Broken Phishing URLs, (Thu, Feb 5th)
ID: 8bf79da9-2f26-5dbc-8a88-a74dd792e6d4
STIX ID: report--8bf79da9-2f26-5dbc-8a88-a74dd792e6d4
Feed Name: SANS ISC Diary
Threat Score
The author reports a resurgence of phishing emails that use intentionally malformed URL query parameters (examples include worker.dev and netlify.app links with broken parameter fragments) to evade detection and break IOC extraction or URL normalization; browsers still follow the links, enabling the malicious site visit while many security controls and regex-based pipelines may miss these IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
