For staging a phishing website, cybercriminals can choose between using
legitimate yet compromised domain names, registering their own domains, and misusing
free web hosting services.
The key to detect and mitigate these cybersecurity threats at the earliest
possible time is to understand how prevalent each of these scenarios is.
IT service company PhishLabs analyzed
over a hundred thousand phishing websites to determine how many of those utilized
compromised domains, domain names registered with malicious intent, or free
website hosting solutions. Around 38% of the websites misused free hosting or utilized
compromised domains, whereas about one-quarter of them used domain names
registered with the intent to cause harm.
It is potentially tricky to determine whether one of these sites
utilizes a compromised or malicious domain at a level that is enough to
correctly represent the modern phishing landscape. Research regarding phishing
has mainly used the following elements.
- Whether the content in the domain name tries to pretend
to be a legitimate website in some way.
- The amount of time elapsed between domain name
registration and its use. The shorter that timeframe was, the chance for
the website to get maliciously registered would be more.
An advantage of utilizing the latter element is that cybercriminals can do
so retroactively, albeit the phishing website is taken down. It can also be
applied efficiently to a big dataset of domains associated with phishing. On
the downside, it assumes that the malicious actor would register a website in
the event that it was utilized for phishing in a definite period. Conservative
pieces of research have used some days as a timeframe, whereas others have
utilized many months. That said, the survival period of vulnerable web
infrastructure is measured as per minutes instead of days or even months. That
method would result in the inaccurate labeling of phishing websites as being
maliciously registered sites.
Free Website Hosting Abuse
The best web hosting
providers often say that nothing is ever free as a criticism of so-called free
versions of these services. That is to say, there are hidden charges associated
with the free services. These service providers, developer tools, dynamic DNS
solutions, code and file sharing websites, and other solutions enable easy web
content hosting without users having to buy domain names. The above-mentioned
services tend to be misused to perform phishing attacks.
When it comes to free web hosting misuse, the whole domain name is no
malicious product. The malicious product is a part of the domain string apart
from the second-level domain and the one that follows the dot symbol.
These websites are based on legitimate domain names, so the requirements
regarding threat intelligence and mitigation are different from the requirements
where hackers register their domains.
Comments
Post a Comment