Following the funnel
The URL that gets reported is usually the lure, not the trap. It wears a brand, asks for nothing, and sends every click to a second address — which is where the password prompt lives. Judged on its own contents, the lure is harmless.
The shape we act on
A follow is not attempted because a page links somewhere else; nearly every page does. It is attempted when the page has all of the following at once:
- it presents itself as a brand — in its title, its text, or the host name it sits on;
- it shows that brand's own imagery, loaded from the brand's own asset hosts, so the resemblance is not a coincidence of words;
- not one of its links goes back to the brand it claims to be;
- not one of its links goes anywhere on its own site;
- and its entire clickable surface resolves to a single unrelated address.
That combination describes a funnel: a page whose only purpose is to move the visitor somewhere else while looking like somebody trustworthy. When we see it, we open that address in a fresh browser context and examine it the same way we examine any page — including pressing the control it offers.
A worked example
A page on a public code-hosting domain reproduced a document-signature notification: the brand in the title, the brand's own images hotlinked from the brand's CDN, and nine links, none of which went to the brand. All nine resolved to the same unrelated address.
Followed, that address served a gate that had to be held rather than clicked. Behind it, the page did not navigate anywhere — it built its next screen in memory and moved to that, a sign-in clone asking for a password at an address no one can inspect or report.
The scan ends Malicious with a reason that names the mechanism and the host to act on, and an analyst card of its own titled "Every link leads to a credential screen". At the time of that scan, the third-party reputation sources consulted on the same submission returned Clean.
How the evidence is recorded
Everything learned at the followed address is stored as a statement about that address, on the record of the page you submitted. It is never written into the fields that describe what the submitted page did. A carrier that funnels to a credential screen and a page that is a credential screen are different findings, and the record keeps them distinguishable.
Refusals are recorded too, by name — a page that links back to the brand it names, or that claims no brand at all, produces a stated reason for not following rather than silence.
Limits worth knowing
- One hop. We follow a single address, once. A chain that needs three moves is out of reach today.
- The follow is an observation, not a verdict. Opening an address does not convict the page that pointed at it; a verdict needs what was actually found there.
- An interstitial changes what we can see. If the submitted URL is sitting behind an anti-bot challenge, the links we can read belong to that challenge page rather than to the site, and a follow may end up examining ordinary infrastructure. It costs a discarded page load and produces no finding.
- Short-lived by nature. These addresses are usually gone within days. A verdict describes what was serving at scan time, which is the point of recording it.