{"id":5763,"date":"2021-05-21T10:01:06","date_gmt":"2021-05-21T08:01:06","guid":{"rendered":"https:\/\/www.retarus.com\/blog\/en\/phishing-attacks-increasingly-launched-using-newly-registered-domains-shows-retarus%e2%80%99-analysis"},"modified":"2024-05-07T19:18:46","modified_gmt":"2024-05-07T17:18:46","slug":"phishing-attacks-increasingly-launched-using-newly-registered-domains-shows-retarus-analysis","status":"publish","type":"post","link":"https:\/\/www.retarus.com\/blog\/en\/phishing-attacks-increasingly-launched-using-newly-registered-domains-shows-retarus-analysis\/","title":{"rendered":"Phishing Attacks Increasingly Launched using Newly Registered Domains, Shows Retarus\u2019 Analysis"},"content":{"rendered":"\n
Around 80 percent of targeted cyberattacks are carried out by way of attachments or links in emails. This figure has remained relatively constant. The best protection: thoroughly examine each inbound email for criminal contents. When it comes to detecting harmful phishing links, however, a new trend has recently been recognized.<\/p>\n\n\n\n
Increasingly, domains which have recently been registered are being used to facilitate malicious campaigns. In many cases, these newly set up internet addresses are created using domain generation algorithms and then used exclusively for criminal purposes.<\/p>\n\n\n\n
Phishing filters need to be capable of considering this factor in their analyses, allowing these suspicious URLs to be blocked dependably. At Retarus, in addition to examining the content of the linked (malware or phishing) website itself, we have responded to this development by taking into account the time at which the domain has been registered. The category of risk is always assigned at the domain level, which provides a crucial benefit for the level of protection. As the classification is partly extended to all URLs belonging to a domain, phishing variants using recently altered addresses are also bound to fail. <\/p>\n\n\n\n
Recent analyses by Retarus\u2019 security experts indicate that across just about all customers, substantially more than half of all blocked phishing messages can be traced back to this single filter criteria. Already this March, it was found that at a large international corporation which safeguards its 100,000 email inboxes with R<\/a>etarus E-Mail Security<\/a> such messages accounted for 70 percent of all phishing attempts.<\/p>\n\n\n\n The internal Retarus analysis also confirms that this filter method does not entail any increase in false positives. One of the reasons for this is that it only takes websites into consideration that have been set up with the respective domain registry organization within the past few days. In contrast and practice speaking, it usually takes a lot longer before legitimate emails are sent from a new domain.<\/p>\n\n\n\nOnly comprehensive filtering methods achieve the required outcome<\/h2>\n\n\n\n