OSINT Portfolio / Case 009
P1 Critical · Belgian Smishing · Bulletproof Hosting · Multi-Country PhaaS

bpost-secure.com · 44-Domain BE/FR/PL/ES Cluster
AS208185 · No Abuse Contact Registered · Seychelles Bulletproof

A domain mimicking the Belgian postal service (bpost) anchors a 44-domain phishing cluster on a Seychelles bulletproof ASN with no registered abuse contact. A single reverse-IP pivot exposed the full platform: Belgian delivery, French parcel services, French highway toll (Ulys/SANEF), French health insurance, Netflix, and cross-border subscription fraud across Belgium, France, Poland, Spain, and Germany — all deployed in a coordinated Nov 2025 – Jan 2026 wave.

Belgian Smishing Bulletproof Hosting French Delivery Phishing Highway Toll Phishing Multi-Country PhaaS AS208185 · No Abuse Contact 44-Domain Cluster Passive OSINT · DNS + CT Logs
Entry Domainbpost-secure.com
Cluster IP102.135.91.206
Total Domains44
ASNAS208185 · Seychelles
Abuse ContactNONE REGISTERED
Deployment WaveNov 2025 – Jan 2026
Countries TargetedBE · FR · PL · ES · DE
StatusServer DOWN · 2026-08-18
● UPDATE — 2026-08-18
Server confirmed offline. As of 2026-08-18, IP 102.135.91.206 (AS208185) returns 100% packet loss and connection timeout on all ports. The server is null-routed or deprovisioned — not an IP allowlist (previous behaviour was TCP timeout in <1s; current behaviour is a 10-second hard timeout, consistent with upstream null-route). All 44 domains still resolve in DNS but the infrastructure behind them is dead. Likely outcome of the RIPE NCC IRT compliance report filed under Case 009, which exposed the deliberate omission of the abuse-mailbox object for netblock 102.135.91.0/24.
Finding 1 — Entry Domain: bpost-secure.com — Belgian Postal Service Lookalike

The investigation started with bpost-secure.com — a domain constructed to mimic bpost, the official Belgian national postal service (bpost.be). The suffix -secure is a deliberate smishing pattern: users receive an SMS claiming a parcel requires payment or identity verification, with a link to the lookalike domain. The word "secure" is injected to suppress suspicion about the unfamiliar URL.

WHOIS analysis confirmed the domain was registered via Spaceship, Inc. (IANA 3862) on 2025-11-21, with a TLS certificate issued by Let's Encrypt exactly one day later on 2025-11-22 — zero-day SSL deployment confirming immediate active deployment. Name servers: LAUNCH1.SPACESHIP.NET / LAUNCH2.SPACESHIP.NET. WHOIS contact data is fully redacted behind registrar privacy.

The domain resolves to 102.135.91.206 — a Frankfurt-hosted IP on AS208185. All HTTP/HTTPS connections time out silently, indicating a server-side IP allowlist that blocks automated and researcher traffic — the same network-layer evasion approach as Case 007 (69HOST), but implemented at the firewall rather than application level.

Domain bpost-secure.com Imitates bpost.be ← official Belgian postal service Registered 2025-11-21 ← via Spaceship, Inc. (IANA 3862) SSL cert 2025-11-22 ← Let's Encrypt · 1 day after reg = immediate deploy IP 102.135.91.206 ← AS208185 · Frankfurt DE (Seychelles routing) NS LAUNCH1.SPACESHIP.NET HTTP :80 TIMEOUT ← network-level IP filter HTTPS :443 TIMEOUT ← all web traffic filtered server-side WHOIS data REDACTED ← registrar privacy
Belgian citizen targeting: bpost handles 2.5+ million parcels per day in Belgium. SMS phishing under the "your parcel cannot be delivered — pay €1.99" pretext is the #1 smishing vector against Belgian mobile users, with bpost as the most impersonated brand. Zero-day SSL deployment on bulletproof infrastructure is the hallmark of a professional smishing kit rollout.
Finding 2 — Reverse-IP Pivot: 44-Domain Multi-Country Phishing Cluster

A single reverse-IP lookup on 102.135.91.206 via HackerTarget's passive DNS API returned 44 domains — the complete inventory of the platform sharing the same server. Brand analysis of the full domain list reveals a multi-country, multi-brand phishing operation covering five primary target languages and six distinct brand categories.

Three Plesk control panel subdomains are visible in the reverse-IP data: compassionate-hopper, pedantic-mclean, and sad-feistel — these are auto-generated container names from Plesk's virtual hosting provisioning. Their presence confirms the server runs Plesk with containerized virtual hosts — one per phishing domain — consistent with a kit operator managing a multi-campaign server through a commercial web hosting panel.

French Delivery / Parcel
7
Subscription / Renewal
6
Polish Multi-Brand
4
French Toll / Highway
3
Spanish Subscription
2
Netflix
2
German Insurance / Land
2
Belgian Post (bpost)
1
French Health Insurance
1
Plesk infra / misc
16
bpost-secure.com ← Belgian bpost lookalike espace-colis.com ← French parcel space (22 SSL certs since 2022) malivraison-suivi.com ← "my delivery tracking" info-expedition.com ← shipment information reprogcolis-mondial-relay.com ← Mondial Relay brand phishing distributionautomatique.info ← automatic distribution badge-peage-fr.com ← French highway toll badge fr-espace-ulys.com ← Ulys (SANEF highway group) phishing renouvellement-en-ligne.com ← online renewal masante-connexion.com ← French health insurance netflx-account.com ← Netflix account ntflx-help.com ← Netflix help akcja-czlonkowstwa.net ← Polish: "membership action" aktualizacja-dsney.net ← Polish: Disney "update" pomoc-techniczna.net ← Polish: "technical support" regler-mon-abonnement.com ← "pay my subscription" abonnement-mon-compte.com ← subscription account mi-suscripcionpagar.com ← Spanish: subscription payment renovacion-sub-net.com ← Spanish: subscription renewal versichern-absichern.com ← German: insurance parzellenerneuerung.net ← German: land plot renewal compassionate-hopper.102-135-91-206.plesk.page ← Plesk auto-named container pedantic-mclean.102-135-91-206.plesk.page sad-feistel.102-135-91-206.plesk.page
Finding 3 — Belgian & French Brand Analysis: Postal, Toll, Health, Parcel

The cluster targets four core French/Belgian consumer service categories — the exact brands that Belgian (CCB/SafeOnWeb) and French (ANSSI/Cybermalveillance) authorities warn about most frequently in annual smishing advisories:

Belgian Postal — bpost: bpost-secure.com targets Belgian users under a parcel delivery pretext. Typical lure: "Votre colis ne peut pas être livré. Payez €1,99 pour réautoriser la livraison." Credit card details are harvested for downstream card fraud. bpost is the most impersonated brand in Belgian smishing statistics.

French Delivery — Mondial Relay: reprogcolis-mondial-relay.com directly impersonates Mondial Relay, the Franco-Belgian parcel point network used by millions of e-commerce buyers. espace-colis.com has been active since at least 2022 (22 CT-logged certificates) — a long-running delivery phishing domain now migrated onto the AS208185 bulletproof cluster. malivraison-suivi.com and info-expedition.com are generic French delivery lures deployable against any carrier.

French Highway Toll — Ulys (SANEF): fr-espace-ulys.com impersonates the Ulys toll badge account portal operated by SANEF (Société des Autoroutes du Nord et de l'Est de la France). badge-peage-fr.com is a generic toll badge lure. The French péage phishing vector exploits a legally enforceable government notice (ANTAI enforcement letters) — victims are conditioned to pay road charges without hesitation. ANSSI specifically flagged this campaign pattern in its 2024–2025 phishing advisories.

French Health Insurance: masante-connexion.com ("my health connection") has been active since October 2024 based on its 6 CT-logged certificates. Targets the French Assurance Maladie system under pretexts of healthcare reimbursements — harvesting Carte Vitale numbers and IBAN data.

espace-colis.com is a long-running asset. With 22 CT-logged SSL certificates dating back to December 2022, this domain has been used in French delivery phishing for over 3 years. Its migration onto AS208185 in November 2025 suggests the same operator has been running French delivery phishing for years and has now consolidated onto bulletproof infrastructure for durability.
Finding 4 — AS208185: Bulletproof Hosting with No Registered Abuse Contact

The IP 102.135.91.206 belongs to AS208185, registered as Internet-Security-IPV4Mall / Internet-security-Moondc, country Seychelles (SC), physically routed through a Frankfurt, Germany data centre. RIPE NCC WHOIS returns the critical finding: "No abuse contact registered for 102.135.91.0 - 102.135.91.255."

This is a deliberate bulletproof configuration. Legitimate hosting providers are required under RIPE NCC policy to register an IRT (Incident Response Team) object with a valid abuse-mailbox address. Intentionally omitting it:

  • Breaks automated abuse reporting pipelines used by CERT teams, browser safe-browsing systems, and registrars
  • Removes any 24-hour response obligation — abuse complaints fail silently with no delivery endpoint
  • Leaves the entire /24 (256 IPs) operating with no compliance accountability in the RIPE NCC member registry

All management ports are also network-filtered: Plesk admin (8443), alternate (7080), and HTTP panel (8880) all time out — the operator has locked down the management surface while keeping DNS pointing to the server for campaign delivery. HTTP and HTTPS (80/443) also time out, indicating an IP allowlist that passes only victim traffic delivered via smishing links.

inetnum 102.135.91.0 - 102.135.91.255 netname Internet-Security-IPV4Mall country SC ← Seychelles registration origin AS208185 descr Internet-security-Moondc abuse NO ABUSE CONTACT REGISTERED ← violates RIPE NCC policy geo Frankfurt, Germany ← physical hosting location :8443 TIMEOUT ← Plesk admin panel blocked :8880 TIMEOUT :80/:443 TIMEOUT ← web traffic IP allowlist only compassionate-hopper.102-135-91-206.plesk.page pedantic-mclean.102-135-91-206.plesk.page sad-feistel.102-135-91-206.plesk.page
No abuse contact is a purposeful bulletproof signal. RIPE NCC requires IRT objects for all registered netblocks. An operator running 44 phishing domains who has deliberately omitted their abuse-mailbox is not making an oversight — it is an operational decision to sever all inbound accountability channels. This is the same approach used by classic bulletproof hosters (Aeza, ChVPS, OMEGATECH/AS202412 from Case 001), engineered to outlast takedown complaint cycles.
Finding 5 — Deployment Timeline & Multi-Registrar Evasion

Cross-referencing WHOIS registration dates with Certificate Transparency log timestamps (crt.sh) reveals a coordinated Nov 2025 – Jan 2026 deployment wave. Domains were registered and TLS certificates were issued within hours of each other across consecutive days, confirming a single operator executing a planned multi-brand rollout.

The operator distributed registrations across five different registrars: Spaceship (Belgian entry domain), Dynadot (French health and delivery), Tucows (entire Polish cluster), OVH (French delivery), and Enom (Spanish). This multi-registrar strategy deliberately fragments the footprint — no single registrar can discover the full portfolio through one abuse complaint, and cross-registrar coordination is slow enough to give the operator months of active campaign time before cluster-wide takedown.

2025-11-07 reprogcolis-mondial-relay.com ← Mondial Relay · registrar unknown 2025-11-08 fr-espace-ulys.com ← Ulys toll · Wild West Domains 2025-11-10 badge-peage-fr.com ← French toll · Tucows · cert same day 2025-11-12 espace-colis.com ← OVH · domain active since 2022 (repurposed) 2025-11-18 renovacion-sub-net.com ← Spanish · Enom 2025-11-21 bpost-secure.com ← Belgian bpost · Spaceship · cert 2025-11-22 2025-11-30 aktualizacja-dsney.net ← Polish Disney · Tucows 2025-12-03 parzellenerneuerung.net ← German · Tucows 2025-12-06 versichern-absichern.com ← German insurance · OVH 2025-12-10 akcja-czlonkowstwa.net ← Polish membership · Tucows · cert same day 2025-12-12 pomoc-techniczna.net ← Polish tech support · Tucows 2025-12-23 malivraison-suivi.com ← French delivery · Dynadot 2026-01-03 masante-connexion.com ← French health · Dynadot · latest cert 2026-01-03 Registrar evasion split: Spaceship → Belgian entry domain Dynadot → French health + delivery Tucows → entire Polish cluster (4 domains) OVH → French delivery repurpose Enom → Spanish subscription
Reporting Actions Taken

Multi-target reporting required: the ASN operator (AS208185 / RIPE NCC), Belgian CERT (CCB/SafeOnWeb) for the bpost smishing component, ANSSI for French targeting scope, registrar Spaceship for the Belgian entry domain, and EC3 for the multi-country multi-brand scope.

CCB / Centre for Cybersecurity Belgium — SafeOnWeb

Reported to suspicious@safeonweb.be. bpost-secure.com directly targets Belgian citizens via parcel delivery smishing — the highest-volume phishing vector against Belgian mobile users. Full 44-domain cluster context and AS208185 bulletproof hosting details included.

RIPE NCC — Missing Abuse Contact Enforcement

Reported to abuse@ripe.net. AS208185 has deliberately omitted its IRT (Incident Response Team) abuse-mailbox object, violating RIPE NCC member policy. The /24 block 102.135.91.0/24 hosts 44 phishing domains with no abuse delivery endpoint. Requested IRT compliance enforcement or escalation to member services.

Spaceship, Inc. — Belgian Entry Domain Registrar

Reported to abuse@spaceship.com. bpost-secure.com registered via Spaceship on 2025-11-21 and SSL-deployed same day. Immediate Belgian postal service phishing confirmed via domain naming convention, CT log, and bulletproof hosting analysis. Requesting suspension under ICANN abuse policy.

ANSSI — French National Cybersecurity Agency

Reported via https://www.cybermalveillance.gouv.fr/ for French-targeting domains: Ulys/SANEF toll phishing (fr-espace-ulys.com, badge-peage-fr.com), Mondial Relay (reprogcolis-mondial-relay.com), French health (masante-connexion.com). The péage/toll vector was specifically flagged in ANSSI's 2024–2025 phishing advisories.

Europol EC3 — Multi-Country PhaaS

Reported to ec3@europol.europa.eu. 44-domain platform targeting Belgium, France, Poland, Spain, Germany from Seychelles-registered bulletproof infrastructure. Coordinated Nov 2025 – Jan 2026 deployment wave and 5-registrar purchase pattern indicate an organised criminal group operating a cross-border PhaaS service.

Method — Full Cluster from One Belgian Lookalike Domain

Phase 1 — Entry domain identification: DNS resolution hunt targeting Belgian brand lookalike patterns (brand + hyphen + descriptor). bpost-secure.com returned a live A record on a non-Belgian IP.

Phase 2 — WHOIS + CT log: WHOIS confirmed Spaceship registration on 2025-11-21. crt.sh Certificate Transparency confirmed Let's Encrypt TLS on 2025-11-22 — zero-day deployment confirming the domain was immediately activated as a phishing asset.

Phase 3 — Reverse-IP pivot: HackerTarget passive DNS reverse lookup on 102.135.91.206 returned 44 co-hosted domains. Full list analysed by brand/language — revealing a 5-country, 6-brand platform from a single query.

Phase 4 — ASN investigation: RIPE NCC WHOIS on the /24 block confirmed AS208185 (Internet-Security-IPV4Mall, Seychelles) with explicit "No abuse contact registered" — confirming intentional bulletproof configuration. All ports confirmed network-filtered.

Phase 5 — Timeline reconstruction: WHOIS registration dates cross-referenced with crt.sh CT log cert timestamps across 13 key domains confirmed the coordinated deployment wave and identified the 5-registrar evasion strategy by correlating registrar names with domain language and target geography.

IOC Table — Key Indicators
Cluster IP 102.135.91.206 AS208185 · Seychelles · Frankfurt DE ASN AS208185 Internet-Security-IPV4Mall Netblock 102.135.91.0/24 No abuse contact registered Belgian entry bpost-secure.com reg 2025-11-21 via Spaceship Total domains 44 on 102.135.91.206 French delivery espace-colis.com 22 certs since 2022 French delivery malivraison-suivi.com French delivery reprogcolis-mondial-relay.com Mondial Relay brand French toll fr-espace-ulys.com SANEF Ulys brand French toll badge-peage-fr.com French health masante-connexion.com active since Oct 2024 Netflix netflx-account.com Netflix ntflx-help.com Polish membership akcja-czlonkowstwa.net Polish Disney aktualizacja-dsney.net Spanish mi-suscripcionpagar.com Registrars Spaceship · Dynadot · Tucows · OVH · Enom
Evidence 1 — RIPE NCC WHOIS · "No Abuse Contact Registered" · Captured 2026-08-16

The RIPE NCC WHOIS response for 102.135.91.0/24 contains the explicit notice "No abuse contact registered for 102.135.91.0 - 102.135.91.255" — confirming AS208185 has deliberately omitted the IRT abuse-mailbox attribute required under RIPE NCC policy. This is not a missing field or administrative oversight: it is a calculated operational decision that renders all automated abuse complaint pipelines inoperable against this /24 block.

whois 102.135.91.206 — RIPE NCC — AS208185 ABUSE CONTACT ABSENT ⚠ NO IRT OBJECT
RIPE NCC WHOIS showing No abuse contact registered for AS208185

The highlighted line is the key finding: RIPE NCC explicitly outputs this notice when no IRT abuse-mailbox attribute exists for the queried netblock. The full WHOIS record confirms Seychelles (SC) country, AS208185, netname Internet-Security-IPV4Mall — all consistent with bulletproof hosting configured to evade accountability.

Evidence 2 — HackerTarget Reverse IP · 44-Domain Cluster · Captured 2026-08-16

A single passive DNS reverse-IP query on 102.135.91.206 returned the complete inventory of 44 co-hosted domains. The colour-coded output below maps every domain to its brand category: Belgian bpost (red), French delivery/parcel (orange), French toll/highway (red), French health (cyan), Netflix (red), Polish brands (blue), Spanish subscription (purple), German (grey), and Plesk infrastructure containers (dim). Three Plesk auto-named virtual host subdomains confirm the server runs Plesk web hosting panel with containerised virtual hosts.

hackertarget.com/reverseiplookup/ — 102.135.91.206 — 44 DOMAINS — AS208185 ⚠ PHISHING CLUSTER
HackerTarget reverse IP showing 44 phishing domains on AS208185

One passive API call. Zero active probing. The entire 44-domain phishing portfolio disclosed by the server's own DNS records. This is the primary technique of this investigation: reverse-IP pivoting from a single Belgian lookalike domain to a full multi-country platform in one query.

Live Infrastructure Status
UPDATE 2026-08-18 — Server offline confirmed. 100% packet loss to 102.135.91.206. HTTP timeout on ports 80 and 443. Hard 10-second timeout differs from previous IP-allowlist behaviour (which dropped datacenter connections in <1s). This confirms upstream null-route or deprovisioning, not selective filtering. Infrastructure is dead. Previous note (2026-08-16): connection timeouts were identified as IP allowlist behaviour, not takedown. That assessment is now superseded.
Loading status…
Previous: Case 008 — vorortliefernsender.de Next: Case 010 — basicmodoralo.com
SevinOS BLE Radar