Disclaimer: This is a user generated content submitted by a member of the WriteUpCafe Community. The views and writings here reflect that of the author and not of WriteUpCafe. If you have any complaints regarding this post kindly report it to us.

For staging a phishing website, cybercriminals can choose between using legitimate yet compromised domain names, registering their own domains, and misusing free web hosting services. The key to detect and mitigate these cybersecurity threats at the earliest possible time is to understand how prevalent each of these scenarios is.

IT service company PhishLabs analyzed over a hundred thousand phishing websites to determine how many of those utilized compromised domains, domain names registered with malicious intent, or free website hosting solutions. Around 38% of the websites misused free hosting or utilized compromised domains, whereas about one-quarter of them used domain names registered with the intent to cause harm.

It is potentially tricky to determine whether one of these sites utilizes a compromised or malicious domain at a level that is enough to correctly represent the modern phishing landscape. Research regarding phishing has mainly used the following elements.

  • Whether the content in the domain name tries to pretend to be a legitimate website in some way.
  • The amount of time elapsed between domain name registration and its use. The shorter that timeframe was, the chance for the website to get maliciously registered would be more.

An advantage of utilizing the latter element is that cybercriminals can do so retroactively, albeit the phishing website is taken down. It can also be applied efficiently to a big dataset of domains associated with phishing. On the downside, it assumes that the malicious actor would register a website in the event that it was utilized for phishing in a definite period. Conservative pieces of research have used some days as a timeframe, whereas others have utilized many months. That said, the survival period of vulnerable web infrastructure is measured as per minutes instead of days or even months. That method would result in the inaccurate labeling of phishing websites as being maliciously registered sites.

Free Website Hosting Abuse

The best web hosting providers often say that nothing is ever free as a criticism of so-called free versions of these services. That is to say, there are hidden charges associated with the free services. These service providers, developer tools, dynamic DNS solutions, code and file sharing websites, and other solutions enable easy web content hosting without users having to buy domain names. The above-mentioned services tend to be misused to perform phishing attacks.

When it comes to free web hosting misuse, the whole domain name is no malicious product. The malicious product is a part of the domain string apart from the second-level domain and the one that follows the dot symbol.

These websites are based on legitimate domain names, so the requirements regarding threat intelligence and mitigation are different from the requirements where hackers register their domains.

Login

Welcome to WriteUpCafe Community

Join our community to engage with fellow bloggers and increase the visibility of your blog.
Join WriteUpCafe