Open navigation

OpenPhish

Modified on: Wed, 28 Aug, 2024 at 4:40 PM

Overview

OpenPhish is a phishing intelligence platform that helps organizations detect and prevent phishing attacks.


The database contains structured and searchable information on all phishing websites detected by OpenPhish, as well as metadata that can be used for detecting and analyzing cyber incidents, searching for patterns and trends, or act as a training or validation dataset for AI applications.


The database contains these forensics indicators for each URL:

  • Hostname, page, path, and language
  • Impersonated brand
  • SSL certificate metadata
  • IP address, ASN, and country
  • Drop accounts


Using the OpenPhish integration on Maltego, investigators can search and filter for brands that are being impersonated, phishing URLs related to domains, ASNs, and more to answer the following questions:

  • Is a particular URL a phish?
  • How many phishing URLs were detected on a specific hostname?
  • How many phishing URLs on a specific IP address?
  • What percentage of URLs have a specific pattern in their path?


OpenPhish Transforms for Maltego


Read more about OpenPhish Transforms for Maltego on our website here.


OpenPhish Transforms

Find Phishing URLs [OpenPhish]

Transform Meta Info

InformationValue
Display NameFind Phishing URLs [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Output Entitiesmaltego.URL

Variants

Transform NameShort DescriptionInput Entities
maltego.openphish.search_ip_urlSearches the OpenPhish database for information about the given IP.maltego.IPv4Address
maltego.openphish.search_asn_for_urlsSearches the OpenPhish database for information about the given AS number.maltego.AS
maltego.openphish.search_brandSearches the OpenPhish database for information about the given brand/company name.maltego.Company

Description

Searches the OpenPhish database for information about the given IP.

Transform Meta Info

InformationValue
Display NameFind ASN related to Phishing IPs [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Transform Namemaltego.openphish.search_ip_asn
Short DescriptionSearches the OpenPhish database for information about the given IP.
Input Entitiesmaltego.IPv4Address
Output Entitiesmaltego.AS

Find Phishing IPs [OpenPhish]

Transform Meta Info

InformationValue
Display NameFind Phishing IPs [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Output Entitiesmaltego.IPv4Address

Variants

Transform NameShort DescriptionInput Entities
maltego.openphish.search_asnSearches the OpenPhish database for information about the given AS number.maltego.AS
maltego.openphish.search_brand_ipSearches the OpenPhish database for information about the given brand/company name.maltego.Company

Find Brands/Companies being impersonated [OpenPhish]

Transform Meta Info

InformationValue
Display NameFind Brands/Companies being impersonated [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Output Entitiesmaltego.Company

Variants

Transform NameShort DescriptionInput Entities
maltego.openphish.search_asn_for_brandsSearches the OpenPhish database for information about the given AS number.maltego.AS
maltego.openphish.search_url_brandsSearches the OpenPhish database for information about the given URL.maltego.URL

Find ASN [OpenPhish]

Description

Searches the OpenPhish database for information about the given brand/company name.

Transform Meta Info

InformationValue
Display NameFind ASN [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Transform Namemaltego.openphish.search_brand_asn
Short DescriptionSearches the OpenPhish database for information about the given brand/company name.
Input Entitiesmaltego.Company
Output Entitiesmaltego.AS

Description

Searches the OpenPhish database for information about the given URL.

Transform Meta Info

InformationValue
Display NameSearch SSL Certificates Related to Phishing [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Transform Namemaltego.openphish.search_url_ssl_certs
Short DescriptionSearches the OpenPhish database for information about the given URL.
Input Entitiesmaltego.URL
Output Entitiesmaltego.X509Certificate

Search Phishing IPs [OpenPhish]

Description

Searches the OpenPhish database for information about the given URL.

Transform Meta Info

InformationValue
Display NameSearch Phishing IPs [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Transform Namemaltego.openphish.search_url_ips
Short DescriptionSearches the OpenPhish database for information about the given URL.
Input Entitiesmaltego.URL
Output Entitiesmaltego.IPv4Address

Find ASNs [OpenPhish]

Description

Searches the OpenPhish database for information about the given URL.

Transform Meta Info

InformationValue
Display NameFind ASNs [OpenPhish]
Owner 
AuthorMaltego Technologies
Data SourceOpenPhish
Transform Namemaltego.openphish.search_url_asn
Short DescriptionSearches the OpenPhish database for information about the given URL.
Input Entitiesmaltego.URL
Output Entitiesmaltego.AS


Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.