Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Credential harvesting with excess padding evasion
2d ago
Aug 25th, 2026
Sublime Security
Link: Credential phishing link with undisclosed recipients
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
9d ago
Aug 18th, 2026
Sublime Security
Credential phishing content and link (untrusted sender)
21d ago
Aug 6th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: QR code with credential phishing indicators
1mo ago
Jul 27th, 2026
Sublime Security
Link: Multistage landing - Trello board abuse
1mo ago
Jul 16th, 2026
Sublime Security
Credential phishing link (unknown sender)
2mo ago
Jun 5th, 2026
Sublime Security
Brand impersonation: Figma with malicious document access overlay
3mo ago
May 27th, 2026
Sublime Security
Link: Microsoft device code authentication with suspicious indicators
5mo ago
Mar 12th, 2026
Sublime Security
Link: Unsolicited email contains link to page containing Tycoon URI structure
5mo ago
Mar 10th, 2026
Sublime Security
Link: Figma design deck with credential theft language
5mo ago
Mar 4th, 2026
Sublime Security
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
6mo ago
Feb 13th, 2026
Sublime Security
Link: Microsoft Dynamics 365 form phishing
7mo ago
Jan 27th, 2026
Sublime Security
Link to auto-downloaded file with Google Drive branding
7mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling - QR Code with suspicious links
7mo ago
Jan 12th, 2026
Sublime Security
Issuu document with suspicious embedded link
7mo ago
Jan 12th, 2026
Sublime Security
Link: Adobe share with suspicious indicators
7mo ago
Jan 12th, 2026
Sublime Security
Google Accelerated Mobile Pages (AMP) abuse
7mo ago
Jan 12th, 2026
Sublime Security
Link: Multistage landing - Scribd document
7mo ago
Jan 12th, 2026
Sublime Security