Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should phishing infrastructure be preserved?

Preserve the whole route that supports the phishing activity, not just a screenshot of the page.

Domains, DNS, hosting, redirects, certificates, account records and submission endpoints can all change quickly.

Start with the exact URL and time

Record:

  • full URL;
  • displayed link text;
  • source communication;
  • date/time and zone;
  • redirect chain;
  • final destination;
  • page content;
  • domain and DNS state;
  • certificate details where relevant.

A screenshot helps show appearance, but it does not preserve the technical route.

Preserve safely

Do not browse a suspicious page from an ordinary workstation just to inspect it.

Use an appropriate safe environment or specialist process to capture:

  • page source;
  • hidden fields;
  • scripts;
  • form destination;
  • redirects;
  • downloaded content;
  • hosting details.
Original linkWhat was supplied?Exact URL and source message.
Redirect chainWhere did it go?Shorteners, tracking and intermediate services.
Hosted pageWhat was served?Page source, certificate and hosting context.
Submission endpointWhere was data sent?Separate infrastructure may receive credentials.

Identify the providers that actually control the records

Different records may sit with:

  • domain registrar;
  • DNS provider;
  • hosting provider;
  • cloud platform;
  • URL shortener;
  • email sender;
  • messaging/telecoms provider;
  • payment provider.

One IP address rarely tells the whole story.

Preserve provider-held account data where justified

Where the investigation and authority support it, relevant provider records may include:

  • customer/account identifiers;
  • registration;
  • access history;
  • uploaded content;
  • payment details;
  • configuration changes;
  • linked accounts.

Shared infrastructure should not be treated as offender identity by itself.

The practical point is: preserve the phishing route before it changes: source link, redirects, page, submission endpoint and provider accounts. A screenshot is useful, but it is only one layer.

Reference: CIM-043Cyber Incidents & Offender Methods