Illustrative example · names, domains and infrastructure changed
OP-2291: Payroll-portal phishing kit
One operation, traced from a single lookalike domain to the hosting, certificate, social
profile and app behind it, with the takedown status for each. This is the kind of
report Averrow produces. Every name here is made up: the brand is a fictional “Acme”,
domains use the reserved .example name, and addresses come from documentation ranges.
Summary
Acme, a fictional payroll customer, was targeted by a credential-phishing operation built around a fake payroll sign-in. Fourteen lookalike domains were registered over eight days. They share two hosting networks and, for the first nine, one TLS certificate, which is what tied them into a single operation rather than fourteen separate alerts. The same operation also runs a fake HR-support social profile and a cloned “Acme Pay” app on a third-party store.
At the time of this report, 8 of 14 domains have been removed, 4 are pending a registrar response and 2 are queued. 6 domains are still live.
Timeline
- Day 0 First lookalike seen
A newly registered domain imitating Acme's payroll sign-in page is flagged for brand impersonation.
- Day 1–2 Cluster grouped
Eight more lookalikes appear on the same hosting network and present the same TLS certificate. They are grouped into one operation, OP-2291, by the infrastructure they share.
- Day 3–4 Operation widens
A second hosting network comes online with three more domains. A fake HR-support social profile and a cloned “Acme Pay” app are linked to the same operation.
- Day 4 Takedowns filed
Evidence packages go to the registrars and hosting providers for the domains found so far; the social profile and the app are drafted with evidence, ready to file with each platform. Later domains are queued as they appear.
- Day 5–8 First removals
Eight domains are removed, starting with the original hosting network.
- Day 9 Report generated
Four domain takedowns are pending a registrar response and two are queued. The social and app cases remain open.
Linked indicators
14 lookalike domains. “Day” counts from first sighting. All names are fictional.
| Domain | Seen | Network | Address | Shared cert | Takedown |
|---|---|---|---|---|---|
acme-payroll-login.example | Day 0 | AS64500 | 192.0.2.14 | Yes | Removed |
acme-payrol1.example | Day 1 | AS64500 | 192.0.2.14 | Yes | Removed |
acmepayroll-portal.example | Day 1 | AS64500 | 192.0.2.21 | Yes | Removed |
login-acme-hr.example | Day 1 | AS64500 | 192.0.2.21 | Yes | Removed |
acme-hr-support.example | Day 1 | AS64500 | 192.0.2.33 | Yes | Removed |
my-acmepay.example | Day 1 | AS64500 | 192.0.2.33 | Yes | Removed |
acme-benefits-portal.example | Day 2 | AS64500 | 192.0.2.47 | Yes | Removed |
acme-timesheets.example | Day 2 | AS64500 | 192.0.2.47 | Yes | Removed |
secure-acme-pay.example | Day 2 | AS64500 | 192.0.2.52 | Yes | Pending |
acme-payroll-update.example | Day 3 | AS64501 | 198.51.100.8 | No | Pending |
acmepay-verify.example | Day 3 | AS64501 | 198.51.100.8 | No | Pending |
acme-employee-id.example | Day 4 | AS64501 | 198.51.100.19 | No | Pending |
acme-payslips.example | Day 6 | AS64501 | 198.51.100.19 | No | Queued |
acme-direct-deposit.example | Day 8 | AS64501 | 203.0.113.40 | No | Queued |
Hosting
| Network | Operator (fictional) | Address ranges | Domains | Note |
|---|---|---|---|---|
| AS64500 | Example Hosting Network A | 192.0.2.0/24 | 9 | Original infrastructure; most domains removed. |
| AS64501 | Example Hosting Network B | 198.51.100.0/24, 203.0.113.0/24 | 5 | Second wave; later registrations. |
Shared TLS certificate
Nine domains on AS64500 present the same certificate, serial 4F:2A:91:C7:0B:3E:D8:65 (fictional), issued by
“Example Certificate Authority”. A shared serial across unrelated-looking domains is strong
evidence of one operator, and it is what lets the operation be grouped before every domain is found.
Other surfaces
@acme_hr_support (example handle). Uses Acme's name and logo, posts “payroll update” links to the lookalike domains, and was created in the same week as the first domains.
“Acme Pay” on the Apple App Store. Copies the real app's name, icon and description. The publisher is unrelated to Acme, and the listing links to the operation's sign-in domains.
Takedown status
| Surface | Target | Status |
|---|---|---|
| Lookalike domains | Registrars and hosting providers | 8 removed · 4 pending · 2 queued |
| Social profile | @acme_hr_support (example handle) | Drafted with evidence · ready to file |
| Cloned app | “Acme Pay” on the Apple App Store | Drafted with evidence · ready to file |
Recommended actions
- Block the 14 domains and both address ranges
Add the indicators below to your mail, web and DNS filters now; don't wait for the takedowns to complete.
- Warn payroll and HR staff
The lures impersonate payroll sign-in, payslips and direct-deposit changes. A short reminder to use bookmarked links only is enough.
- Move Acme's DMARC policy past “none”
Acme's own domain publishes DMARC at p=none, so spoofed mail from it is delivered. Step up to quarantine, then reject, once reports look clean.
- Report the cloned app to the store and your mobile team
Tell customers and staff that the only official Acme Pay app is the one listed on your site.
- Keep watching for re-registration
Operations like this tend to return on new names. Monitoring stays on Acme's name and the infrastructure above.
Illustrative example · names, domains and infrastructure changed. See how we count the numbers on our homepage.
See what is aimed at your brand
Run the free scan, or book a walk-through of a report built from your own data.