.
Open redirect: Meta --> YouTube Redirection Chain
Message contains use of a redirect chain which involves Meta and YouTube. This has been exploited in the wild.
Open redirect: mindmixer.com
Message contains use of the mindmixer.com redirect. This has been exploited in the wild for phishing.
Open redirect: MSN
Message uses an MSN open redirect. Sample (benign) redirect to sublimesecurity[.]com: https[:]//www[.]msn[.]com/en-gb/lifestyle/rf-best-products-uk/redirect?url=aHR0cHM6Ly93d3cuc3VibGltZXNlY3VyaXR5LmNvbQ==
Open redirect: museepicassoparis.fr
Message contains use of the museepicassoparis.fr open redirect. This has been exploited in the wild.
Open redirect: Nested Doubleclick.net
Doubleclick.net link leveraging a nested doubleclick.net open redirect from a new or outlier sender. The unusual behavior of nesting a doubleclick URL inside another doubleclick link warrants increasing the severity of this rule.
Open redirect: Newegg
Message contains use of the Newegg open redirect, but the sender is not Newegg. This has been exploited in the wild.
Open redirect: next2.io
Message contains use of a next.io redirect. This redirection has been abused by threat actors in the wild.
Open redirect: nowlifestyle.com
Message contains use of the nowlifestyle.com open redirect. This has been exploited in the wild.
Open redirect: obunsha.co.jp
Detects messages containing Obunsha's passnavi redirect service that can be exploited to redirect users to malicious sites. This has been used in phishing campaigns.