carlos2
Member
OP
- Joined:
- Jun 2024
- Posts:
- 158
- From:
- Medellín, CO
The form POSTed to a different domain but the visual assets were hotlinked or mirrored.
The one I got was self-contained. All assets base64 encoded in the HTML, single POST to a .xyz domain. No external dependencies, no tracking pixels, nothing that would trigger a security tool.
Whoever built it knew exactly what they were doing. Professional operation, not a script kiddie.
not your keys, not your coins
rustyrack_grag
Member
- Joined:
- Jun 2024
- Posts:
- 68
- From:
- Tallinn, Estonia
Tallinn. I strip paint. I also strip email headers for fun.
The IP range Carlos mentioned, I looked it up. ASN belongs to a residential ISP in Eastern Europe. Compromised router or deliberate bulletproof hosting? Hard to say. The upstream is a German carrier that does not respond to abuse reports quickly.
I have reported fifty of these this year. Two takedowns.
if it ain't broke, rust it
carlos2
Member
OP
- Joined:
- Jun 2024
- Posts:
- 158
- From:
- Medellín, CO
Hetzner does not send verification emails at all unless you trigger a password reset
This is the most useful thing anyone has said. I did not know this. I assumed it was routine because other providers do send periodic verification.
So the entire email category is a scam. Good to know.
not your keys, not your coins