Search papers, labs, and topics across Lattice.
This study introduces PhiShark2026, a comprehensive multi-layer active-web dataset designed to enhance phishing website research by preserving raw evidence from 67,502 scans, including 33,387 phishing observations. By maintaining detailed information across various web layers and explicitly recording unavailable evidence, the dataset allows for the exploration of new extraction methods and cross-layer relationships that were previously constrained by traditional datasets. The findings reveal systematic differences in resource usage and infrastructure context between phishing and benign websites, providing a robust foundation for future research in phishing detection and analysis.
Phishing detection just got a major upgrade with a dataset that captures the raw evidence behind 67,502 web scans, revealing critical differences between phishing and benign sites.
Phishing websites are short-lived and rapidly changing, yet many phishing datasets reduce observations to URLs or precomputed features, constraining researchers to predefined representations and discarding the underlying evidence needed to derive alternative features, apply new extraction methods, examine cross-layer relationships, and reanalyze observations as phishing techniques evolve. This study addresses this limitation with a multi-layer active-web dataset comprising 67,502 scans, including 33,387 phishing observations from operational feeds and 34,115 screened benign reference observations. The corpus preserves raw evidence across HTML content and screenshots, URL and redirect behavior, HTTP and security headers, compliance files, TLS certificates, DNS and domain registration, open ports, geolocation and accessibility measurements, and network infrastructure, while explicitly recording unavailable evidence rather than treating it as negative observations. To avoid misleading infrastructure attribution on shared platforms, the study applies a hosting-aware evidence model that masks provider-owned infrastructure signals for free-hosted tenant pages while retaining meaningful page- and transport-level evidence. Characterization reveals systematic differences between phishing and benign websites across web-resource usage, domain maturity, mail and policy configuration, security headers, and infrastructure context. By preserving raw artifacts together with acquisition metadata and explicit evidence availability, the corpus provides an inspectable and reproducible foundation for future phishing measurement and dataset research.