The attacker used an intermediate Google redirector URL (https://google.sm/url?…q=…) which then leads to another URL (https://sepro.com.pe/jamb/) that finally ends up at a malicious fake Microsoft login page.
The initial GET returned HTTP/2 301 with a Location: header pointing the browser at the Google redirector target; following the chain returned a webpage titled “Redirect Notice” and then the phishing site.
Attackers use legitimate redirectors and chained redirects to hide the final malicious domain, bypass filters, and increase click-through trust.
Defend with email auth checks (SPF/DKIM/DMARC), link-unfurling engines, redirect analysis, user education, and rapid incident response when credentials are suspected.


