
Summary
This detection rule identifies potential phishing attempts leveraging the shoppermeet.net domain through open redirects. The rule analyzes inbound messages for links that redirect to the domain 'link.shoppermeet.net'. It specifically looks for links that contain certain query parameters such as 'propertyid=', 'publisherkey=', and 'url='. Additionally, it ensures that the redirect does not lead back to an original valid domain if it contains the links specified. The rule further scrutinizes the sender's domain, considering it a potential threat if it is not from a high-trust sender domain or if it has failed DMARC authentication. This is particularly significant because open redirects are often exploited in phishing campaigns to bypass security checks and deceive users into revealing sensitive information.
Categories
- Web
- Cloud
- Application
Data Sources
- Web Credential
- Network Traffic
- Logon Session
Created: 2025-03-18