Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
ClickFunnels link infrastructure abuse
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Attachment: EML file with IPFS links
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
Link: File sharing impersonation with suspicious language and sending patterns
12d ago
Oct 31st, 2025
Sublime Security
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Credential phishing: Onedrive impersonation
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92
Brand impersonation: Coinbase with suspicious links
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Zoom Events newsletter abuse
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Link: Free file hosting with undisclosed recipients
2mo ago
Sep 11th, 2025
Sublime Security
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Brand impersonation: Fake Fax
2mo ago
Aug 14th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Deceptive Dropbox mention
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Attachment: HTML smuggling Microsoft sign in
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Link: Multistage landing - Abused Docusign
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645
Link: Free subdomain host with undisclosed recipients
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-free-subdomain-host-with-undisclosed-recipients-c23d979d
Vendor compromise: GovDelivery message with suspicious link
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172
Link: Webflow link from unsolicited sender
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Message traversed multiple onmicrosoft.com tenants
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Link: Credential phishing via WordPress
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-credential-phishing-via-wordpress-db696058
Link: Jensi file preview link from unsolicited sender
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Link: Abused Adobe Express
3mo ago
Jul 23rd, 2025
Sublime Security
/feeds/core/detection-rules/link-abused-adobe-express-c7d17bfd
Spoofable internal domain with suspicious signals
3mo ago
Jul 23rd, 2025
Sublime Security
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Low reputation link to auto-downloaded HTML file with smuggling indicators
3mo ago
Jul 23rd, 2025
Sublime Security
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6