While bug hunting I came across a url that looked something like http://click.example.com/track?mktoTestLink
that rendered a blank page HTML page with just the word Hello
in the body. It appeared to be a tracking link where mktoTestLink
would be replaced with the base64 encoded redirect url.
A cursory Google search showed only a few similar links and a handful of results for analyzed malware which contained similar links. Eventually, directory discovery with gobuster revealed a 404.html
page on the subdomain. The page revealed nothing new except for an svg graphic of a bird. This bird graphic was hosted on another site which was traced back to Marketo, an Adobe owned marketing company.