How should phishing infrastructure be preserved?¶
Preserve the whole route that supports the phishing activity, not just a screenshot of the page.
Domains, DNS, hosting, redirects, certificates, account records and submission endpoints can all change quickly.
Start with the exact URL and time¶
Record:
- full URL;
- displayed link text;
- source communication;
- date/time and zone;
- redirect chain;
- final destination;
- page content;
- domain and DNS state;
- certificate details where relevant.
A screenshot helps show appearance, but it does not preserve the technical route.
Preserve safely¶
Do not browse a suspicious page from an ordinary workstation just to inspect it.
Use an appropriate safe environment or specialist process to capture:
- page source;
- hidden fields;
- scripts;
- form destination;
- redirects;
- downloaded content;
- hosting details.
Identify the providers that actually control the records¶
Different records may sit with:
- domain registrar;
- DNS provider;
- hosting provider;
- cloud platform;
- URL shortener;
- email sender;
- messaging/telecoms provider;
- payment provider.
One IP address rarely tells the whole story.
Preserve provider-held account data where justified¶
Where the investigation and authority support it, relevant provider records may include:
- customer/account identifiers;
- registration;
- access history;
- uploaded content;
- payment details;
- configuration changes;
- linked accounts.
Shared infrastructure should not be treated as offender identity by itself.
The practical point is: preserve the phishing route before it changes: source link, redirects, page, submission endpoint and provider accounts. A screenshot is useful, but it is only one layer.