OSINT Radar

Phishtank

www.phishtank.com

PhishTank collects and verifies reported phishing URLs, helping analysts investigate malicious campaigns and block fraudulent domains.

Free Open Source #Phishtank #Cyber Threat OSINT tools #Cyber Threat OSINT resources #analysts #block #campaigns #collects #domains #fraudulent
Open tool

Pivot map

You have domain ip url
You get indicators infrastructure malware

Use this map to decide whether Phishtank accepts the lead you are holding, and what kind of lead it may return for the next step.

Pivot from here

Outputs from Phishtank can become inputs for the next tool. These are the most relevant follow-on pivots in the library.

Investigator Use

PhishTank is a community-powered database of verified phishing URLs, maintained by OpenDNS and operated as a public resource for the security community. It allows anyone to submit suspicious phishing URLs, which are then verified by community members and added to a searchable database accessible via web interface and API.


What investigators use PhishTank for: checking whether a URL is a known phishing site before clicking, researching phishing infrastructure associated with a target domain or IP, identifying phishing campaigns targeting specific brands or organizations, and integrating phishing URL data into automated threat analysis workflows.


What PhishTank exposes: verified phishing URLs with submission dates, the target brand being impersonated, current online status of the phishing site, submission and verification history, and community voting records. The complete database is downloadable for offline analysis and integration into security tools.


PhishTank is particularly useful for brand impersonation investigations. If a financial institution or e-commerce brand is being targeted by phishing campaigns, searching PhishTank by brand name surfaces all known phishing URLs mimicking that organization. These URLs often share hosting infrastructure, domain registration patterns, and redirect chains that link multiple campaigns together.


For domain attribution: when investigating a suspicious domain, submitting it to PhishTank and searching for similar domains can reveal whether a domain operator has a history of phishing activity. Many phishing actors reuse the same hosting providers, registrars, and URL patterns across multiple campaigns.


API access: PhishTank provides a free API for programmatic access to the database. The API accepts URLs for lookup and returns verified phishing status, making it easy to integrate into automated analysis pipelines.


In a workflow: check PhishTank early in any URL-focused investigation, alongside URL Void and VirusTotal. If a domain appears in PhishTank, pivot to its hosting infrastructure using SecurityTrails and Shodan to identify related phishing infrastructure. Use certificate transparency logs to find other domains issued certificates from the same provider at the same time — a common pattern in phishing kit deployment.

Before You Pivot

Record Context

Capture the target, search terms, and why this source is relevant before you leave the page.

Preserve Evidence

Archive volatile pages, save screenshots, and keep timestamps for anything that may change.

Corroborate

Treat one tool as a lead source. Confirm important findings with independent sources.

Related tools