EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Open redirect: k-mil.net

Message contains use of the k-mil.net open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: Klaviyo

Message contains use of the Klaviyo (kmail-lists.com) open redirect, but the link display text does not match known permutations. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Open redirect: labcluster.com

Message contains use of the cm.labcluster.com/go.aspx redirect. This has been exploited in the wild for phishing.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: LearningApps

Message contains use of the LearningApps open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: Linkedin

Detects emails containing links using Linkedin '/slink?code=xxxxx' open redirect where the email has not come from Linkedin.com

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: LinkedIn Redirect

Message contains use of a LinkedIn Redirect. The redirect contains a 3 second delay before redirecting the browser. This redirection has been abused by threat actors in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: listing.ca

Message contains use of the listing.ca redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: magic4media.com

Message contains use of the magic4media.com open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: magiccity.ne.jp

Message contains use of the magiccity.ne.jp redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: magneticmarketing.com

Message contains use of the magneticmarketing.com open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: mail.spiceworks.com

Message contains use of the mail.spiceworks.com redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: Mailtrack Korea

Detects messages containing links to mailtrack.ksd.or.kr tracking service that redirect to external domains, potentially bypassing security controls through the legitimate Korean mail tracking infrastructure.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Open redirect: marketing.edinburghairport.com

Message contains use of a marketing.edinburghairport.com redirect. This redirection has been abused by threat actors in the wild.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Open redirect: McGill University

Message contains use of McGill University's open redirect but the sender is not McGill University.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimelow

Open redirect: Medium

Message contains use of the Medium open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: Meta --> YouTube Redirection Chain

Message contains use of a redirect chain which involves Meta and YouTube. This has been exploited in the wild.

T1566T1566.001T1566.002T1598
Sublimemedium

Open redirect: mindmixer.com

Message contains use of the mindmixer.com redirect. This has been exploited in the wild for phishing.

T1566T1566.001T1566.002T1598
Sublimemedium

Open redirect: MSN

Message uses an MSN open redirect. Sample (benign) redirect to sublimesecurity[.]com: https[:]//www[.]msn[.]com/en-gb/lifestyle/rf-best-products-uk/redirect?url=aHR0cHM6Ly93d3cuc3VibGltZXNlY3VyaXR5LmNvbQ==

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: museepicassoparis.fr

Message contains use of the museepicassoparis.fr open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: Nested Doubleclick.net

Doubleclick.net link leveraging a nested doubleclick.net open redirect from a new or outlier sender. The unusual behavior of nesting a doubleclick URL inside another doubleclick link warrants increasing the severity of this rule.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimehigh

Open redirect: Newegg

Message contains use of the Newegg open redirect, but the sender is not Newegg. This has been exploited in the wild.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: next2.io

Message contains use of a next.io redirect. This redirection has been abused by threat actors in the wild.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Open redirect: nowlifestyle.com

Message contains use of the nowlifestyle.com open redirect. This has been exploited in the wild.

T1566T1566.001T1566.002T1598
Sublimemedium

Open redirect: obunsha.co.jp

Detects messages containing Obunsha's passnavi redirect service that can be exploited to redirect users to malicious sites. This has been used in phishing campaigns.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium
PreviousPage 40 of 53Next