heroui logo

Link: Observed malicious URL path /redirect/redirect/

Sublime Rules

View Source
Summary
High-severity inbound rule detecting messages containing links where the href URL path includes the nested segment '/redirect/redirect/'. The pattern is used to bypass link scanners by chaining redirects and steering users to malicious landing pages. Lures include fake academic transcript notices, internal administrative notices, and generic invitations issued from compromised or unrelated legitimate domains. The rule targets credential phishing campaigns that rely on social engineering and evasion through open redirects. Detection relies on URL/path analysis and content analysis of the inbound message to identify the specific redirect pattern and associated malicious landing pages. The rule is categorized under open redirect, social engineering, and evasion, with detection methods that combine URL analysis and content analysis to flag suspicious inbound links.
Categories
  • Web
  • Network
Data Sources
  • Network Traffic
Created: 2026-08-13