• URL screenshot

Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing content and link (untrusted sender)
2d ago
Jun 16th, 2025 UTC
Sublime Security
Credential Phishing
Social engineering
Computer Vision
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
14d ago
Jun 4th, 2025 UTC
Sublime Security
Credential Phishing
Impersonation: Brand
Social engineering
Computer Vision
Content analysis
Header analysis
Natural Language Understanding
Optical Character Recognition
Sender analysis
URL screenshot
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Link: Multistage Landing - Scribd Document
1mo ago
May 16th, 2025 UTC
Sublime Security
Credential Phishing
Evasion
Social engineering
Impersonation: Brand
Free file host
URL analysis
HTML analysis
Natural Language Understanding
Computer Vision
Optical Character Recognition
URL screenshot
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage Landing - Ludus Presentation
1mo ago
May 14th, 2025 UTC
Sublime Security
Credential Phishing
Evasion
Social engineering
Impersonation: Brand
Header analysis
URL analysis
Computer Vision
URL screenshot
Natural Language Understanding
Optical Character Recognition
Sender analysis
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Figma Design Deck With Credential Phishing Language
1mo ago
May 7th, 2025 UTC
Sublime Security
Credential Phishing
Evasion
Free file host
Social engineering
Natural Language Understanding
Computer Vision
Optical Character Recognition
URL analysis
URL screenshot
Sender analysis
/feeds/core/detection-rules/link-figma-design-deck-with-credential-phishing-language-87601924
Issuu Document With Suspicious Embedded Link
1mo ago
May 5th, 2025 UTC
Sublime Security
Credential Phishing
Social engineering
Free file host
Evasion
URL analysis
URL screenshot
Natural Language Understanding
Optical Character Recognition
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Credential phishing link (unknown sender)
1mo ago
Apr 30th, 2025 UTC
Sublime Security
Credential Phishing
Social engineering
Computer Vision
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b
Attachment: QR code with credential phishing indicators
2mo ago
Apr 14th, 2025 UTC
Sublime Security
Credential Phishing
QR code
Social engineering
Computer Vision
Header analysis
Natural Language Understanding
QR code analysis
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Free subdomain link with credential theft indicators
6mo ago
Dec 12th, 2024 UTC
Sublime Security
Credential Phishing
Free subdomain host
Content analysis
Header analysis
Natural Language Understanding
Optical Character Recognition
URL analysis
URL screenshot
/feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c
Link: Adobe Share with Suspicious Indicators
6mo ago
Dec 3rd, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Free file host
Content analysis
URL screenshot
Sender analysis
Natural Language Understanding
URL analysis
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Link: Microsoft Dynamics 365 form phishing
7mo ago
Nov 14th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Content analysis
File analysis
Optical Character Recognition
Natural Language Understanding
URL analysis
URL screenshot
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Attachment: EML with link to credential phishing page
9mo ago
Sep 13th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Free file host
Free subdomain host
Social engineering
Computer Vision
Content analysis
File analysis
Header analysis
HTML analysis
Natural Language Understanding
Optical Character Recognition
URL analysis
URL screenshot
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Suspicious Recipients pattern with no Compauth pass and suspicious content
9mo ago
Aug 27th, 2024 UTC
Sublime Security
Content analysis
Computer Vision
Header analysis
Natural Language Understanding
URL analysis
URL screenshot
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6
Google Drive abuse: Credential phishing link
10mo ago
Jul 31st, 2024 UTC
Sublime Security
Credential Phishing
Free file host
Impersonation: Brand
Computer Vision
Natural Language Understanding
Optical Character Recognition
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/google-drive-abuse-credential-phishing-link-c74aece0
Suspicious recipient pattern and language with low reputation link to login
1y ago
Apr 30th, 2024 UTC
Sublime Security
Credential Phishing
Social engineering
Computer Vision
Content analysis
Header analysis
Natural Language Understanding
Optical Character Recognition
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402
Google Accelerated Mobile Pages (AMP) abuse
1y ago
Apr 25th, 2024 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Impersonation: Brand
Open redirect
Computer Vision
Content analysis
Natural Language Understanding
Optical Character Recognition
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Link: Credential Phishing link with Undisclosed Recipients
1y ago
Apr 25th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Computer Vision
Header analysis
URL screenshot
/feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e
Link to auto-downloaded file with Google Drive branding
1y ago
Apr 25th, 2024 UTC
Sublime Security
Malware/Ransomware
Impersonation: Brand
Social engineering
Content analysis
File analysis
Optical Character Recognition
URL analysis
URL screenshot
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Free subdomain link with login or captcha (untrusted sender)
1y ago
Apr 25th, 2024 UTC
Sublime Security
Credential Phishing
Free subdomain host
Social engineering
Computer Vision
File analysis
Sender analysis
URL screenshot
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Attachment: HTML smuggling - QR Code with suspicious links
1y ago
Apr 25th, 2024 UTC
Sublime Security
Credential Phishing
QR code
Computer Vision
Header analysis
Natural Language Understanding
QR code analysis
Sender analysis
URL analysis
URL screenshot
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d