Phishing Webpage Longevity
摘要
Cybercriminals often spend considerable time preparing for phishing attacks, which surprisingly tend to last only a few hours. This short longevity is evident when older phishing links quickly become inaccessible, either taken down or flagged as malicious. While this benefits potential victims by shortening the effective risk period, it also poses a challenge for researchers aiming to track and analyze current phishing trends to develop effective countermeasures. Understanding the typical lifespan of phishing webpages is crucial for creating phishing data collection solutions. Our study involved monitoring phishing webpages from PhishTank and OpenPhish for three months while capturing their active/inactive status. Collected data had to undergo multiple steps - removing duplicate, incorrect, or non-relevant entries. The analysis focused on uncovering the phishing webpages’ longevity, while the summary offered key findings. The study reveals that phishing webpages have a remarkably short active lifespan, with significant variations in the ratio of active to inactive pages across different periods. The initial rapid decrease by \(\approx \) 12% in active phishing webpages is notable, dropping from 65% to 53% within the first five minutes and less than 40% remaining active after 24 h.