• On MovieTome: TRANSFORMERS 2 SPOILERS!

December 3, 2007 7:49 AM PST

Shorter URLs help phishers hook more victims

Phishers are using shorter URLs for malicious sites in a bid to lend an air of legitimacy to threatening links.

Internet Security Services, IBM's online-security division, claims to have noticed a significant drop in the number of characters used by fraudsters in their phishing URLs.

A post on ISS's Frequency X blog stated that "analysts have been observing host names within fraudulent phishing URLs consistently arrive with lengths of between 30 and 37 characters"; observers "have noted a significant change" as phishing host names have shrunk down to an average of only 17 characters in recent weeks.

Ralf Iffert, researcher for ISS's X-Force threat analysis team and author of the Frequency X blog, believes this is another step in the increasingly sophisticated social-engineering measures adopted by cybercriminals.

Phishers "appear to have adopted shorter URLs to avoid the suspicion of their potential victims," he said.

Steve Reddock, senior IT specialist for ISS, believes that this is a developing trend. "This is a pattern we've noticed over several months; it's not just a blip."

Reddock said phishers often experiment with new techniques, but only for very short periods of time. However, in this case, the tactic of using shortened URLs as a means of deception has been around long enough to be considered a best practice for cybercriminals.

"It has to be making money for them. These groups run very efficient businesses," he said.

Paul Ducklin, head of technology for the Asia-Pacific region at security firm Sophos, said users and security firms alike should be wary of making assumptions based on the character length of a URL, be it long or short.

"We need to be careful about security metrics, which might lead users to assume a reliable correlation between the size of an Internet object and its danger...In any case, your e-mail client may disguise the real URL with a link that looks completely different--not just a different length--from what it really is," he said.

ISS' Reddock claims that as users have become more aware of dangerous links, revenues have declined for phishers, thus prompting the need for new approaches.

"The fact that they felt the need to make this move suggests that they were seeing diminishing returns," Reddock said.

Sophos' Paul Ducklin remains skeptical as to whether this new tactic will make a difference--or whether it is something phishers will continue using.

"Size, as they say, generally doesn't matter," Ducklin added.

Marcus Browne of ZDNet Australia reported from Sydney.

See more CNET content tagged:
phishing, Sophos Plc., victim, link, researcher

Add a Comment (Log in or register) 2 comments
Shorter names in recent weeks?
by paulej December 3, 2007 6:40 PM PST
Weeks? If this is the case, does it not suggest that there is actually a very small number of people coordinating these scams?

Or, is there a "phisher central" web site out there where phishers hold a vote to agree on URL lengths? :-)
Reply to this comment
It's been a while ...
by My-Self December 4, 2007 4:05 PM PST
I've seen that for a while.

Example : paypal.com could become paypaI.com or paypa1.com, secure-paypal.com, ssl-paypal.com, etc ... (those are already reserved, only one by ebay, the legitimate owner)
Those kind of addresses are then redirected to the compromised server (regular or with frame).

given the size of the problem for various financial institutions, I wonder why there is no central blacklist that could be used for URI checks in antispam softwares such as spamassassin.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right