HAWK EYES

HAWK EYES

ID: ekobfalejalidceannlelkiombbfmgad

Supported Languages

πŸ‡ΊπŸ‡ΈEnglish

Extension Info & Metadata

Status
Active
Version
1.0.1
Size
0.07 MB
Rating
5.0/5
Reviews
1
Users
99
Type
Extension
Updated
Apr 19, 2022
Category
Education
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
HAWK EYESView Profile
Country
Canada
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
Dance Act Avenue Oshawa, ON [email protected] Canada
Website
Visit
Total Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Total Users
99
Screenshot 1
Screenshot 2

A browser extension powered by machine learning to detect zero-day phishing attacks in real-time.

**Overview** Hawk Eyes is a lightweight browser extension that is easy to install. The core function of this plugin is to analyze URLs and page content on the fly and alert the user of possible phishing attacks. Detection services and datasets are deployed on the server-side. The machine learning-based model for predicting whether a website is a phishing website is also deployed on the server; the mode is trained off-line. Hawk Eyes URL prediction service combines blacklist blocking, whitelist filtering, heuristic methods and machine learning models. **How it Works** When the user opens a web page in the browser, the extension sends the current URL and part of the page HTML to the server but nothing is saved on the server-side except the URL and only if it is a phishing link. The core detection service is divided into three stages. First, the blacklist is compared. If it hits, the result will be a phishing link. Next, compare the whitelist, and if it hits, it will directly return to the normal link. Then, analyze page content and URL character content, and filter pages that do not require the submission of sensitive information. Finally, the machine learning model predicts whether there is a phishing risk. When the plugin receives the detection result, if there is a risk of phishing, a warning box with a red background will pop up on the page to notify the user. **Key Features** The extension will warn you when you visit phishing web pages. When the user clicks the extension's icon, site information is presented, such as domain, organization, registration year. Other services include: - Check whether a URL has phishing risk - Report a suspicious URL - Search detected phishing URLs **Publications** L. Tang and Q. H. Mahmoud, β€œA Survey of Machine Learning-Based Solutions for Phishing Website Detection,” Machine Learning and Knowledge Extraction, vol. 3, no. 3, pp. 672–694, Aug. 2021. Doi: https://doi.org/10.3390/make3030034. L. Tang and Q. H. Mahmoud, "A Deep Learning-Based Framework for Phishing Website Detection," in IEEE Access, vol. 10, pp. 1509-1521, 2022. doi: 10.1109/ACCESS.2021.3137636.

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:β€’ 10% increase: Early script execution enables pre-emptive content manipulation
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://www.api.thehawkeyes.com/*
Host
Medium
Host permission β€” access limited to this URL pattern.
https://api.thehawkeyes.com/*
Host
Medium
Host permission β€” access limited to this URL pattern.
http://api.thehawkeyes.com/*
Host
Medium
Host permission β€” access limited to this URL pattern.
http://www.api.thehawkeyes.com/*
Host
Medium
Host permission β€” access limited to this URL pattern.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
URLs
17
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.api.thehawkeyes.com/predict/aihttps://www.api.thehawkeyes.com/predict/ai
getbootstrap.com-https://getbootstrap.com/
github.com/twbs/bootstrap/blob/main/LICENSEhttps://github.com/twbs/bootstrap/blob/main/LICENSE
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.api.thehawkeyes.com/verify/addhttps://www.api.thehawkeyes.com/verify/add?error_type=2&url=
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*https://*/*
*/*http://*/*
www.api.thehawkeyes.com/*https://www.api.thehawkeyes.com/*
api.thehawkeyes.com/*https://api.thehawkeyes.com/*
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.0.0
Latest
0.07 MB
Benign
β€”
1.0.1
0.07 MB
Benign
β€”
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.