A Large-Scale Analysis of Phishing Websites Hosted on Free Web Hosting Domains
Sayak Saha Roy, Unique Karanjit, Shirin Nilizadeh

TL;DR
This study introduces FreePhish, a scalable framework for detecting phishing websites hosted on free web hosting domains, revealing their prevalence, evasion tactics, and the challenges faced by existing defenses.
Contribution
We developed FreePhish, a novel framework to identify and analyze phishing sites on free web hosting services, providing insights into their characteristics and detection challenges.
Findings
Over 31,400 phishing URLs detected on 17 free hosting services
FWB phishing sites evade traditional anti-phishing tools more effectively
Some FWBs and social platforms are slow to remove phishing content
Abstract
Free Website Building services (FWBs) provide individuals with a cost-effective and convenient way to create a website without requiring advanced technical knowledge or coding skills. However, malicious actors often abuse these services to host phishing websites. In this work, we propose FreePhish, a scalable framework to continuously identify phishing websites that are created using FWBs. Using FreePhish, we were able to detect and characterize more than 31.4K phishing URLs that were created using 17 unique free website builder services and shared on Twitter and Facebook over a period of six months. We find that FWBs provide attackers with several features that make it easier to create and maintain phishing websites at scale while simultaneously evading anti-phishing countermeasures. Our study indicates that anti-phishing blocklists and browser protection tools have significantly lower…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSpam and Phishing Detection · Internet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques
