Skip to content

Almost sent $500 to a cloned WHMCS site

General Discussion by annexbi 4 replies 389 views
#1

So I was about to (don't judge me (I was tired)) pay an invoice for what I thought was my Hostinger panel and the URL was hostinger.com (which (and this is where I should have caught it)) had a valid SSL cert but the WHOIS was three days old and the real one is billing.hostinger.com and I caught it at the last second because the CSS was slightly off (you know that feeling when something is wrong but you can't place it) and I checked the SPF record which was... absent (red flag ) and then I saw the MX was pointing to some random IP in a range I'd never seen and I almost sent $500 to a clone that looked BETTER than the real site which is honestly the worst part

push. done. coffee.
#2

For what it's worth, the absence of SPF is not inherently a phishing indicator—many legitimate hosts have misconfigured email infrastructure. Hot take: the real signal was the domain registration age combined with the transposed subdomain structure. A proper DMARC policy with p=reject on the legitimate domain would have helped you verify authenticity via forensic reporting, though most hosting providers deploy DMARC at p=none or not at all. The cloned site's valid certificate was likely from a free ACME provider with no domain validation beyond control. Check the CT logs for issuance patterns; rapid multiple certificates for similar domains often precede phishing campaigns. Worth noting: I checked Hostinger's actual domain and their DMARC record is... missing entirely. Their SPF is a single include that resolves to a softfail default. The clone had better email hygiene than the real operation.

SPF, DKIM, DMARC — holy trinity ✉️
#3

¡¿Can you believe this?! Is very crazy jajaja... I almost fall for similar thing last year... is very important to check the certificate details not just the lock icon... Vut now I am thinking... maybe the real Hostinger needs to hire the phishers for security consulting jajaja... no wait... is very serious actually... I delete this and repost... Hostinger security is very bad if clone is better... ¡¿where is their bug bounty?!

#4

Maybe the real site is the clone all along you know. Maybe we are living in simulation where bad security is original and good security is copy you know. Maybe check if your password still works on both you know. Maybe they cloned your clone...

SPF, DKIM, DMARC — holy trinity ✉️
#5

Valid ssl on a 3 day old domain? I don't buy it

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft