OSINT Portfolio / Cases / Case 004
Case 004 · P1 Critical · Financial Fraud · 2026-08-16

PigButcher Network — 499+ Fake Crypto Platforms
Targeting 30+ Countries from a Single IP

Passive OSINT investigation of norevixpulses-de.com uncovered a single IP hosting 499+ live fake crypto investment platforms in 30+ languages. Same scam kit. Same offshore hosting. Russian-speaking operator identified via Vimeo account. People are losing money right now.

Pig-Butchering Financial Fraud Organized Crime 499+ Domains 30+ Countries IP Reverse Lookup Kit Fingerprinting Operator Attribution Offshore Hosting Multi-Language
Entry Pointnorevixpulses-de.com
Network IP181.174.167.37
Hostingoffshoreracks.com (Panama)
Domains Found499+ (all live)
Countries Targeted30+ confirmed
Site StatusLIVE
Operator Lead"Ray Mercier" (alias, Vimeo)
MethodPassive OSINT only
P1 Critical — Active Financial Fraud Multiple countries · Real monetary losses · Ongoing operation
499+ Live fake investment platforms — single IP — confirmed 2026-08-16
Active harm: All 499+ platforms are live right now. Each one is collecting real victim names, email addresses, phone numbers, and IP locations, then connecting victims with human scammers ("account advisors") who pressure them to deposit cryptocurrency. People are losing money today.

Investigation began as a routine check of norevixpulses-de.com — a suspected fake German-language crypto trading platform. A standard IP reverse lookup via HackerTarget revealed that the same server hosts at minimum 499 other domains, all running an identical scam kit, all live, targeting a different country or language with each domain. This is not a collection of unrelated sites — it is a single coordinated financial fraud operation deployed at industrial scale.

Finding 1 — Entry Point: norevixpulses-de.com
Domain
norevixpulses-de.com
Target Country
Germany (DE)
Registrar
NETIM SAS
Created
2026-04-23 (new)
Server IP
181.174.167.37
Hosting
offshoreracks.com — PA
Nameservers
wn0vib.com / rt78u9.com
HTTP Status
200 — LIVE

The site presents as a "serious crypto trading platform with verified reviews" (seriöse Krypto-Handelsplattform mit verifizierten Bewertungen) — standard pig-butchering marketing language. It embeds real TradingView price charts for BTC, ETH, SOL, BNB, IOTA, and DOGE to appear credible. Fake "verified customer reviews" are displayed as testimonials with human-looking names and initials.

The nameservers (wn0vib.com, rt78u9.com, pl9vr3.com) are themselves randomly generated domains registered May 2026 — a deliberate obfuscation pattern to make it harder to enumerate related infrastructure via NS lookup.

Finding 2 — Victim Data Collection & Scam Flow

Source: /assets/js/forms.js + /assets/js/geo.js (both publicly accessible). The scam funnel has four stages:

; Stage 1 — Geolocation (geo.js) ; On every page load, victim IP is sent to ipapi.co GET https://ipapi.co/json/ ; Returns: country_code, city, region, ISP, lat/lon ; Cached in localStorage under 'user_country' — daily refresh ; Used to pre-fill phone country selector with victim's own country ; Stage 2 — Registration (forms.js → POST /send) Collected fields: name ; Full name email ; Email address phone ; Phone number (digits only) full_phone ; E.164 format — e.g. +4917612345678 country_code ; Victim's dial prefix — e.g. +49 ; Stage 3 — Auto-login (server response) POST /send{ success: true, auto_login_url: "https://[crm-domain]/..." } ; Victim auto-redirected to fake trading dashboard in 5 seconds ; Message shown: "In 5 Sekunden werden Sie zu Ihrem Konto weitergeleitet..." ; "Our representative will contact you as soon as possible." ; Stage 4 — The call ; Human scammer ("account advisor") calls victim using the collected phone number ; Builds trust → shows fake profits in dashboard → pressures deposit → money gone
"Unser Vertreter wird Sie schnellstmöglich kontaktieren" — "Our representative will contact you as soon as possible." This is the pig-butchering confirmation phrase. Human operators are on the other end of these registrations, actively calling victims.

The POST /send endpoint returns HTTP 405 on GET requests — confirming it is a live active handler. Fake urgency countdown timers are stored in localStorage and reset automatically when they expire, creating perpetual pressure.

Finding 3 — Full Network: 499+ Domains, Single IP, 30+ Countries
; IP reverse lookup — HackerTarget passive DNS GET https://api.hackertarget.com/reverseiplookup/?q=181.174.167.37 → 499 domains returned (API limit) ; All sampled domains: HTTP 200 — LIVE ; All share: window.translations, window.userCountry, intl-tel-input, action="/send" ; Same scam kit — different brand name + language per domain ; Kit fingerprint confirmed on 15+ randomly sampled domains
Country Code Example Domain Title (as shown to victim) Status
GermanyDEnorevixpulses-de.comNorevixPulses Plattform | Offizielle WebsiteLIVE
AustriaATfels-wertburg.comFels Wertburg Plattform | Offizielle WebsiteLIVE
PolandPLamber-zyskawa.comPlatforma Amber Zyskawa | Oficjalna stronaLIVE
BelgiumBEberkwaardiek.comBerk Waardiek Platform | Officiële websiteLIVE
ItalyITferra-rendorio.comPiattaforma Ferra Rendorio | Sito UfficialeLIVE
DenmarkDKfyrvinstlund.comFyr Vinstlund Platform | Officiel hjemmesideLIVE
Czech RepublicCZkotva-hodnotura.comPlatforma Kotva Hodnotůra | Officiální stránkyLIVE
TurkeyTRlikidite-kur.orgLikídite Kur Platformu | Resmi Web SitesiLIVE
IrelandIElindengewinvale.comLinden Gewinvale Platform | Official WebsiteLIVE
SingaporeSGfuturovonyx-ai.comFuturovOnyx AI Platform | Official WebsiteLIVE
ArgentinaARbonsavio.comBonsavio Platform | Sitio Web OficialLIVE
SpainESaltair-trade.netAltair Trade Plataforma | Sitio web oficialLIVE
JapanJPnorakado.orgNorakado Platform | 公式サイトLIVE
JapanJPmeiken-beruku.com明堅 ベルクプラットフォーム | 公式ウェブサイトLIVE
OmanOMmusabir-faidana.comمثابر فائدانة منصة | الموقع الرسميLIVE
QatarQAnabigh-sandaqiya.comنابغ صندقية المنصة | الموقع الرسميLIVE
Belgian victims confirmed: berkwaardiek.com actively targets Belgian residents. This gives Belgian authorities (FSMA, FCCU) direct jurisdiction over this network.
Finding 4 — Operator Attribution: "Ray Mercier" — Russian-Speaking
; norevixpulses-de.com embeds 4 "testimonial" videos from Vimeo ; Vimeo oEmbed API — passive lookup, no auth required GET https://vimeo.com/api/oembed.json?url=https://vimeo.com/1141150117 Response: title: "видео 1" ; Russian — "video 1" author_name: "Ray Mercier" ; Likely alias author_url: https://vimeo.com/user248890522 ; Same account (user248890522) uploaded all 4 fake testimonial videos: 1141150117 → "видео 1" ; Russian title = Russian-speaking operator 1141149756 → "видео 2" 1141150276 → "видео 3" 1141149904 → "видео 4"

The Vimeo account name "Ray Mercier" is almost certainly an alias — the Russian-language video titles (видео = video) indicate the actual operator speaks Russian. This is consistent with Eastern European/CIS-based pig-butchering operations, which are well-documented by Europol and Interpol as a dominant source of organized investment fraud targeting Western and Asian victims.

The Vimeo account user248890522 is a direct link from the fake testimonial infrastructure to the operator's production account. This is a significant attribution lead for law enforcement.

OSINT technique: The videos are embedded with dnt=1 (do not track) in the iframe URL — ironically, the operators are privacy-conscious about tracking their own Vimeo views while mass-tracking their victims via ipapi.co.
Finding 5 — Offshore Infrastructure: offshoreracks.com (Panama)
Server IP
181.174.167.37
CIDR Block
181.174.164.0/22
Country
Panama (PA)
Host Name
offshoreracks.com
PTR Record
host-181-174.167.37.offshoreracks.com
Registrar
NameCheap (since 2005)
IP Block Contact
Jorge Miranda (Panama)
Domains on IP
499+ (all scam)

offshoreracks.com is a hosting provider explicitly positioned for offshore/anonymous operations (the name is self-describing). The IP block 181.174.164.0/22 is registered to Panama under an individual name, making law enforcement takedown requests significantly harder than with mainstream providers. This is consistent with intentional selection of bulletproof-adjacent infrastructure.

The domain registrar for the scam sites is NETIM SAS (France) — which, unlike the hosting provider, is an ICANN-accredited registrar subject to ICANN abuse policies. A single abuse report to NETIM documenting 499+ fraudulent domains can trigger mass suspension through ICANN's Uniform Rapid Suspension (URS) or similar mechanism.

Reporting Actions Taken

Scale of this network warrants reporting to multiple tiers simultaneously — national financial regulators, international law enforcement, platform-level abuse, and registrar mass suspension.

Europol EC3 — European Cybercrime Centre

Reported to ec3@europol.europa.eu. Multi-country organized financial fraud with 499+ active platforms. Belgian, German, Italian, Dutch, Polish, Czech, Danish, Irish, and Spanish EU victims confirmed. Full IOC list, kit fingerprint, and Vimeo operator lead submitted. EC3 scope: organized transnational financial crime with cross-border victim impact.

NETIM SAS — Registrar Mass Suspension Request

Reported to abuse@netim.net. NETIM is the registrar for the majority of the 499+ domains. A single bulk abuse report documenting the shared IP, identical kit, and coordinated fraud operation is sufficient grounds for ICANN-backed mass suspension. This is the highest-leverage single action available — one registrar, potentially 499 takedowns.

BaFin — German Federal Financial Supervisory Authority

Reported to BaFin (bafin@bafin.de). norevixpulses-de.com and fels-wertburg.com (Austria-targeted) are operating unlicensed investment platforms soliciting German and Austrian residents — a direct violation of the German Securities Trading Act (WpHG) and EU MiFID II. BaFin has authority to issue public warnings and refer for criminal prosecution.

FSMA — Belgian Financial Services Authority

Reported to FSMA (https://www.fsma.be/en/contact). berkwaardiek.com is actively targeting Belgian residents with an unlicensed investment platform. FSMA can issue public warnings, blacklist the domain, and coordinate with FCCU for criminal referral.

FCCU — Belgian Federal Computer Crime Unit

Reported to fccu@police.belgium.eu. berkwaardiek.com is actively targeting Belgian residents with a criminal investment fraud scheme. FCCU has jurisdiction over computer-enabled financial crime affecting Belgian victims and can coordinate with FSMA for a joint enforcement action. Criminal referral pathway: FSMA (financial regulator) → FCCU (criminal investigation) → prosecutors for the pig-butchering fraud network.

Vimeo — Fake Testimonial Video Takedown

Reported to https://vimeo.com/help/contact. Vimeo account user248890522 ("Ray Mercier") is hosting fake testimonial videos for 499+ financial fraud platforms. Takedown removes the legitimacy signal from all 499 sites simultaneously and severs a direct link to the operator identity.

offshoreracks.com — Host Abuse

Reported to abuse@namecheap.com (registrar of offshoreracks.com). offshoreracks.com is hosting 499+ active financial fraud sites on a single IP block. Namecheap has a consistent record of acting on well-documented abuse reports. A successful complaint could trigger IP block blacklisting or deregistration.

Method — How This Was Found

Phase 1 — Entry point: Passive HTTP analysis of norevixpulses-de.com. HTML source inspection revealed fake-legitimacy patterns: real TradingView embeds, intl-tel-input library, countdown timers, geo-tracking.

Phase 2 — JS analysis: forms.js and geo.js read directly from the server. Documented the complete victim data collection flow, the POST /send registration endpoint, and the auto_login_url redirection pattern.

Phase 3 — IP pivoting: Single passive DNS query to HackerTarget's reverse IP lookup API. One query, one second, 499 domains returned. All confirmed live via HTTP HEAD requests.

Phase 4 — Kit fingerprinting: Verified shared kit by checking 15+ random samples from the 499 for the same JavaScript fingerprint: window.translations, window.userCountry, window.geo, intl-tel-input, and action="/send".

Phase 5 — Operator attribution: Vimeo oEmbed API lookup (public, no auth) on the embedded video IDs from the page source. Single API call returned the Vimeo account name and confirmed Russian-language operator via video title language.

Skill demonstrated: A single IP reverse lookup turned one suspicious domain into a 499-domain organized crime network. The operator's identity was found via a public API without touching anything that wasn't already publicly available from the page source. This is the compounding power of passive OSINT pivoting — each step multiplies the scope.
Live Evidence — Screenshot Captured 2026-08-16

Headless browser screenshot of norevixpulses-de.com captured during investigation. German-language fake investment platform presenting as "NorevixPulses Plattform" — targeting German-speaking victims with fake 4.9-star reviews and fabricated trader statistics.

norevixpulses-de.com — LIVE FRAUD PLATFORM (1 of 499+) ⚠ MALICIOUS
Screenshot: NorevixPulses fake crypto investment platform

Evidence captured passively. Do not invest — this is a pig-butchering fraud platform with no licensed status.

Live Infrastructure Status
Loading status…
Previous: Case 003 — dulo.cx All Cases Next: Case 005 — Amazon PhaaS
SevinOS BLE Radar