IP Library › Granted Patent US 12,641,118
Granted Patent B2
US 12,641,118 · App. 18/425,212 · Granted May 26, 2026

Performing automated detection of phishing web sites using embedded tracking element

Inventors: Eric Robert Brandel (Minnetonka, MN); Daniel Christopher J. Flettre (St. Paul, MN)
Assignee: Target Brands, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,118
App. No.
18/425,212
Granted
May 26, 2026
Kind
B2
Abstract

In some implementations, a method performed by data processing apparatuses includes serving a web page comprising an embedded markup image and a detection script. The detection script is configured to cause a client device to, in response to loading the embedded markup image, determine a current environment location indicative of a source of the web page, determine whether the current environment location matches a domain associated with a subject system, generate an obfuscated data payload based on the current environment location, and send a request to a predetermined endpoint in response to determining that the current environment location does not match the domain associated with the subject system. The request includes the obfuscated data payload.

Claims (47)

1 . A computer-implemented method for detecting potential phishing attempts, the method comprising:

serving, by a subject system, a web page comprising (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:

load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;

decode the contents of the obfuscated data attribute to recover a detection script; and

execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:

determining a current environment location indicative of a source of the web page;

determining whether the current environment location matches a domain associated with the subject system; and

in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.

2 . The method of claim 1 , wherein the embedded markup image comprises a scalable vector graphics image.

3 . The method of claim 1 , wherein the obfuscated data attribute represents a plurality of numeric values, and wherein to decode the obfuscated data attribute comprises to convert the plurality of numeric values represented by the obfuscated data attribute into a plurality of characters indicative of the detection script.

4 . The method of claim 3 , wherein to convert the plurality of numeric values comprises to convert the numeric values with an American Standard Code for Information Interchange (ASCII) encoding.

5 . The method of claim 1 , wherein the current environment location comprises a window location uniform resource locator (URL), and wherein determining whether the current environment location matches the domain associated with the subject system comprises determining whether the window location URL matches a top-level domain associated with the subject system.

6 . The method of claim 1 , wherein generating the obfuscated data payload comprises generating a base64-encoded string indicative of the current environment location.

7 . The method of claim 1 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.

8 . The method of claim 7 , wherein the predetermined endpoint comprises an obfuscated website address.

9 . The method of claim 1 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.

10 . The method of claim 1 , further comprising:

receiving, by the predetermined endpoint, the at least one request from the client device;

decoding, by the predetermined endpoint, the obfuscated data payload of the at least one request to recover the current environment location; and

adding, by the predetermined endpoint, the current environment location to a database of potential phishing sources.

11 . The computer-implemented method of claim 1 , wherein the detection script is configured to cause the client device to perform operations further comprising:

dividing the obfuscated data payload into multiple segments; and

including each segment of the multiple segments with a respective request, along with a unique identifier and a sequential counter.

12 . The computer-implemented method of claim 1 , wherein the embedded markup image renders as a visual element of the website.

13 . The computer-implemented method of claim 1 , wherein the embedded markup image renders as an invisible element of the website.

14 . A computer system comprising:

one or more data processing apparatuses including one or more processors, memory, and storage devices storing instructions that, when executed, cause the one or more processors to perform operations comprising:

serving a web page comprising an (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:

load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;

decode the contents of the obfuscated data attribute to recover a detection script; and

execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:

determining a current environment location indicative of a source of the web page;

determining whether the current environment location matches a domain associated with the subject system; and

in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.

15 . The computer system of claim 14 , wherein the current environment location comprises a window location uniform resource locator (URL), and wherein determining whether the current environment location matches the domain associated with the computer system comprises determining whether the window location URL matches a top-level domain associated with the computer system.

16 . The computer system of claim 14 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.

17 . The computer system of claim 14 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.

18 . A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

serving a web page comprising (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:

load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;

decode the contents of the obfuscated data attribute to recover a detection script; and

execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:

determining a current environment location indicative of a source of the web page;

determining whether the current environment location matches a domain associated with the subject system; and

in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.

20 . The non-transitory computer-readable storage medium of claim 18 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2026
From: BRANDEL, ERIC ROBERT; FLETTRE, DANIEL CHRISTOPHER JAY
To: TARGET BRANDS, INC.
Reel/Frame 074413/0410 →
Continuity (1)
Related Publication 20250247423A1 · Jul 31, 2025
References Cited (53)
US 6401118B1 · Thomas · 2002 [cited by applicant]
US 8291065B2 · Goodman · 2012 [cited by examiner]
US 8381292B1 · Warner et al. · 2013 [cited by applicant]
US 8695091B2 · Komili · 2014 [cited by examiner]
US 8839418B2 · Hulten et al. · 2014 [cited by applicant]
US 9065850B1 · Sobrier · 2015 [cited by examiner]
US 9111090B2 · Klein · 2015 [cited by examiner]
US 9411785B1 · Wong · 2016 [cited by examiner]
US 10511628B1 · Richards · 2019 [cited by examiner]
US 11109197B2 · Lamb · 2021 [cited by examiner]
US 11356481B1 · Singh · 2022 [cited by examiner]
US 11444978B1 · Liao · 2022 [cited by examiner]
US 11470114B2 · Pratt · 2022 [cited by examiner]
US 11561988B2 · Jenkins · 2023 [cited by applicant]
US 12021894B2 · Clausen · 2024 [cited by examiner]
US 12231464B2 · Azarafrooz · 2025 [cited by examiner]
US 12294611B2 · Maha · 2025 [cited by examiner]
US 20040202327A1 · Little · 2004 [cited by examiner]
US 20070039038A1 · Goodman · 2007 [cited by examiner]
US 20080040503A1 · Kleks · 2008 [cited by examiner]
US 20080092242A1 · Rowley · 2008 [cited by examiner]
US 20080244715A1 · Pedone · 2008 [cited by examiner]
US 20100205297A1 · Sarathy · 2010 [cited by examiner]
US 20100325107A1 · Kenton et al. · 2010 [cited by applicant]
US 20110196864A1 · Mason · 2011 [cited by examiner]
US 20130263264A1 · Klein · 2013 [cited by examiner]
US 20140172495A1 · Schneck et al. · 2014 [cited by applicant]
US 20140358888A1 · Whitelaw et al. · 2014 [cited by applicant]
US 20160055490A1 · Keren et al. · 2016 [cited by applicant]
US 20160253679A1 · Venkataraman et al. · 2016 [cited by applicant]
US 20160352805A1 · Seida · 2016 [cited by applicant]
US 20180338283A1 · Karsi · 2018 [cited by examiner]
US 20190268373A1 · Celik · 2019 [cited by examiner]
US 20200286015A1 · Richards · 2020 [cited by examiner]
US 20200287934A1 · Richards · 2020 [cited by examiner]
US 20210117544A1 · Kurtz · 2021 [cited by examiner]
US 20210203691A1 · Pratt · 2021 [cited by examiner]
US 20210203693A1 · Clausen · 2021 [cited by examiner]
US 20220188699A1 · Matlick · 2022 [cited by examiner]
US 20230065787A1 · Akhter · 2023 [cited by examiner]
US 20230231879A1 · Li · 2023 [cited by examiner]
US 20230247050A1 · Seletskiy · 2023 [cited by examiner]
US 20230262078A1 · Rozhnov · 2023 [cited by examiner]
US 20240114053A1 · Katz · 2024 [cited by examiner]
US 20240193282A1 · Townsend · 2024 [cited by examiner]
US 20240205194A1 · Low · 2024 [cited by examiner]
US 20240314152A1 · Mistry · 2024 [cited by examiner]
US 20240388443A1 · Zemla · 2024 [cited by examiner]
US 20250168087A1 · Mauhourat · 2025 [cited by examiner]
US 20250247423A1 · Brandel · 2025 [cited by examiner]
WO WO2025115017A1 · 2025 [cited by examiner]
Sergei Bachinin, What is base64 Encoding andWhy is it Necessary?, Nov. 28, 2023, https://www.freecodecamp.org/news/what-is-base64-encoding/ (Year: 2023). [cited by examiner]
Gamal et al., convert String to ASCII and ASCII to String, Apr. 22, 2015, https://stackoverflow.com/questions/29809923/convert-string-to-ascii-and-ascii-to-string (Year: 2015). [cited by examiner]