Skip to content

Scam warning: fake 'abuse department' emails targeting our niche

General Discussion by tifiucem 15 replies 7.4K views
#11

Has anyone actually clicked through and reported what the fake login pages look like now? I forwarded my Contabo one to their abuse@ but never heard back. Curious if they're using the same kit across all these providers or if each fake page is customised. The InterServer one was pretty lazy but the Hetzner copy was almost spot on. Would be useful to know if there's a common host or registrar behind them.

your margin is my opportunity
#12

Late to this but wanted to add something from our side.

tifiucem said:
The logo was pixel-perfect, even the footer matched.

We've started signing all real abuse mails with a domain key now. If it doesn't pass that check, it's not us. Still not widely known though.

The 24 hour suspension line is in basically every fake now. Real notices give more time unless it's something extreme.

30 days quiet but this is cyclical. They'll be back.

swimming upstream since 2019 🐟
#13

39 days quiet but this just happened to me too

Got a "CloudCone Security Alert" last week

tifiucem said:
The scare tactic was "your node will be suspended in 24 hours"

Mine said 12 hours, even more pressure

The sender was CloudCone-security dot something, not their real domain

I almost clicked because I actually had a ticket open with them already

Did anyone report these to the actual providers

Do they even care or is it just noise to them

rm -rf / --no-preserve-root ☯
#14

The two-Ls domain feels lazy compared to the pixel-perfect Vultr clone. Wondering if there are two separate groups behind this or one outfit just getting sloppy with certain targets. Also 57 days later — has the wave died down or are people just not reporting it anymore?

#15

76 days late to this but did anyone ever report that Vultr-abuse domain to their actual abuse team. I tried checking if it was still live and got a 404 but the registrant info might still be useful to someone.

I got a similar mail last week claiming to be from HostHatch, the suspension timer was 12 hours instead of 24. Same pressure tactic just faster.

#16

Just saw this thread after getting hit myself.

RAJ said:
Has anyone actually clicked through and reported what the fake login pages look like now?
Caught my eye because mine was "interserverl-abuse" too, so they're definitely still running that specific variant.

The 24-hour suspension thing got me to hover at least, so the pressure tactic works. Did anyone actually report these domains to the registrars or are we just warning each other and moving on. Feels like whack-a-mole but maybe it helps slow them down.

Also 95 days since the last reply, hope this is still useful to someone scrolling through.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft