Illustrative example · names, domains and infrastructure changed

Sample operation report

OP-2291: Payroll-portal phishing kit

One operation, traced from a single lookalike domain to the hosting, certificate, social profile and app behind it, with the takedown status for each. This is the kind of report Averrow produces. Every name here is made up: the brand is a fictional “Acme”, domains use the reserved .example name, and addresses come from documentation ranges.

Scan your own domain
9 daysFirst seen to report
3Surfaces (domains, social, app)
14 → 6Domains live
19Linked indicators

Summary

Acme, a fictional payroll customer, was targeted by a credential-phishing operation built around a fake payroll sign-in. Fourteen lookalike domains were registered over eight days. They share two hosting networks and, for the first nine, one TLS certificate, which is what tied them into a single operation rather than fourteen separate alerts. The same operation also runs a fake HR-support social profile and a cloned “Acme Pay” app on a third-party store.

At the time of this report, 8 of 14 domains have been removed, 4 are pending a registrar response and 2 are queued. 6 domains are still live.

Timeline

  1. Day 0
    First lookalike seen

    A newly registered domain imitating Acme's payroll sign-in page is flagged for brand impersonation.

  2. Day 1–2
    Cluster grouped

    Eight more lookalikes appear on the same hosting network and present the same TLS certificate. They are grouped into one operation, OP-2291, by the infrastructure they share.

  3. Day 3–4
    Operation widens

    A second hosting network comes online with three more domains. A fake HR-support social profile and a cloned “Acme Pay” app are linked to the same operation.

  4. Day 4
    Takedowns filed

    Evidence packages go to the registrars and hosting providers for the domains found so far; the social profile and the app are drafted with evidence, ready to file with each platform. Later domains are queued as they appear.

  5. Day 5–8
    First removals

    Eight domains are removed, starting with the original hosting network.

  6. Day 9
    Report generated

    Four domain takedowns are pending a registrar response and two are queued. The social and app cases remain open.

Linked indicators

14 lookalike domains. “Day” counts from first sighting. All names are fictional.

DomainSeenNetworkAddressShared certTakedown
acme-payroll-login.example Day 0 AS64500 192.0.2.14 Yes Removed
acme-payrol1.example Day 1 AS64500 192.0.2.14 Yes Removed
acmepayroll-portal.example Day 1 AS64500 192.0.2.21 Yes Removed
login-acme-hr.example Day 1 AS64500 192.0.2.21 Yes Removed
acme-hr-support.example Day 1 AS64500 192.0.2.33 Yes Removed
my-acmepay.example Day 1 AS64500 192.0.2.33 Yes Removed
acme-benefits-portal.example Day 2 AS64500 192.0.2.47 Yes Removed
acme-timesheets.example Day 2 AS64500 192.0.2.47 Yes Removed
secure-acme-pay.example Day 2 AS64500 192.0.2.52 Yes Pending
acme-payroll-update.example Day 3 AS64501 198.51.100.8 No Pending
acmepay-verify.example Day 3 AS64501 198.51.100.8 No Pending
acme-employee-id.example Day 4 AS64501 198.51.100.19 No Pending
acme-payslips.example Day 6 AS64501 198.51.100.19 No Queued
acme-direct-deposit.example Day 8 AS64501 203.0.113.40 No Queued

Hosting

NetworkOperator (fictional)Address rangesDomainsNote
AS64500 Example Hosting Network A 192.0.2.0/24 9 Original infrastructure; most domains removed.
AS64501 Example Hosting Network B 198.51.100.0/24, 203.0.113.0/24 5 Second wave; later registrations.

Shared TLS certificate

Nine domains on AS64500 present the same certificate, serial 4F:2A:91:C7:0B:3E:D8:65 (fictional), issued by “Example Certificate Authority”. A shared serial across unrelated-looking domains is strong evidence of one operator, and it is what lets the operation be grouped before every domain is found.

Other surfaces

Social profile

@acme_hr_support (example handle). Uses Acme's name and logo, posts “payroll update” links to the lookalike domains, and was created in the same week as the first domains.

Cloned app

“Acme Pay” on the Apple App Store. Copies the real app's name, icon and description. The publisher is unrelated to Acme, and the listing links to the operation's sign-in domains.

Takedown status

SurfaceTargetStatus
Lookalike domains Registrars and hosting providers 8 removed · 4 pending · 2 queued
Social profile @acme_hr_support (example handle) Drafted with evidence · ready to file
Cloned app “Acme Pay” on the Apple App Store Drafted with evidence · ready to file

Recommended actions

  1. Block the 14 domains and both address ranges

    Add the indicators below to your mail, web and DNS filters now; don't wait for the takedowns to complete.

  2. Warn payroll and HR staff

    The lures impersonate payroll sign-in, payslips and direct-deposit changes. A short reminder to use bookmarked links only is enough.

  3. Move Acme's DMARC policy past “none”

    Acme's own domain publishes DMARC at p=none, so spoofed mail from it is delivered. Step up to quarantine, then reject, once reports look clean.

  4. Report the cloned app to the store and your mobile team

    Tell customers and staff that the only official Acme Pay app is the one listed on your site.

  5. Keep watching for re-registration

    Operations like this tend to return on new names. Monitoring stays on Acme's name and the infrastructure above.

Illustrative example · names, domains and infrastructure changed. See how we count the numbers on our homepage.

See what is aimed at your brand

Run the free scan, or book a walk-through of a report built from your own data.