Residential Proxies for Threat Intelligence
· 3 min read
Phishing pages and other malicious sites inspect their visitors before showing anything. One arriving from a cloud provider or a security vendor is served a harmless page, while one on home broadband is served the real thing. An analyst working from the wrong IP therefore sees nothing of note and marks the link as safe.
How common this is
- Bolster examined roughly 19,000 phishing kits and found them blocking IP ranges belonging to datacenters, hosting providers and threat intelligence services, with Amazon's and Microsoft's ranges blocked most often.
- ZeroFox has estimated that around a third of phishing attacks employ cloaking.
- Abnormal documented a recent kit offering one-click options to block clouds, VPNs, Tor and known proxy networks, with suspected scanners redirected to a decoy page.
The conclusion to draw from that body of research is that a clean result from an automated scanner means "inconclusive", not "safe".
What the investigating IP needs
- To sit on a consumer ISP, not in a hosting range.
- To be free of any VPN or proxy flag.
- To be located in the country the campaign targets.
The second requirement grows in importance every year. The large rotating residential networks are well known, their exit IPs are flagged by IP intelligence providers, and the more capable kits block them as well. An IP that is residential yet flagged as a proxy is shown the decoy.
Why static residential works well
A static residential proxy is a fixed address on a consumer ISP that is used by you alone.
- It is not part of a known proxy pool, making it far less likely to be flagged.
- Its history is your own. You can check its reputation in the knowledge that it will read the same a week from now. See IP fraud scores explained.
- It gives you a stable identity for work stretching over days, such as following a campaign or keeping a session alive on a forum or a fraudulent shop.
Rotating residential proxies retain their place. They are quick enough for retrieving a page and they reach countries where you hold no static IP. Where they fall short for this kind of work is the proxy flag and the ever-changing address.
Working safely
- Keep investigation traffic on dedicated IPs, apart from corporate traffic.
- Use different IPs for different cases, and retire one once a serious adversary has seen it.
- Browse from a disposable VM or container holding no saved credentials.
- Restrict the proxy to your analysis machines by means of an IP allowlist.
- Capture everything on the first visit, as many kits show the real page once per IP and the decoy from then on.
- Never enter real credentials or personal data.
Other uses
- Brand protection: counterfeit shops and impersonation pages are often shown to consumer traffic alone.
- Malvertising: malicious ads are concealed from server traffic in the same manner. See ad verification with residential proxies.
- Testing your own detection against what a victim would actually be shown.
What Leastslow provides
Static residential IPs on a US consumer ISP in Ashburn, Virginia, with no prior proxy or VPN use and a fraud score of zero. Allowlists and denylists are included, and every IP supports HTTP, SOCKS5 and UDP. Coverage is limited to the US. Prices are on the homepage.