The 20 most common words in phishing attacks

When online spies or criminals want to get their hands on sensitive information, they usually start by going phishing, sending e-mails to people inside a government agency or contractor, trying to lure them to a malicious site or download a file where malware awaits.

Many of the high-profile attacks in recent years against agencies and government contractors involved targeted phishing — or spear-phishing — campaigns, from the hack of intelligence analysis company Strategic Forecasting to an attack on Oak Ridge National Laboratory.

In fact, according to the U.S. Computer Emergency Readiness Team, 51.2 percent of reported attacks on federal, state and local government agencies in 2011 involved phishing.

What can users do to keep their guard up? A new report from cybersecurity company FireEye that analyzes how malicious files get past traditional defenses also includes a helpful list of the most common file names and extensions being used in phishing attacks.

If you order anything to be shipped, whether for work or home, be careful of where your confirmation and tracking e-mails come from. The FireEye report says that, between the second half of 2011 and the first half of 2012, words related to shipping grew from 19.2 percent to 26.3 percent of phishing e-mails, with “label” and “invoice” being the most common. 

Another tactic on the rise is sending e-mails that try to create a sense of urgency, which grew from 1.72 percent to 10.68 percent of the e-mails, the report said.

The 20 most common words in use in the first half of the year, and the percentage of phishing e-mails in which they appeared:

  1. label, 15.17
  2. invoice, 13.81
  3. post, 11.27
  4. document, 10.92
  5. postal, 9.80
  6. calculations, 8.98
  7. copy, 8.93
  8. fedex, 6.94
  9. statement, 6.12
  10. financial, 6.12
  11. dhl, 5.20
  12. usps, 4.63
  13. 8, 4.32
  14. notification, 4.27
  15. n, 4.22
  16. irs, 3.60
  17. ups, 3.46
  18. no, 2.84
  19. delivery, 2.61
  20. ticket, 2.60

The five most common categories used in phishing e-mails were: postal (26.33 percent); urgency, such as confirmations and alerts (10.68); banking or tax matters (3.83); airline and travel information (2.45) and billing (0.68).

Phishers aiming to distribute malicious files generally try to get users to click on a link to a malicious website or download a file attached to the e-mail. In terms of attachments, users would be wise to be wary of .zip attachments, which appeared in 76.91 percent of the phishing e-mails FireEye checked in the first half of the year.

The next most common attachments were .pdf (11.79 percent), .exe (3.98), .doc (2.67) and .pif (1.09). The .exe extension, noting an executable file for downloading and running programs, was once the go-to extension for malware distribution, but with people learning to be careful about it, hackers have moved on to ZIP and PDF.

Tactics change, but the most common ruse at the moment is trying to get people to feel they can’t wait to find out about the matter at hand.

“By referencing important and usually time-sensitive information — express shipment notifications, tax return forms, financial account status, airline ticket confirmations, and so on — cybercriminals are fostering a sense of urgency in their targets, hoping to get them to rush into downloading the malware that exploits their system,” the report concludes.

Security experts have standard advice for avoiding phishing attacks, including keeping browsers and anti-virus software up to date, using a firewall and using anti-phishing toolbars. But very often, it comes down to a user’s decision to click or not to click. The more you know about how phishing campaigns operate, the safer you’ll be.

Reader Comments

Tue, Feb 12, 2013 Derek Mandeville S.F. Bay Region

Knowing the "hit" words could mean useability in COTS security apps, configured to flag Phish key words for the Inbox (if the major vendors are not doing this already); should flag as potential mal-mail, not relegate automatically to the SPAM folder. Would also like to know more re: "8" and "n". Or are they just enigmatic out of context?

Wed, Nov 14, 2012 DarthDana

Doesn't do a lot of good to know what the most common words are because they're the same words that a bona-fide e-mail would use; FedEx, DHL, USPS, delivery, etc. But "8" and "n"? WTF?

Thu, Sep 27, 2012 Jerry Johnson

Well, now THAT'S actionable... (eyes rolling)

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above