Phishing at scale is not hand-built. Operators buy or download a kit: the cloned front end copied from the real login page, a harvesting script that captures what is submitted and forwards it, evasion logic that blocks scanners and geofences victims, and a deployment config so the whole thing drops onto a new host in minutes.
Because the same kit is reused across many campaigns, it leaves consistent traces. An identical favicon hash, the same directory structure, a reused TLS issuer, a shared hosting ASN. Those fingerprints are a gift to defenders, because they turn one discovered URL into the full set of domains running the same kit, including the ones not yet weaponised.
The evasion layer is why a page can look clean to an automated check and still be live for victims. Kits routinely serve a blank page to known scanner IP ranges, to datacentre traffic, or to anyone outside the target country.
Operationally the lesson is to fingerprint before filing. A campaign taken down one URL at a time is a campaign that outlives the effort; a campaign taken down at its shared infrastructure does not.
How Fraudox handles it
Phishing site takedown