Skip to content

Interpreting Actor Profiles

PhishDestroy edited this page Nov 29, 2025 · 1 revision

Interpreting Actor Profiles

Each actor JSON includes:

risk_score

0–100 metric from blacklist sources.

brand_impersonation

Brands the actor is currently abusing:

  • MetaMask
  • Coinbase
  • Ledger
  • Bank logins
  • Microsoft
  • Email providers

screenshots

Thumbnails of phishing pages.

blacklist_sources

Where domain was reported earlier:

  • PhishTank
  • destroylist
  • Cloudflare block pages

domain list

Full set of domains used by actor.

code evidence

JS, HTML, or drainer fingerprints.

Actor files allow investigators to:

  • Track evolution
  • Identify infrastructure reuse
  • Map campaigns

Clone this wiki locally