Website Clone Detection

The ideal phishing website attack technique is to copy the customer website HTML to imitate the user experience of a real website.

The following steps illustrate how the Phishing Watch works when a website is cloned:

  1. The Phishing Watch JavaScript snippet is created and embedded in the website.

  2. The snippet launches each time the webpage is loaded or refreshed.

  3. When the snippet identifies a nonformal suspicious website (by inspecting the URL of the webpage), it reports the suspicious URL back to Threat Command servers in a stealthy, low footprint manner.

  4. The snippet's whitelist excludes cases where it may be operating on the organization's official website.

