Dating Phish: An Analysis of the Life Cycles of Phishing Attacks and Campaigns

Vincent Drury, Luisa Lux, Ulrike Meyer · Proceedings of the 17th International Conference on Availability, Reliability and Security · 2022

Phishing attacks are still a general and world-wide threat to users of the Internet. In the past, several approaches to detect phishing websites earlier and shorten the time frame between their creation and inclusion in a blocklist have been proposed. Understanding the life cycle of phishing attacks, in particular the time of their creation and the time span from the first to last attack in a campaign, provides additional insights into the potential success of these methods. In this paper, we present an analysis of the life cycles of 133,667 phishing websites based on the publicly available information from certificates, whois, as well as images and resources on the phishing websites themselves. While we confirm the findings from previous work, that many websites have short lifetimes of only several days, we also note that the timing information from phishing websites using public hosting or compromised infrastructure is far less accurate in dating the creation of the websites. We further cluster the phishing websites into campaigns based on patterns in their domain names, and find that the detected campaigns often take place over several weeks, with an average duration of almost 12 days. Our results showcase advantages and limitations for the early detection of phishing websites, in particular regarding the time span between the creation of a website and its inclusion in a blocklist, and how patterns in domain names remain the same over a period of up to several weeks in the phishing campaigns analyzed in this paper.

Read the paper · More papers on PaperTik