Takedown process

Phishing kit

A packaged set of files that recreates a target's login page and ships the captured credentials to the operator.

Also known as phish kit · phishing toolkit

Phishing at scale is not hand-built. Operators buy or download a kit: the cloned front end copied from the real login page, a harvesting script that captures what is submitted and forwards it, evasion logic that blocks scanners and geofences victims, and a deployment config so the whole thing drops onto a new host in minutes.

Because the same kit is reused across many campaigns, it leaves consistent traces. An identical favicon hash, the same directory structure, a reused TLS issuer, a shared hosting ASN. Those fingerprints are a gift to defenders, because they turn one discovered URL into the full set of domains running the same kit, including the ones not yet weaponised.

The evasion layer is why a page can look clean to an automated check and still be live for victims. Kits routinely serve a blank page to known scanner IP ranges, to datacentre traffic, or to anyone outside the target country.

Operationally the lesson is to fingerprint before filing. A campaign taken down one URL at a time is a campaign that outlives the effort; a campaign taken down at its shared infrastructure does not.

How Fraudox handles it

Phishing site takedown

See the service

Related terms

Seen this on your brand?

Send us the URL or account. We file, escalate and verify. You only pay when the content actually comes down.