Remix.run Logo
heipei an hour ago

Legitimate file hosting services present the biggest total volume of newly discovered phishing pages / unique hostnames. Another (similar) angle is using unrelated legitimate domains which are compromised (think insecure Wordpress) to host phishing sites in subdirectories. A lot of traditional ML scoring and blocking approaches fall flat if the hosting domain is on a very legitimate and hard-to-block domain, such as a government website.