Performing automated detection of phishing web sites using embedded tracking element
In some implementations, a method performed by data processing apparatuses includes serving a web page comprising an embedded markup image and a detection script. The detection script is configured to cause a client device to, in response to loading the embedded markup image, determine a current environment location indicative of a source of the web page, determine whether the current environment location matches a domain associated with a subject system, generate an obfuscated data payload based on the current environment location, and send a request to a predetermined endpoint in response to determining that the current environment location does not match the domain associated with the subject system. The request includes the obfuscated data payload.
1 . A computer-implemented method for detecting potential phishing attempts, the method comprising:
serving, by a subject system, a web page comprising (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:
load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;
decode the contents of the obfuscated data attribute to recover a detection script; and
execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:
determining a current environment location indicative of a source of the web page;
determining whether the current environment location matches a domain associated with the subject system; and
in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.
2 . The method of claim 1 , wherein the embedded markup image comprises a scalable vector graphics image.
3 . The method of claim 1 , wherein the obfuscated data attribute represents a plurality of numeric values, and wherein to decode the obfuscated data attribute comprises to convert the plurality of numeric values represented by the obfuscated data attribute into a plurality of characters indicative of the detection script.
4 . The method of claim 3 , wherein to convert the plurality of numeric values comprises to convert the numeric values with an American Standard Code for Information Interchange (ASCII) encoding.
5 . The method of claim 1 , wherein the current environment location comprises a window location uniform resource locator (URL), and wherein determining whether the current environment location matches the domain associated with the subject system comprises determining whether the window location URL matches a top-level domain associated with the subject system.
6 . The method of claim 1 , wherein generating the obfuscated data payload comprises generating a base64-encoded string indicative of the current environment location.
7 . The method of claim 1 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.
8 . The method of claim 7 , wherein the predetermined endpoint comprises an obfuscated website address.
9 . The method of claim 1 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.
10 . The method of claim 1 , further comprising:
receiving, by the predetermined endpoint, the at least one request from the client device;
decoding, by the predetermined endpoint, the obfuscated data payload of the at least one request to recover the current environment location; and
adding, by the predetermined endpoint, the current environment location to a database of potential phishing sources.
11 . The computer-implemented method of claim 1 , wherein the detection script is configured to cause the client device to perform operations further comprising:
dividing the obfuscated data payload into multiple segments; and
including each segment of the multiple segments with a respective request, along with a unique identifier and a sequential counter.
12 . The computer-implemented method of claim 1 , wherein the embedded markup image renders as a visual element of the website.
13 . The computer-implemented method of claim 1 , wherein the embedded markup image renders as an invisible element of the website.
14 . A computer system comprising:
one or more data processing apparatuses including one or more processors, memory, and storage devices storing instructions that, when executed, cause the one or more processors to perform operations comprising:
serving a web page comprising an (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:
load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;
decode the contents of the obfuscated data attribute to recover a detection script; and
execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:
determining a current environment location indicative of a source of the web page;
determining whether the current environment location matches a domain associated with the subject system; and
in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.
15 . The computer system of claim 14 , wherein the current environment location comprises a window location uniform resource locator (URL), and wherein determining whether the current environment location matches the domain associated with the computer system comprises determining whether the window location URL matches a top-level domain associated with the computer system.
16 . The computer system of claim 14 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.
17 . The computer system of claim 14 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.
18 . A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
serving a web page comprising (i) an embedded markup image that shares a naming convention with other embedded markup images in the web page, and that is referenced in code of the web page in proximity to the other embedded markup images, and (ii) a first script, wherein the first script is configured to cause a client device to, in response to loading the embedded markup image:
load an obfuscated data attribute, wherein the obfuscated data attribute is stored as an Extensible Markup Language (XML)/Hypertext Markup Language (HTML) attribute of the embedded markup image, and wherein at least one of (i) a name of the obfuscated data attribute or (ii) metadata associated with the obfuscated data attribute is related to a visual presentation element of the webpage;
decode the contents of the obfuscated data attribute to recover a detection script; and
execute the detection script that has been recovered by decoding the contents of the data attribute, wherein the detection script is configured to cause the client device to perform operations comprising:
determining a current environment location indicative of a source of the web page;
determining whether the current environment location matches a domain associated with the subject system; and
in response to determining that the current environment location does not match the domain associated with the subject system, (i) generating an obfuscated data payload that specifies the current environment location, and (ii) sending, to a predetermined endpoint, at least one request that comprises the obfuscated data payload.
19 . The non-transitory computer-readable storage medium of claim 18 , wherein sending the at least one request to the predetermined endpoint comprises sending a hypertext transfer protocol request that comprises the obfuscated data payload to the predetermined endpoint.
20 . The non-transitory computer-readable storage medium of claim 18 , wherein sending the at least one request comprises sending one or more Domain Name System (DNS) requests to the predetermined endpoint, wherein the one or more DNS requests comprises the obfuscated data payload.