Skip to content

Evidence Types Collected

PhishDestroy edited this page Nov 29, 2025 · 1 revision

Evidence Types Collected

The dashboard aggregates multiple categories of forensic evidence:

1. Domain-Level Evidence

  • WHOIS data (creation time, registrar, NS)
  • Registrar patterns (cheap hosting, repeat behavior)
  • Bulk domain purchases by same actor

2. Page-Level Evidence

  • Full HTML dumps
  • JavaScript fingerprinting
  • Hardcoded wallet, API keys or endpoints
  • Template markers reused across campaigns

3. Visual Evidence

  • URLScan screenshots
  • Archive.org screenshots
  • Web-cloned UI patterns
  • Matching pixel-perfect layout reuse

4. Behavioral Evidence

  • Brand impersonation clusters
  • Drainer redirect logic
  • Crypto wallet address reuse
  • IP/ASN mobility patterns

5. External Correlation

  • PhishTank records
  • VirusTotal URL entries
  • Other blacklist sources

Evidence is collected 100% legally and consists ONLY of public information.

Clone this wiki locally