Skip to content

Malicious External Link

It refers to outbound links on a webpage that point to malicious or restricted domains. These links are often injected into compromised websites by attackers to distribute malware, redirect users to phishing pages, or establish hidden communication channels with command-and-control (C2) infrastructure.

Also surfaces as:
Restricted External LinkMalicious External Link from Landing PageRestricted External Link from Landing PageMalicious External Link from Landing Page with High ConfidenceRestricted External Link from Landing Page with High Confidence
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Malicious External Link' mean in SOC or web analysis?

It refers to outbound links on a webpage that point to malicious or restricted domains. These links are often injected into compromised websites by attackers to distribute malware, redirect users to phishing pages, or establish hidden communication channels with command-and-control (C2) infrastructure.

Why it matters02

How can a legitimate domain contain malicious external links?

A legitimate website can be compromised without the owner’s knowledge. Attackers may exploit vulnerabilities or inject scripts that add hidden external links in the page’s HTML. These links are often invisible to visitors but lead to malicious destinations, allowing the attacker to abuse the domain’s reputation for further exploitation.

How analysts use it03

What does it mean when malicious links are found on the landing page and marked as high confidence?

When malicious links are located directly on the landing (main) page, it indicates that the compromise affects the most visible and frequently accessed part of the website. Every visitor accessing the page may be exposed to malicious redirects, payloads, or phishing attempts. The 'High Confidence' classification means that this detection has been verified by multiple intelligence sources, sandbox executions, or behavioral correlations, confirming it as an active and validated malicious linkage.

Often paired with:block_domain
Evidence shape

What Malicious External Link looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "malicious_outlink",
  "name": "Malicious External Link",
  "group": "relational_intelligence",
  "subgroup": "web_relational_infra",
  "direction": "malicious",
  "evidence": {
    "inlink_count": 312,
    "malicious_outlink_count": 4,
    "visited_by_malicious_count": 2,
    "backlink_quality": "mixed"
  }
}
See in API reference
Siblings

Peers in Web Relational Infrastructure

2 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Active Association with Malicious Domain

It indicates that the domain was contacted or interacted with by a known malicious domain during the same session or act

MaliciousCore
High Number of Inbound Links

It indicates that the domain receives a large number of backlinks from diverse external sources across the internet. Thi

Safe
In the wild

See Malicious External Link fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Malicious External Link. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.