the job started with the usual smell: a parking-payment domain that looked close enough to be trusted by someone in a hurry, but not close enough to survive inspection. the goal was not to be dramatic. the goal was to gather evidence, route it to the right abuse desks, and keep eyes on the target until it stopped being useful to the operators.
evidence first
takedowns work best when the evidence is complete and boring. i captured the landing page, response headers, client scripts, hashes, screenshots, dns, hosting data, registrar path, and the live collection behavior. nothing fancy, just a clean bundle that makes it easy for every responsible party to act without another round trip.
pressure in the right places
the reporting path hit the infrastructure provider, registrar-side abuse channel, browser blocklists, and the impersonated brand. public writeups should not include live endpoints, operational tricks, or reusable indicators that help the next kit operator, so those details stay out of this page.
result
- identified hosting, registrar, nameserver pattern, and collection flow
- submitted usable evidence to the parties that could actually take action
- monitored the campaign until it stayed down
- retired the monitors once the operation was no longer alive
the useful lesson: good anti-phishing work is paperwork with teeth. if the proof is clean, the target is real, and the escalation path is correct, a campaign can disappear without turning the process into theater.