Wandera - the world's largest provider of cloud security for remote workers, just published its
Cloud Security Report for September 2020.
In which they refocus on
phishing, looking at the length of phishing URLs compared to safe URLs, but nor only.
Researches from
Wandera found that the length of a URL can be a telltale sign of a
phishing attack.
legitimate URLs typically sit between 20 and 44 characters, anything beyond that is most likely a phishing link. On average, requests made to unsafe domains were 1.8x the length of requests made to safe domains.
Wandera researches warn that spotting suspicious links could be very problematic on smartphones and tablets because modern browsers truncate URLs for a sleeker design.
Users need to apply a greater level of scrutiny when using browsers on mobile devices, particularly given the rise in use of punycode in phishing URLs.
I encourage everyone to read about
Punycode and Phishing attacks, in this report are many interesting pieces of information, like the days of the week in which people visit phishing sites the most.
... largely stable during the week aside from Monday... Interestingly, Saturday was the day with the highest number of requests made to phishing domains.
Here link to the full report:
https://www.wandera.com/cloud-security-report-september-2020/