Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Google application integration redirecting to suspicious hosts
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-application-integration-redirecting-to-suspicious-hosts-473d3247
Self-sent fake PDF attachment with misleading link
17d ago
Dec 16th, 2025
Sublime Security
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Deceptive Dropbox mention
18d ago
Dec 15th, 2025
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Link: Tycoon2FA phishing kit (non-exhaustive)
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: Cryptocurrency fraud with suspicious links
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Service abuse: Random Google Firebase sender address with suspicious content
1mo ago
Nov 26th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Brand impersonation: Fake Fax
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Attachment: EML file with IPFS links
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
ClickFunnels link infrastructure abuse
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Link: File sharing impersonation with suspicious language and sending patterns
2mo ago
Oct 31st, 2025
Sublime Security
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Credential phishing: Onedrive impersonation
3mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92
Brand impersonation: Coinbase with suspicious links
3mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Zoom Events newsletter abuse
3mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Link: Free file hosting with undisclosed recipients
3mo ago
Sep 11th, 2025
Sublime Security
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Message traversed multiple onmicrosoft.com tenants
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Attachment: HTML smuggling Microsoft sign in
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Link: Jensi file preview link from unsolicited sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Link: Multistage landing - Abused Docusign
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645
Link: Webflow link from unsolicited sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Link: Credential phishing via WordPress
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-credential-phishing-via-wordpress-db696058