heroui logo

Service abuse: Meetup.com redirect with brand impersonation

Sublime Rules

View Source
Summary
Detects inbound messages that abuse Meetup.com's click-through tracking service (clicks.meetup.com) by using excessively long redirect URLs to impersonate legitimate Meetup communications. The rule flags emails whose body links point to clicks.meetup.com and where the URL length exceeds 300 characters. It excludes legitimate Meetup communications by verifying absence of Meetup branding in the HTML (specifically meetupstatic assets) and filters out high-trust senders that pass DMARC authentication. The combination reduces false positives from legitimate Meetup messages while isolating potential credential-phishing campaigns leveraging brand impersonation and open redirects. Detection relies on URL analysis, HTML analysis, content inspection, and sender authentication checks to differentiate phishing from trusted communications.
Categories
  • Web
  • Application
  • Network
Data Sources
  • Application Log
  • Network Traffic
  • Domain Name
Created: 2026-04-16