• Sublime Core Feed
High Severity

Link: URL fragment with hexadecimal pattern obfuscation

Description

Detects links containing URL fragments with repeating hexadecimal patterns, commonly used to obfuscate malicious destinations or bypass security filters.

References

No references.

Sublime Security
Created Jan 29th, 2026 • Last updated Jan 29th, 2026
Source
type.inbound
and any(body.links,
        regex.contains(.href_url.fragment, '.html\/\?(?:[a-f0-9]{2}\.){12,}')
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started