- the job started with the usual smell: a parking-payment domain that looked close enough - to be trusted by someone in a hurry, but not close enough to survive inspection. the goal - was not to be dramatic. the goal was to gather evidence, route it to the right abuse desks, - and keep eyes on the target until it stopped being useful to the operators. -
- -evidence first
-- takedowns work best when the evidence is complete and boring. i captured the landing page, - response headers, client scripts, hashes, screenshots, dns, hosting data, registrar path, - and the live collection behavior. nothing fancy, just a clean bundle that makes it easy for - every responsible party to act without another round trip. -
- -pressure in the right places
-- the reporting path hit the infrastructure provider, registrar-side abuse channel, browser - blocklists, and the impersonated brand. public writeups should not include live endpoints, - operational tricks, or reusable indicators that help the next kit operator, so those details - stay out of this page. -
- -result
--
-
- identified hosting, registrar, nameserver pattern, and collection flow -
- submitted usable evidence to the parties that could actually take action -
- monitored the campaign until it stayed down -
- retired the monitors once the operation was no longer alive -
- the useful lesson: good anti-phishing work is paperwork with teeth. if the proof is clean, - the target is real, and the escalation path is correct, a campaign can disappear without - turning the process into theater. -
-
-