HomeHow ToHow to spot a malicious website

How to spot a malicious website

Many of the websites on the internet are created solely to scam users and steal personal information or money. But how can you recognize such a malicious website?

See also: Twitter: Creates Tor website to combat Russian censorship

malicious website

The first thing you should do before visiting a website is to make sure the domain name is the one you intend to visit. Scammers create fake websites that masquerade as official entities, usually in the form of an organization you probably recognize, such as Amazon, PayPal, or Wal-Mart. Sometimes the difference between the real website name and the name of a malicious website is almost negligible (for example, microsoft.com is replaced by rnicrosoft.com).

Malicious actors can trick users into visiting such a website in two ways. Either through phishing, where an email is sent with a malicious attachment, or through "typosquatting," which uses misspellings in domain names (as mentioned above).

Regardless of how you reach the site, once you log in to it, the hacker will collect your login credentials and other personal data, such as your credit card information, and then use those credentials themselves on the real site or any other site where you use the same login credentials.

Domain name

The first and most basic method of spotting a fraudulent website is to make sure the domain name is the one you actually intend to visit.

When you visit a website, look for the lock to the left of the URL in the address bar. This lock indicates that the website is secured with a TLS/SSL certificate, which encrypts data sent between the user and the website.

If the website does not have a TLS/SSL certificate, an exclamation mark ( ! ) will appear to the left of the domain name in the address bar.

The downside to this is that not all SSL certificates are genuine. It’s still best to take a closer look at the padlock to be sure.

See also: Malware campaign impersonates company looking to buy websites

First, click on the padlock and then click on "Connection is secure" from the context menu.

If the certificate is valid, then you will see the text "Certificate is valid" in the next menu. Go ahead and click on it for more details.

A new window will appear showing information about the certificate. You can check which website the certificate was issued to, who issued it, and its expiration date.

While this won't always protect you from scammers, the padlock (and certificate information) is a good indication that you're visiting a legitimate website.

locate

Privacy and returns policy

Reputable websites, such as Amazon, have a fairly comprehensive return policy and privacy policy that details everything the customer needs to know about each respective policy.

If a website has a poorly written return or privacy policy, it's a sign that something is wrong. If a website doesn't state these policies at all, avoid it at all costs, as the site is likely malicious.

Spelling or syntax errors

Another warning sign is spelling or syntax errors. Most reputable websites have teams of professionals who create these sites. If a site looks like it was created in a day by one person, is full of spelling and grammatical errors, and has a questionable user interface (UI), there is a chance it is malicious.

Ways of protection

To be a little more sure that the website you're visiting is the right one, use a website scanner like McAfee SiteAdvisor. These tools crawl the web and check websites for spam and malware. If you visit a dangerous (or potentially dangerous) website that the program determines may contain malicious content that could harm your computer, you'll be notified and asked to confirm that you still want to proceed to the website when you try to visit it.

If you purchased something using your credit or debit card from a malicious website, the first thing you should do is call your bank immediately and report what happened. They will immediately freeze your accounts and cards so that the hacker can no longer purchase anything with your information.

See also: eBike phishing websites promote scams through Google Ads

If you believe your personal information may also have been leaked, such as your social security number, date of birth, address, etc., you should freeze your credit so the scammer cannot take out loans or open any accounts in your name.

Once this is taken care of, file a report with your local police, notify the Internet Crime Complaint Center, and report the website to Google.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS