Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a malicious link?

A malicious link is a URL used to support harmful or unauthorised activity.

It may lead to a fake login page, malware download, redirect chain, tracking page or an exploit attempt.

The important thing for an investigator is to separate the link itself from what actually happened after it was requested.

Preserve the exact route

Keep:

  • displayed link text;
  • full underlying URL;
  • source message/page;
  • receipt time;
  • any security rewriting;
  • redirect chain;
  • final destination;
  • related domains and certificates where relevant.

A visible link may say:

northmere-payroll.example

while actually pointing somewhere completely different.

Security products may alter the first URL you see

Email gateways sometimes rewrite links for scanning or click protection.

Security scanners may also request the URL automatically.

So the first network request may belong to a security system rather than the victim.

That is why browser, process and device evidence matter.

A URL request is not the consequence

A browser can request a link and then:

  • be blocked;
  • receive an error;
  • redirect elsewhere;
  • load a fake page;
  • download a file;
  • trigger an exploit attempt;
  • do nothing harmful.
SourceEmail or messageWhere the link was supplied.
RequestBrowser/process accesses URLWho or what made the request?
RouteRedirects and final destinationWhere did traffic actually go?
OutcomePage, download, submission or blockSeparate evidence shows consequence.

Analyse safely

Do not casually browse a live suspicious URL from an ordinary workstation.

Use the appropriate safe analysis environment or specialist process.

The practical point is: preserve the full link path and work out who or what requested it. Then prove the resulting page load, download, submission or compromise separately.

Reference: CIM-034Cyber Incidents & Offender Methods