A domain mimicking the Belgian postal service (bpost) anchors a 44-domain phishing cluster on a Seychelles bulletproof ASN with no registered abuse contact. A single reverse-IP pivot exposed the full platform: Belgian delivery, French parcel services, French highway toll (Ulys/SANEF), French health insurance, Netflix, and cross-border subscription fraud across Belgium, France, Poland, Spain, and Germany — all deployed in a coordinated Nov 2025 – Jan 2026 wave.
The investigation started with bpost-secure.com — a domain constructed to mimic bpost, the official Belgian national postal service (bpost.be). The suffix -secure is a deliberate smishing pattern: users receive an SMS claiming a parcel requires payment or identity verification, with a link to the lookalike domain. The word "secure" is injected to suppress suspicion about the unfamiliar URL.
WHOIS analysis confirmed the domain was registered via Spaceship, Inc. (IANA 3862) on 2025-11-21, with a TLS certificate issued by Let's Encrypt exactly one day later on 2025-11-22 — zero-day SSL deployment confirming immediate active deployment. Name servers: LAUNCH1.SPACESHIP.NET / LAUNCH2.SPACESHIP.NET. WHOIS contact data is fully redacted behind registrar privacy.
The domain resolves to 102.135.91.206 — a Frankfurt-hosted IP on AS208185. All HTTP/HTTPS connections time out silently, indicating a server-side IP allowlist that blocks automated and researcher traffic — the same network-layer evasion approach as Case 007 (69HOST), but implemented at the firewall rather than application level.
A single reverse-IP lookup on 102.135.91.206 via HackerTarget's passive DNS API returned 44 domains — the complete inventory of the platform sharing the same server. Brand analysis of the full domain list reveals a multi-country, multi-brand phishing operation covering five primary target languages and six distinct brand categories.
Three Plesk control panel subdomains are visible in the reverse-IP data: compassionate-hopper, pedantic-mclean, and sad-feistel — these are auto-generated container names from Plesk's virtual hosting provisioning. Their presence confirms the server runs Plesk with containerized virtual hosts — one per phishing domain — consistent with a kit operator managing a multi-campaign server through a commercial web hosting panel.
The cluster targets four core French/Belgian consumer service categories — the exact brands that Belgian (CCB/SafeOnWeb) and French (ANSSI/Cybermalveillance) authorities warn about most frequently in annual smishing advisories:
Belgian Postal — bpost: bpost-secure.com targets Belgian users under a parcel delivery pretext. Typical lure: "Votre colis ne peut pas être livré. Payez €1,99 pour réautoriser la livraison." Credit card details are harvested for downstream card fraud. bpost is the most impersonated brand in Belgian smishing statistics.
French Delivery — Mondial Relay: reprogcolis-mondial-relay.com directly impersonates Mondial Relay, the Franco-Belgian parcel point network used by millions of e-commerce buyers. espace-colis.com has been active since at least 2022 (22 CT-logged certificates) — a long-running delivery phishing domain now migrated onto the AS208185 bulletproof cluster. malivraison-suivi.com and info-expedition.com are generic French delivery lures deployable against any carrier.
French Highway Toll — Ulys (SANEF): fr-espace-ulys.com impersonates the Ulys toll badge account portal operated by SANEF (Société des Autoroutes du Nord et de l'Est de la France). badge-peage-fr.com is a generic toll badge lure. The French péage phishing vector exploits a legally enforceable government notice (ANTAI enforcement letters) — victims are conditioned to pay road charges without hesitation. ANSSI specifically flagged this campaign pattern in its 2024–2025 phishing advisories.
French Health Insurance: masante-connexion.com ("my health connection") has been active since October 2024 based on its 6 CT-logged certificates. Targets the French Assurance Maladie system under pretexts of healthcare reimbursements — harvesting Carte Vitale numbers and IBAN data.
The IP 102.135.91.206 belongs to AS208185, registered as Internet-Security-IPV4Mall / Internet-security-Moondc, country Seychelles (SC), physically routed through a Frankfurt, Germany data centre. RIPE NCC WHOIS returns the critical finding: "No abuse contact registered for 102.135.91.0 - 102.135.91.255."
This is a deliberate bulletproof configuration. Legitimate hosting providers are required under RIPE NCC policy to register an IRT (Incident Response Team) object with a valid abuse-mailbox address. Intentionally omitting it:
All management ports are also network-filtered: Plesk admin (8443), alternate (7080), and HTTP panel (8880) all time out — the operator has locked down the management surface while keeping DNS pointing to the server for campaign delivery. HTTP and HTTPS (80/443) also time out, indicating an IP allowlist that passes only victim traffic delivered via smishing links.
Cross-referencing WHOIS registration dates with Certificate Transparency log timestamps (crt.sh) reveals a coordinated Nov 2025 – Jan 2026 deployment wave. Domains were registered and TLS certificates were issued within hours of each other across consecutive days, confirming a single operator executing a planned multi-brand rollout.
The operator distributed registrations across five different registrars: Spaceship (Belgian entry domain), Dynadot (French health and delivery), Tucows (entire Polish cluster), OVH (French delivery), and Enom (Spanish). This multi-registrar strategy deliberately fragments the footprint — no single registrar can discover the full portfolio through one abuse complaint, and cross-registrar coordination is slow enough to give the operator months of active campaign time before cluster-wide takedown.
Multi-target reporting required: the ASN operator (AS208185 / RIPE NCC), Belgian CERT (CCB/SafeOnWeb) for the bpost smishing component, ANSSI for French targeting scope, registrar Spaceship for the Belgian entry domain, and EC3 for the multi-country multi-brand scope.
Reported to suspicious@safeonweb.be. bpost-secure.com directly targets Belgian citizens via parcel delivery smishing — the highest-volume phishing vector against Belgian mobile users. Full 44-domain cluster context and AS208185 bulletproof hosting details included.
Reported to abuse@ripe.net. AS208185 has deliberately omitted its IRT (Incident Response Team) abuse-mailbox object, violating RIPE NCC member policy. The /24 block 102.135.91.0/24 hosts 44 phishing domains with no abuse delivery endpoint. Requested IRT compliance enforcement or escalation to member services.
Reported to abuse@spaceship.com. bpost-secure.com registered via Spaceship on 2025-11-21 and SSL-deployed same day. Immediate Belgian postal service phishing confirmed via domain naming convention, CT log, and bulletproof hosting analysis. Requesting suspension under ICANN abuse policy.
Reported via https://www.cybermalveillance.gouv.fr/ for French-targeting domains: Ulys/SANEF toll phishing (fr-espace-ulys.com, badge-peage-fr.com), Mondial Relay (reprogcolis-mondial-relay.com), French health (masante-connexion.com). The péage/toll vector was specifically flagged in ANSSI's 2024–2025 phishing advisories.
Reported to ec3@europol.europa.eu. 44-domain platform targeting Belgium, France, Poland, Spain, Germany from Seychelles-registered bulletproof infrastructure. Coordinated Nov 2025 – Jan 2026 deployment wave and 5-registrar purchase pattern indicate an organised criminal group operating a cross-border PhaaS service.
Phase 1 — Entry domain identification: DNS resolution hunt targeting Belgian brand lookalike patterns (brand + hyphen + descriptor). bpost-secure.com returned a live A record on a non-Belgian IP.
Phase 2 — WHOIS + CT log: WHOIS confirmed Spaceship registration on 2025-11-21. crt.sh Certificate Transparency confirmed Let's Encrypt TLS on 2025-11-22 — zero-day deployment confirming the domain was immediately activated as a phishing asset.
Phase 3 — Reverse-IP pivot: HackerTarget passive DNS reverse lookup on 102.135.91.206 returned 44 co-hosted domains. Full list analysed by brand/language — revealing a 5-country, 6-brand platform from a single query.
Phase 4 — ASN investigation: RIPE NCC WHOIS on the /24 block confirmed AS208185 (Internet-Security-IPV4Mall, Seychelles) with explicit "No abuse contact registered" — confirming intentional bulletproof configuration. All ports confirmed network-filtered.
Phase 5 — Timeline reconstruction: WHOIS registration dates cross-referenced with crt.sh CT log cert timestamps across 13 key domains confirmed the coordinated deployment wave and identified the 5-registrar evasion strategy by correlating registrar names with domain language and target geography.
The RIPE NCC WHOIS response for 102.135.91.0/24 contains the explicit notice "No abuse contact registered for 102.135.91.0 - 102.135.91.255" — confirming AS208185 has deliberately omitted the IRT abuse-mailbox attribute required under RIPE NCC policy. This is not a missing field or administrative oversight: it is a calculated operational decision that renders all automated abuse complaint pipelines inoperable against this /24 block.
The highlighted line is the key finding: RIPE NCC explicitly outputs this notice when no IRT abuse-mailbox attribute exists for the queried netblock. The full WHOIS record confirms Seychelles (SC) country, AS208185, netname Internet-Security-IPV4Mall — all consistent with bulletproof hosting configured to evade accountability.
A single passive DNS reverse-IP query on 102.135.91.206 returned the complete inventory of 44 co-hosted domains. The colour-coded output below maps every domain to its brand category: Belgian bpost (red), French delivery/parcel (orange), French toll/highway (red), French health (cyan), Netflix (red), Polish brands (blue), Spanish subscription (purple), German (grey), and Plesk infrastructure containers (dim). Three Plesk auto-named virtual host subdomains confirm the server runs Plesk web hosting panel with containerised virtual hosts.
One passive API call. Zero active probing. The entire 44-domain phishing portfolio disclosed by the server's own DNS records. This is the primary technique of this investigation: reverse-IP pivoting from a single Belgian lookalike domain to a full multi-country platform in one query.