P1 Critical · Netflix Credential Phishing · PhaaS · 228-Domain Platform

Case 007 — Netflix PhaaS
"Made with ❤ By Hands" Kit · 228 Domains · 69HOST AS205397

Day-old Netflix credential phishing domain on a 228-domain phishing-as-a-service platform hosted at 69HOST LLC (AS205397, Frankfurt). French-language kit with active ASN-based bot detection. Multi-brand targeting: Netflix, Amazon Prime, La Poste, Mondial Relay, Ameli/CPAM, Banque Postale, BBVA, Intesa/Raiffeisen — covering France, Spain, Denmark, Belgium, Serbia, Albania, Switzerland.

P1 Critical Credential Phishing Netflix Clone PhaaS Platform 228 Domains Bot Detection French-Language Kit 69HOST LLC · AS205397 Apache + PHP 8.3 + Plesk Multi-Brand · 8+ Countries Passive OSINT Only
Entry Domainnetf-reintegration-definition.com
StatusLIVE — Active Phishing
Domain Age1 day (2026-08-15)
Platform Scale228 domains
IP45.74.61.10
Hosting69HOST LLC · AS205397
Kit Signature"Made with ❤ By Hands"
Primary BrandNetflix (lang=fr)
✓ INFRASTRUCTURE DOWN — 2026-08-19 Automated IOC monitoring (30-min interval) confirmed all three tracked entry points offline as of August 19, 2026. netf-reintegration-definition.com, ntflx-france.com, and the active phish page at /pages/ are all returning HTTP 000 (connection refused). The 228-domain cluster this kit operated from is confirmed down at the infrastructure level — 69HOST LLC (AS205397) netblock no longer responding for this operator. Reports filed: EC3/Europol, FCCU, CCB SafeOnWeb, 69HOST abuse.
Finding 1 — Entry Domain: Fresh Netflix Clone (24 Hours Old)

The domain netf-reintegration-definition.com was registered 2026-08-15T21:55:51Z — less than 24 hours before investigation. The name follows a deliberate obfuscation pattern: "netf" (Netflix abbreviation) combined with a nonsense English phrase ("reintegration-definition") to pass naive keyword filters while remaining meaningless.

The root page delivers an obfuscated JavaScript redirect. The JS is encoded using a string-shuffling array technique (common in phishing kits) to evade static scanners, but decodes trivially to a single instruction:

// Original: ~800 bytes of shuffled string array + parseInt rotation loop // Decoded output: window['location']['href'] = './pages/'; // Kit creator comment left in root HTML: <!-- Made with <3 By Hands --> // Also: random fake date timestamps in HTML comments (anti-crawl noise): <!-- 1969-10-31 15:38:59 --> <!-- 1938-11-16 08:02:06 --> <!-- BkazHBgYp2398L8 --> <!-- 9J9vxC2HI --> (random tokens — honeypot?)
Registered
2026-08-15 (1 day old)
Registrar
Global Domain Group LLC
Redirect Target
/pages/ (Netflix clone)
Kit Comment
"Made with ❤ By Hands"
Page Language
lang="fr" (French)
Favicon
Netflix ICO (48×48, confirmed)
Finding 2 — Active Bot Detection: ASN + UA + Mobile Gate

The /pages/ endpoint runs a three-factor fingerprinting gate before serving phishing content. Requests that fail the check receive a debug response revealing the exact values being checked:

# Gate response for blocked requests (served as the body text): <title>Netflix</title> ← Kit identity confirmed even in gate response User-Agent: <full UA string> | ASN: Unknown | Mobile: No ↑ Blocks datacenter/VPS ASNs ↑ Blocks desktop crawlers # Three gate conditions that must ALL pass: 1. UA must not identify as a known bot/crawler (curl, wget, python-requests, etc.) 2. ASN must resolve to a consumer ISP (not datacenter/cloud/VPN/research infra) 3. Mobile must = Yes (UA must report a mobile device) # Why this matters: # Standard anti-phishing crawlers (VirusTotal, Google Safe Browse, CERT scanners) # all run from datacenter ASNs — this kit evades all of them at the server level.
OPSEC significance (and why this matters for threat intel): By probing with controlled UA/ASN variations, I was able to map exactly what the gate checks. This means the phishing content never appears in VirusTotal URL scans, Google Safe Browsing, or automated CERT scanner databases — it only renders for real mobile users on consumer ISPs. The domain registers as "200 OK but empty" in most automated threat intel feeds. Documenting the gate logic itself is the intelligence product — it tells defenders exactly what scanner exemption to build.
UA Check
Active (curl/bots blocked)
ASN Check
Active (datacenter blocked)
Mobile Check
Active (desktop blocked)
Safe Browse Impact
Evasion likely
Finding 3 — Platform Scale: 228 Domains on Single IP · Multi-Brand PhaaS

A reverse IP lookup on 45.74.61.10 (69HOST LLC, AS205397) reveals 228 active domains — a full Phishing-as-a-Service platform covering multiple brands and target countries. This is not a single criminal deploying one phishing page; it is a PhaaS operation offering credential harvesting infrastructure across 12+ brand categories targeting 8+ European countries.

French Delivery (La Poste / Mondial Relay)
34
Amazon Prime Video (FR)
11
Netflix (FR + ES)
10
French Healthcare (Ameli / CPAM)
10
French Banking (BP / CA / CM / SG)
10
Balkan Banking (Intesa / Raiffeisen)
9
Spanish targets (BBVA / DGT)
6
Danish health / banking
6
Advance fee / upfront scams
5
Facebook (Eastern Europe)
2
Other / misc
74+
French-language focus: The dominant use case is French citizen targeting — delivery fraud (La Poste, Mondial Relay), healthcare credential theft (Ameli, CPAM), and banking phishing (Banque Postale, Crédit Agricole). The Netflix and Prime Video clones are secondary revenue streams on the same infrastructure. The kit is likely authored by a French-speaking threat actor group and sold or shared as a service.
Finding 4 — Infrastructure Analysis: 69HOST LLC Bulletproof-Adjacent Hosting

69HOST LLC (AS205397) is a Frankfurt-based hosting provider whose infrastructure is almost exclusively hosting phishing and fraud domains in this reverse-IP lookup. Zero legitimate commercial or consumer sites visible among the 228 results — all domain names are brand-impersonation patterns.

IP 45.74.61.10 ASN AS205397 — 69HOST LLC Location Frankfurt am Main, Hesse, Germany DNS (NS) ns1.69host.cc / ns2.69host.cc Abuse contact abuse@69host.cc ← primary takedown target Web server Apache / PHP 8.3.33 / PleskLin TLS Valid cert (HTTPS) No MX records → credential exfiltration is NOT email-based → consistent with Telegram bot exfil (standard for this kit type) Registrar Global Domain Group LLC (IANA 3956) Registrar abuse abuse@globaldomaingroup.com ← domain takedown target Created 2026-08-15T21:55:51Z Status clientTransferProhibited ← registrar lock, can't be transferred away
No MX records → Telegram exfiltration: French-language phishing kits of this generation consistently use Telegram bots to forward harvested credentials in real time. Each domain operator receives a Telegram message the instant a victim submits. Without MX records, the kit has no email server to trace — the exfil channel is the Telegram API (api.telegram.org), which is encrypted and harder to monitor. This is a deliberate operational choice, not an oversight.
Finding 5 — Kit Signature: "Made with ❤ By Hands" — French PhaaS Author

The HTML comment <!-- Made with <3 By Hands --> is a persistent signature left by the kit author across all deployments. This is a known marker in French-language phishing kit distribution circles — the author markets their kit, receives payment (often in cryptocurrency), and deploys infrastructure for paying operators, or sells the kit for self-hosting.

Additional kit characteristics consistent with this author's style:

  • Random fake historical dates in HTML comments (1907, 1929, 1938...) — anti-crawl noise designed to confuse timeline analysis tools
  • Random 10-15 character alphanumeric tokens in HTML comments — possibly session/license markers or just noise
  • Obfuscated JS redirect using string-array shuffling with a numeric XOR seed (identical pattern seen in multiple French PhaaS kits)
  • Server-side ASN gate (PHP-level, not JS) — protects ALL kit deployments on the server regardless of operator skill
  • Assets served from sibling directories (../img/) — consistent kit folder structure across all 228 deployments
<!-- Made with <3 By Hands --> ← author credit <!-- 1969-10-31 15:38:59 --> ← fake date (anti-crawl noise) <!-- BkazHBgYp2398L8 --> ← random token (license/noise) window['location']['href'] = './pages/' ← obfuscated redirect (decoded) ../img/fav.ico ← consistent folder structure lang="fr" ← French-first kit ASN-gate in PHP ← server-side, not JS
Finding 6 — Signature Intelligence: Kit Pivot via Shodan & Censys

The HTML comment <!-- Made with <3 By Hands --> is not just a provenance marker — it is a searchable fingerprint across the open internet. Indexing engines like Shodan, Censys, and FOFA scan HTTP response bodies and can return every server currently serving this string, including deployments on different IPs than the 45.74.61.10 cluster identified through reverse-IP pivot.

This technique converts a single kit signature into a proactive sensor: new deployments registered after this investigation can be found before they register victims, by querying the same string against live internet scan data. Security teams can create persistent saved searches (Shodan Alerts, Censys Watchlists) to receive notifications when new servers serving the signature come online.

Recommended queries (passive, read-only — using publicly indexed data, not active scanning):

http.html:"Made with <3 By Hands" → Returns all currently indexed servers with this HTML comment services.http.response.body:"Made with <3 By Hands" → Full-text body search across IPv4 scan data body="Made with <3 By Hands" → May surface additional ASNs not covered by Shodan/Censys app:"Made with <3 By Hands" "Made with <3 By Hands" lang:php → May surface leaked kit source code, enabling deeper static analysis

This approach scales the single 228-domain pivot into a global coverage map of every server currently running the same kit. The kit author's consistent use of this signature across all deployments — likely a vanity mark or license watermark — inadvertently created a permanent identification mechanism for the entire platform.

Reporting Actions Taken

Multi-target reporting required: the hosting provider (69HOST), the registrar (Global Domain Group), the impersonated brand (Netflix), French national CERT (ANSSI) for the French citizen targeting scope, and Europol EC3 for the multi-country PhaaS platform.

69HOST LLC — Hosting Provider Abuse

Reported to abuse@69host.cc. All 228 domains on AS205397 IP 45.74.61.10 are phishing or fraud pages. No legitimate sites identified in the reverse IP. The entire server is being operated as phishing infrastructure. Requesting immediate suspension of all domains and IP block.

Global Domain Group — Registrar Abuse

Reported to abuse@globaldomaingroup.com. Domain registered 2026-08-15 (one day before report). Active Netflix credential phishing within hours of registration. Requesting domain suspension under ICANN abuse policy.

Netflix Security — Brand Abuse

Reported to phishing@netflix.com. Active Netflix credential phishing at netf-reintegration-definition.com/pages/ with Netflix favicon and French-language clone. Additional Netflix impersonation domains on same infrastructure: ntflx-france.com, netflix-clients.com, netflixclient.com, hellpntfliix.com, netfilxaccount-es.com, netfix-renewal.com, support-ntflx.com, support-account-flix.net, renovarntflx.com, www.netflix-espana.com.

ANSSI — French National Cybersecurity Agency

Reported via https://www.cybermalveillance.gouv.fr/ (French national phishing reporting platform). The platform primarily targets French citizens: Ameli (French health insurance), Banque Postale, Crédit Agricole, Mondial Relay, La Poste — all French national institutions. The scale (34 delivery phishing domains alone) indicates an organized campaign against French users.

Europol EC3 — Multi-Country PhaaS

Reported to ec3@europol.europa.eu. Platform spans Belgium, France, Spain, Denmark, Serbia, Albania, Switzerland, Hungary — EU multi-jurisdiction case. 228 active phishing domains on single infrastructure suggest organized cybercriminal group, not individual actor. French-language PhaaS kit sold or operated as a service across multiple campaigns.

Method — Full Investigation from One Domain

Phase 1 — DNS + WHOIS: Initial DNS lookup reveals IP 45.74.61.10. WHOIS confirms 1-day-old domain via Global Domain Group LLC, NS records pointing to 69HOST's own nameservers.

Phase 2 — Reverse IP pivot: Single HackerTarget reverse-IP query on 45.74.61.10 returns 228 domains — the full PhaaS platform inventory. Brand analysis of all domain names reveals the complete attack surface: 12+ brand categories, 8+ EU countries.

Phase 3 — JS deobfuscation: Root page JS decoded from ~800-byte shuffled-array obfuscation to a single window.location.href = './pages/' redirect. Kit creator comment Made with <3 By Hands extracted from HTML.

Phase 4 — Evasion infrastructure dissection: Systematic controlled probes with varied User-Agents, Accept-Language, and Referer headers caused the server's gate to self-disclose its three-factor algorithm in its own response body. This is a deliberate OSINT technique — the server's debug output became the intelligence product. The investigation stopped at infrastructure characterisation: no attempt was made to interact with or submit data to phishing forms, consistent with passive OSINT principles.

Operator identity: No registration data visible (WHOIS privacy / redacted by registrar). 69HOST LLC appears to operate permissively — the entire ASN is phishing infrastructure. This is consistent with bulletproof-adjacent hosting that accepts payment without content scrutiny.

IOC Table — Key Indicators
Entry domain netf-reintegration-definition.com Phish page netf-reintegration-definition.com/pages/ IP 45.74.61.10 69HOST LLC · AS205397 · Frankfurt DE NS ns1.69host.cc Registrar Global Domain Group LLC IANA 3956 Created 2026-08-15T21:55:51Z 1 day before report Kit sig "Made with <3 By Hands" French PhaaS kit author Bot gate ASN + UA + Mobile check Server-side PHP · evades most scanners Exfil method Telegram bot (inferred) No MX records; standard for this kit Total domains 228 on 45.74.61.10 Full PhaaS platform Netflix IOCs 10 domains ntflx-france.com · netflix-clients.com · ... Prime IOCs 11 domains avisprimevideo-notification.com · ... Delivery IOCs 34 domains mondial-colisbe.com · livraison-* · ...
Live Evidence — Evasion Gate Dissection · Captured 2026-08-16

The screenshot below captures the deliberate controlled probe that mapped the gate's logic. By systematically varying User-Agent, Accept-Language, and Referer headers, the server's own response disclosed exactly which values it checks and what it outputs for each scenario. The gate's debug output — visible in the server response — reveals the full fingerprinting algorithm in one request.

This is an intentional OSINT technique: rather than attempting to access phishing content (which would cross into unauthorized territory), the investigation focused on fully characterising the anti-detection infrastructure — which is itself a primary threat intelligence finding.

netf-reintegration-definition.com/pages/ — GATE DISSECTION · EVASION INFRASTRUCTURE MAPPED ⚠ NETFLIX PHISHING
Screenshot: Netflix phishing evasion gate dissection

Gate response decoded: server echoes back the probed UA, the ASN resolution result, and the Mobile flag — revealing the three-check algorithm. Investigation focus was intentionally on infrastructure mapping rather than credential-harvesting interaction.

Live Infrastructure Status
Loading status…
Previous: Case 006 — FID Verlag Next: Case 008 — Fake Delivery Lead-Gen
SevinOS BLE Radar