Sean Mackert professional headshot

Sean Mackert

- Passionate about security
- Aspiring red teamer
- Seeking mentorship

1-Minute Read

While bug hunting I came across a url that looked something like that rendered a blank page HTML page with just the word Hello in the body. It appeared to be a tracking link where mktoTestLink would be replaced with the base64 encoded redirect url.

A cursory Google search showed only a few similar links and a handful of results for analyzed malware which contained similar links. Eventually, directory discovery with gobuster revealed a 404.html page on the subdomain. The page revealed nothing new except for an svg graphic of a bird. This bird graphic was hosted on another site which was traced back to Marketo, an Adobe owned marketing company.

