heroui logo

Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain

Sublime Rules

View Source
Summary
Detects inbound messages addressed to a single recipient where the body includes a link that embeds the recipient’s email address in a URL query parameter. The rule further requires that the URL's destination domain has a Whois age of less than 100 days. This pattern is characteristic of personalized redirect links used in spearheaded or credential phishing campaigns to evade generic URL filtering and direct targets to newly registered infrastructure. The detection logic inspects the current thread’s links, matches the href_url.url against the recipient's email, checks for a non-empty decoded url query parameter, then parses the URL to find the recipient’s email and resolves the domain’s Whois age. If all conditions are met, the rule flags potential open redirect abuse and social-engineering risk. Attack types: Credential Phishing. Tactics: Open Redirect, Social Engineering. Detection methods: URL analysis, Whois.
Categories
  • Endpoint
  • Network
Data Sources
  • Application Log
  • Network Traffic
  • Domain Name
Created: 2026-07-26