Phish Report uses a combination of WHOIS data, RDAP (Registration Data Access Protocol), and a manually curated list of shared hosting providers to automatically identify website hosting providers. This combined approach improves the accuracy and reliability of the identification process.
WHOIS data provides valuable details about domain ownership and registration. By querying the WHOIS database, Phish Report can extract information such as the domain registrar, registrant organization, and administrative contact. This data can be used to uncover the hosting provider associated with the domain, as hosting providers are often responsible for domain registration as well.
In addition to WHOIS data, RDAP offers a more standardized and comprehensive way to access registration data. RDAP provides a machine-readable format for retrieving domain registration information, including hosting provider details. By querying RDAP, Phish Report can gather up-to-date and consistent information from domain registries, enabling more accurate identification of hosting providers.
To further enhance the identification process, Phish Report incorporates a manually curated list of shared hosting providers. This list is compiled based on extensive research and knowledge of common hosting platforms and services. By comparing the gathered WHOIS and RDAP data with this curated list, Phish Report can identify if a website is hosted on a shared hosting platform and pinpoint the specific provider.
Combining these three approaches lets Phish Report more efficiently and accurately identify website hosting providers. This helps security professionals and organizations in their efforts to investigate and mitigate potential phishing attacks.