Patent attributes
The disclosed non-limiting embodiments of the present technology are directed to methods and systems for warning in regard to cyber threats, especially methods to detect malicious web resources, in particular phishing websites, and mirrors of blocked and/or prohibited websites. The disclosed method comprises receiving, by the computer device, pointers for a plurality of web resources; extracting, by the computer device, at least some of the content elements of each web resource of the plurality of web resources. Iteratively combining, by the computer device, at least two content elements into subgroups and then iteratively combining subgroups into groups in response to a number of web resources including the at least two content elements exceeding a predefined minimum threshold of web resources for the at least one first subgroup and/or group.