Checking whether phishing kits hide their images on everyday CDNs
Phishing pages rarely look broken to a casual visitor. The logos are crisp, the form fields align, and the corporate branding loads almost instantly because the images are not sitting on a sketchy server in a faraway data centre. They sit on content delivery networks, the same global infrastructure that news sites, streaming platforms and retailers use to push pixels across the world at speed. That overlap is precisely what makes modern phishing so hard to spot, and it is why learning to check where a page's images actually live has become a small but useful skill for anyone running a household network, a school device fleet or a small business in Adelaide or Hobart.
The exercise is not about declaring a CDN guilty by association. Cloudflare, Akamai, Amazon CloudFront and a long list of image hosts serve billions of legitimate images every day. The goal is to spot when a domain you have never heard of is quietly piggybacking on that reputation, hiding its visual payload inside infrastructure that browsers and mail gateways are trained to trust. Below is a practical workflow you can run in a browser tab, without paying for enterprise tooling, that walks through that verification from the first right-click to the final reputation lookup.
Why mainstream image hosts appeal to scam operators
A phishing kit author wants three things from an image host: speed, uptime and a low chance of being blocked. Free static hosts and commercial CDNs tick all three boxes. When a scam page loads a logo from cdn.example.net instead of a freshly registered domain, the browser sees a familiar hostname, the corporate proxy sees a recognised ASN, and the recipient's spam filter sees an asset served over HTTPS from a major provider. The image might be a stolen bank logo, a fake MyGov banner or a counterfeit Australia Post label, but the wrapping around it is indistinguishable from the wrapping a real marketing email uses.
Phishers also rotate quickly. A new domain might live for thirty-six hours before it is burned, but the image assets can be re-uploaded to a different free host and reused across hundreds of disposable URLs. Operators even reuse Telegram-themed infrastructure for the same reason, and researchers regularly see new arrivals such as telegram-themed phishing pages appear, recycle the same look, and disappear just as fast. Recognising that pattern is the first mental step before any technical check.
Pulling the image URLs straight from the page source
Open the suspect page in a desktop browser, leave the network alone and press Ctrl+U (or right-click and choose View Page Source). The raw HTML will spill out and you can search for img src=, srcset and background-image. Each match is a clue. Jot down the full hostname, not just the path, because the hostname is the bit that tells you who is actually serving the bytes. A page that visually looks like a government portal but whose images all come from i.imgur.com or images.weserv.nl is telling you something useful.
A faster route is the Network panel. Reload the page with the DevTools open, filter the list by Img, and watch which hosts respond. The waterfall column will show you whether a fetch was served from a regional edge, which is a hallmark of a real CDN, or from a single origin, which is a hallmark of an opportunistic free host. For a small business in Brisbane running a handful of staff devices, this is the kind of five-minute check that can be folded into a quarterly phishing drill without buying anything new.
Mapping the host to a CDN and ASN
Once you have a shortlist of image hostnames, drop each one into a whois lookup or a DNS tool such as SecurityTrails, ViewDNS or the dig command on a Linux terminal. Most legitimate CDNs return clear, consistent ownership. Cloudflare ranges announce under AS13335, Akamai under AS20940, Amazon CloudFront under AS16509. If a hostname resolves to one of those ASNs and the reverse DNS matches the brand, you are almost certainly looking at a real CDN rather than a lookalike.
The interesting cases sit at the edges. A free image host running on shared infrastructure, or a domain whose images are served from a hosting reseller in a country that does not match the apparent brand, is worth a second look. You will also see that some domains never get around to running any real content at all. Researchers documenting oddities have noted that the parked address may show a cPanel login prompt rather than a working site, which is itself a signal that whoever registered the name never finished setting it up and that any future use is likely to be opportunistic.
Cross-checking host reputation with Australian and global feeds
After confirming the network layer, the next step is reputation. The Australian Cyber Security Centre runs the ReportCyber portal and publishes alerts through cyber.gov.au, while the ACCC's Scamwatch feed surfaces trends at consumer level. On the global side, VirusTotal aggregates more than ninety engines and will mark a host if it has been flagged for phishing, malware distribution or spam. URLVoid, Cisco Talos and Spamhaus add further depth, and many of them accept the bare hostname so you can test image hosts even when you do not have a full URL.
A consistent theme in Australian guidance, including material from the Office of the Australian Information Commissioner, is that image hosts are a soft spot in many privacy and notifiable data breaches investigations under the Privacy Act 1988. A logo scraped from a public source is one thing; a passport scan, a payslip or a Medicare image that ends up cached on a free host is another, and that is where the legal exposure sits for an Australian organisation. Keeping a record of every host you encounter is a low-effort way to be ready if a regulator later asks what your team checked and when.
Reading HTTP headers for telltale CDN behaviour
If you are comfortable with curl -I, a single command line can tell you more than a screenshot. Real CDNs leave distinctive fingerprints in their response headers. Cloudflare sends cf-cache-status and a server: cloudflare line. Amazon CloudFront returns x-amz-cf-id and via: 1.1 ... cloudfront.net. Fastly uses x-served-by and x-cache. A mismatched header is a strong tell: a hostname claiming to be on Cloudflare but returning Server: Apache/2.4 from a single IP is not actually on Cloudflare at all, it is just resolving into Cloudflare's range through a DNS trick or a flat rental.
Browser extensions such as uBlock Origin, Wappalyzer or the built-in Firefox network view can surface most of this without typing commands. For community groups in regional Victoria or the Northern Territory, where technical support is thin on the ground, those extensions are a reasonable substitute for a full corporate stack. They also work on the NBN connections most Australian households already use, with no extra cost or training required.
A short checklist for everyday verification
- Capture every image hostname from the page source and the Network panel before drawing conclusions.
- Resolve each hostname and confirm the ASN matches the brand it appears to represent.
- Look for Cloudflare, Akamai, CloudFront, Fastly or jsDelivr fingerprints in the response headers.
- Run the hostnames through VirusTotal, URLVoid and Scamwatch to see if they have already been reported.
- Check the registration record for the parent domain; a domain that still shows a hosting login screen is not a credible brand.
- Save the result alongside any screenshot, so a future review under the Notifiable Data Breaches scheme has a paper trail.
The honest answer is that a CDN match is evidence, not a verdict. Plenty of genuine community newsletters, sports clubs and small charities in Perth and Darwin host their images on free CDNs because they cannot afford anything else. The point of the workflow is to combine the network layer, the headers and the reputation databases into a single picture, then weigh that picture against the context of the page. A fifteen-minute sweep each quarter, recorded in a simple spreadsheet and revisited whenever an unfamiliar domain lands in a staff inbox, is enough to give a household or a small Australian business a much sharper sense of which sites deserve trust, and which are simply borrowing a trusted network to look the part.