logo

Broken Phishing URLs, (Thu, Feb 5th)

ID: 8bf79da9-2f26-5dbc-8a88-a74dd792e6d4

STIX ID: report--8bf79da9-2f26-5dbc-8a88-a74dd792e6d4

Feed Name: SANS ISC Diary

Threat Score
30/100

Date Published: 2026-02-05

Date Updated: 2026-04-19

...
...

The author reports a resurgence of phishing emails that use intentionally malformed URL query parameters (examples include worker.dev and netlify.app links with broken parameter fragments) to evade detection and break IOC extraction or URL normalization; browsers still follow the links, enabling the malicious site visit while many security controls and regex-based pipelines may miss these IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.