Searching for phishing infrastructure at the preparation stage

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Searching for Phishing Infrastructure at the Preparation Stage 🧱
In protecting an organization from phishing threats, it is useful not to limit yourself to simply blocking already sent emails and URLs. It is necessary to apply threat detection techniques at the preparation stage. While an attacker is registering a domain or issuing an SSL certificate, we can try to identify and neutralize them without waiting for the first victim.
Below, we will review some tools and tactics for proactive phishing defense.
Domain Monitoring 💻
The first thing an attacker does is register a domain. When spoofing a legitimate service, you can expect the registered domain to be visually similar to the spoofed domain. This is classic cybersquatting.
We can set up monitoring and respond to the registration of domains that are similar to the services and brands we care about. It is important to remember that domain owners themselves may also register such domains, so it is necessary to additionally check the domain registrants and compare them with the original to avoid false positives.
SSL Certificate Analysis 🤔
A low number of clicks on links without a valid SSL certificate forces attackers to bother with issuing one. Most major, well-known certificate authorities maintain open logging of all issued SSL certificates, and the resulting list of protected objects can be used for analysis. The analysis methodology can be the same as for domains obtained through monitoring. It is worth noting that the very fact of issuing an SSL certificate for a suspicious domain can be considered a sign of a phishing attack planned for the near future.
Checking Hostnames on a Domain 😐
Situations often occur where an attacker’s greedy hands reach for a large number of brands simultaneously. To do this, they register a single domain and a single wildcard certificate, and this domain is visually dissimilar to anything. To separate the spoofed brands, the attacker uses higher-level domains, for example <brand>.domain.xyz. The presence of such subdomains on a newly registered domain can be an indicator of readiness to conduct a phishing attack.
Obtaining the complete composition of a domain zone from a DNS server is practically impossible and will not yield results with a large stream of domain names. Here, you will need to use intelligence data collected from external sources or TI portals, or try to brute-force various subdomains yourself to check for their existence.
Registrant Connections 🕊
Analysis of domain owner data can reveal a network of related resources registered by the same organization for a series of attacks. The linking indicator could be the registrant’s name (if not hidden by privacy settings) or their contact information: email or phone. As knowledge gained through proactive phishing domain hunting accumulates, we can compile a list of malicious registrants and use it to react to new domain registrations. Of course, expecting an attacker to repeatedly publish phishing domains under the same name (not hidden by privacy settings) is extremely optimistic, but this verification tool should not be excluded from the arsenal.
🏗In conclusion, upon discovering a phishing platform “under construction,” we can:
• add the detected network indicators to internal lists in information security tools;
• warn the organization’s employees or the service’s users;
• if phishing content or an email campaign has been published, forward this information to the registrar and hosting provider to conduct a takedown and reduce the attack’s effectiveness.
#TI #tip #phishing
@ptesacaltor
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



