Skip to content

Scam near-miss: the 'account verification' that wasn't

General Discussion by carlos2 29 replies 3.4K views
#21

Has anyone checked if these fake Hetzner pages are using the actual CSS from the real site? I inspected one and it was pulling assets from a CDN that had scraped the real site. The form POSTed to a different domain but the visual assets were hotlinked or mirrored.

This is more sophisticated than cloning. It is parasitic.

2 #22
quellejar said:
The form POSTed to a different domain but the visual assets were hotlinked or mirrored.

The one I got was self-contained. All assets base64 encoded in the HTML, single POST to a .xyz domain. No external dependencies, no tracking pixels, nothing that would trigger a security tool.

Whoever built it knew exactly what they were doing. Professional operation, not a script kiddie.

not your keys, not your coins
#23

Tallinn. I strip paint. I also strip email headers for fun.

The IP range Carlos mentioned, I looked it up. ASN belongs to a residential ISP in Eastern Europe. Compromised router or deliberate bulletproof hosting? Hard to say. The upstream is a German carrier that does not respond to abuse reports quickly.

I have reported fifty of these this year. Two takedowns.

if it ain't broke, rust it
9 #24
rustyrack_grag said:
ASN belongs to a residential ISP in Eastern Europe

Estonia has good cybercrime reporting through the national CERT. But they only care if the target is Estonian infrastructure. Foreign phishing hosted elsewhere forwarded to them, they do not have jurisdiction or interest.

I have started just blocking entire ASNs at my firewall. Aggressive but effective.

1 #25

This thread drifted hard from "almost got phished" to "email authentication is broken" to "which ASN can I block." Classic forum.

To answer the original XMR question: there is a provider in Switzerland that takes it for VPS, but they are expensive and oversubscribed. I will not name them because they do not need the attention. Search "VPS XMR no KYC" and you will find the same three names everyone mentions.

#26

I am late but: the fake Vultr email minhdock described, I got one too. The giveaway was that it threatened "account suspension in 24 hours" and I knew my billing cycle was not due for two weeks.

Urgency is the universal red flag. Real companies give you weeks. Scammers give you hours.

9 #27

Oh~~~ very good tip joshpest~~~

I will check check billing cycle very much~~~ thank you~~~

But my host email still look like scam~~~ hard to know~~~

#28

Has anyone mentioned that Hetzner does not send verification emails at all unless you trigger a password reset or add a new payment method? The "account verification" premise is itself the scam.

If you get unsolicited Hetzner verification email, it is fake by definition. This should be in their docs https://docs.hetzner.com but it is not.

3 #29
proalex said:
Hetzner does not send verification emails at all unless you trigger a password reset

This is the most useful thing anyone has said. I did not know this. I assumed it was routine because other providers do send periodic verification.

So the entire email category is a scam. Good to know.

not your keys, not your coins
#30

Same here. I got one of these last month and assumed it was real because I had just moved servers. Turned out the move was unrelated and the email was fake. I caught it because the TOTP prompt came from a different domain than my authenticator expected.

Hardware security keys would not have helped. The phishing site proxied the real login and relayed my TOTP in real time. I changed passwords immediately.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft