What is a malicious link?¶
A malicious link is a URL used to support harmful or unauthorised activity.
It may lead to a fake login page, malware download, redirect chain, tracking page or an exploit attempt.
The important thing for an investigator is to separate the link itself from what actually happened after it was requested.
Preserve the exact route¶
Keep:
- displayed link text;
- full underlying URL;
- source message/page;
- receipt time;
- any security rewriting;
- redirect chain;
- final destination;
- related domains and certificates where relevant.
A visible link may say:
northmere-payroll.example
while actually pointing somewhere completely different.
Security products may alter the first URL you see¶
Email gateways sometimes rewrite links for scanning or click protection.
Security scanners may also request the URL automatically.
So the first network request may belong to a security system rather than the victim.
That is why browser, process and device evidence matter.
A URL request is not the consequence¶
A browser can request a link and then:
- be blocked;
- receive an error;
- redirect elsewhere;
- load a fake page;
- download a file;
- trigger an exploit attempt;
- do nothing harmful.
Analyse safely¶
Do not casually browse a live suspicious URL from an ordinary workstation.
Use the appropriate safe analysis environment or specialist process.
The practical point is: preserve the full link path and work out who or what requested it. Then prove the resulting page load, download, submission or compromise separately.