P1 Critical
PhaaS Cluster
Multi-Brand
EU Banking
499 Domains
SK Gateway Abuse
499-Domain EU PhaaS Cluster —
ING · DKB · Belfius Belgium · CJIB · plesk2.living-bots.net
A single Frankfurt Plesk server at 91.218.65.223 (AS44486, Oliver Horscht t/a SYNLINQ)
hosts 499 phishing domains impersonating ING Bank, DKB, Belfius Belgium, ICS Cards,
Klarna, CJIB (Dutch Government), isybank Italy, EasyBank Austria, Commerzbank, DHL, Spotify and PayPal.
Entry point: spotify-accounts-login.callora.cz — a live French-language Spotify credential
phish deployed via a Slovak gateway domain. Infrastructure uses Docker container
auto-naming for automated kit deployment. All gateway domains route through Websupport.sk nameservers.
91.218.65.223
AS44486 SYNLINQ
plesk2.living-bots.net
callora.cz
Websupport.sk
ING Bank NL
Belfius BE
DKB DE
CJIB NL Gov
Frankfurt DE
Server IP91.218.65.223
ASNAS44486 SYNLINQ
Hostnameplesk2.living-bots.net
Phishing Domains499+
Brands Targeted12+
Countries TargetedNL BE DE AT IT SE
Entry Domaincallora.cz
Discovered2026-08-17
● UPDATE — 2026-08-19 · NCSC-NL Active — Ticket #737568 — 2 Exchanges
NCSC-NL engaged — 2 PGP-signed exchanges. Ticket #737568 confirmed. Exchange 1: receipt acknowledged (SHA512). Exchange 2: NCSC requested direct contact with the German hosting provider (SYNLINQ, AS44486, abuse@living-bots.net) and DNS registrar (Websupport.sk, abuse@websupport.sk) before escalating internally. Abuse reports dispatched to both on 2026-08-19 per NCSC guidance. NCSC to be updated with outcome.
ⓘ Evidence note: Screenshots are cropped to remove the PGP cryptographic signature blocks (base64 ciphertext) — those contain no intelligence value and add visual noise. The -----BEGIN PGP SIGNED MESSAGE----- header and hash type (SHA512 / SHA256) are retained in each image as proof of cryptographic signing. Full signatures are on file.
● Exchange 1 — Receipt Confirmed · SHA512
cert@ncsc.nl · 2026-08-19 08:58 · "We will get back to you within two working days."
● Exchange 2 — Action Tasked · SHA256
cert@ncsc.nl · 2026-08-19 10:28 · Requested direct contact with SYNLINQ + Websupport.sk.
Entry domain spotify-accounts-login.callora.cz resolved to 91.218.65.223.
A HackerTarget reverse-IP lookup on that address returned 499 co-hosted domains, all served
from the same Plesk node plesk2.living-bots.net. The domain list contains systematic
brand-impersonation naming targeting at least 12 financial institutions and services across six EU countries.
$ curl "https://api.hackertarget.com/reverseiplookup/?q=91.218.65.223" | wc -l
499
$ host 91.218.65.223
223.65.218.91.in-addr.arpa = plesk2.living-bots.net.
ING Bank (NL) 76
DKB (DE) 16
Belfius Belgium 6
ICS Cards (NL) 6
Klarna (EU) 3
Commerzbank (DE) 2
DHL Logistics 2
Spotify 2
EasyBank (AT) 1
CJIB (NL Gov) 1
isybank Italy 1
Zoho 1
CJIB (Centraal Justitieel Incassobureau) is the Dutch government's Central Fine Collection Agency.
cjib-inloggen.spolbyt-group.com impersonates a national government debt collection authority.
This is among the highest-risk phishing vectors: victims believe they owe fines and pay fraudsters.
The reverse-IP domain list contains two categories: brand-impersonation domains (e.g. accont-banking-belfuise-be.91-218-65-223.plesk.page)
and a second set with Docker container naming convention adjective-scientist names:
admiring-bohr, condescending-euler, dazzling-mahavira, adoring-merkle, etc.
These are Plesk-generated subdomains that correspond to running Docker containers on the phishing server.
The naming convention is the Docker Engine default random name generator — this confirms the operator
is deploying new phishing kits as Docker containers and Plesk auto-creates a subdomain for each.
admiring-bohr.91-218-65-223.plesk.page
admiring-kapitsa.91-218-65-223.plesk.page
admiring-pasteur.91-218-65-223.plesk.page
adoring-merkle.91-218-65-223.plesk.page
condescending-euler.91-218-65-223.plesk.page
condescending-hamilton.91-218-65-223.plesk.page
dazzling-hugle.91-218-65-223.plesk.page
dazzling-mahavira.91-218-65-223.plesk.page
goofy-elion.91-218-65-223.plesk.page
The co-existence of named containers as Plesk subdomains alongside brand-specific phishing domains on the
same IP indicates a shared-infrastructure PhaaS model: the operator sells or rents kit instances per brand,
each running in its own Docker container with a Plesk-provisioned subdomain.
The phishing server is reached not only via the wildcard *.91-218-65-223.plesk.page Plesk addresses
but also through four externally registered domains, all with Websupport.sk nameservers and A records
pointing to 91.218.65.223. This layer provides legitimacy — a branded domain looks less suspicious than a
Plesk IP wildcard. The operator either compromised Websupport.sk-hosted accounts or created them specifically for this operation.
callora.cz
registrant: MG REAL s.r.o. / Mária Gajanová, Liptovský Mikuláš, SK
created: 2026-01-20 registrar: REG-WEBSUPPORT
nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk
A record: 91.218.65.223 (phish) + 185.158.133.1 (legit SK web)
ABUSED SUBDOMAIN: spotify-accounts-login.callora.cz → 91.218.65.223
mojesvetielko.sk
registrant: WS-2563304 (Websupport customer)
nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk
PHISHING: spotify-login-com.mojesvetielko.sk
PHISHING: login-isybank-it.mojesvetielko.sk
stastna-hvezda.com
created: 2020-07-01 registrar: Gransy/regtons.com
nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk
PHISHING: easybank-banking-login.stastna-hvezda.com
spolbyt-group.com
created: 2022-09-12 registrar: Gransy/regtons.com
nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk
PHISHING: klarna-login.spolbyt-group.com
PHISHING: cjib-inloggen.spolbyt-group.com (Dutch GOVERNMENT impersonation)
callora.cz root domain is a legitimate Slovak AI receptionist service (CALLORA).
The phishing subdomain was added to the domain's DNS by an attacker with access to the
Websupport.sk DNS management panel. Mária Gajanová / MG REAL s.r.o. is a victim of account compromise,
not an operator. Websupport.sk must be notified to remove the fraudulent subdomain A records.
spotify-accounts-login.callora.cz served a French-language Spotify login credential phish
(HTTP 200, 5200 bytes) during this investigation. The page replicated the Spotify login UI and posted
credentials via process.php (302 redirect after submission). Server identity:
nginx + PleskLin (x-powered-by: PleskLin), last-modified: 2026-06-24.
The page was live for at least 7 weeks.
$ curl -sI "https://spotify-accounts-login.callora.cz/"
HTTP/2 200
server: nginx
content-type: text/html
content-length: 5200
x-powered-by: PleskLin
last-modified: Wed, 24 Jun 2026 15:20:28 GMT
Language: French (targets French-speaking Spotify users)
Form action: process.php (relative POST)
POST fields: email, password
Response: 302 redirect (kill-chain continues server-side)
$ curl -sI "https://spotify-accounts-login.callora.cz/"
HTTP/2 200 content-length: 5200
Kit rotation is standard PhaaS operational security. The content was replaced with a Plesk default page
after investigation activity. The subdomain remains active and can host a new kit immediately.
The infrastructure persists even when specific kits are cycled.
The phishing server sits in AS44486, operated by Oliver Horscht trading as SYNLINQ,
registered address Hanauer Landstrasse 328-330, 60314 Frankfurt, Germany.
The abuse contact for AS44486 in RIPE is abuse@living-bots.net, operated by the same entity.
This is commercial shared Plesk hosting, not a purpose-built bulletproof provider — but 499 phishing
domains on one node indicates either chronic abuse report failure or insufficient abuse processing.
ASN: AS44486
Holder: Oliver Horscht is trading as "SYNLINQ"
Address: Hanauer Landstrasse 328-330, 60314 Frankfurt, DE
Abuse: abuse@living-bots.net
PTR: plesk2.living-bots.net
$ curl -sI "http://91.218.65.223/"
Server: nginx
Content-Length: 4839
Last-Modified: Tue, 18 Feb 2020 19:35:21 GMT
$ chromium "https://accont-banking-belfuise-be.91-218-65-223.plesk.page/"
ERR_SSL_PROTOCOL_ERROR (HSTS policy enforced)
→ "website sent back unusual and incorrect credentials"
→ HSTS preloaded during active phishing = prior valid TLS certificate was deployed
$ whois -h whois.ripe.net AS44486 | grep "abuse-c"
abuse-c: AR46113-RIPE → email: abuse@living-bots.net
MITRE ATT&CK mapping: T1583.001 (Acquire Domains — mass registration of phishing variants),
T1583.003 (Virtual Private Server — Plesk commercial hosting), T1036.005 (Match Legitimate Name or Location —
brand typosquatting), T1056.003 (Web Portal Capture — credential form exfil),
T1071.001 (Web Protocols — HTTP/S C2), T1078.004 (Valid Accounts: Cloud Accounts —
Websupport.sk account compromise for DNS pivot).
Reporting Targets
abuse@living-bots.net / SYNLINQ (AS44486) ✓ Sent 2026-08-19
abuse@living-bots.net
Primary hosting abuse: 499 phishing domains on single Plesk node. Request immediate suspension of 91.218.65.223 customer account. Reported per NCSC-NL #737568 guidance.
Websupport.sk (Slovak registrar/host) ✓ Sent 2026-08-19
abuse@websupport.sk
DNS abuse: fraudulent A records on callora.cz, mojesvetielko.sk, stastna-hvezda.com, spolbyt-group.com pointing to phishing server. Remove subdomain records immediately. Reported per NCSC-NL #737568 guidance.
CCB / SafeOnWeb Belgium ✓ Sent 2026-08-19
suspicious@safeonweb.be
Belfius Belgium impersonation across 6+ domains on EU server. Belgian financial institution targeting.
CJIB (Centraal Justitieel Incassobureau) Security
security@cjib.nl
Government agency impersonation: cjib-inloggen.spolbyt-group.com. Victims pay fake fines to criminals.
NCSC Netherlands ✓ ACTIVE — 3 Exchanges
cert@ncsc.nl · Ticket #737568 · PGP-signed (SHA256/SHA512) · 2026-08-19
Multi-Dutch-brand PhaaS: ING Bank, ICS Cards, CJIB government impersonation, DHL. Exchange 1: Initial report sent to security@ncsc.nl 2026-08-19. Exchange 2: PGP-signed receipt confirmed (cert@ncsc.nl, ticket #737568, SHA512). Exchange 3: NCSC requested direct hosting + registrar contact before escalating. Abuse reports confirmed sent to SYNLINQ (abuse@living-bots.net) and Websupport.sk (abuse@websupport.sk) 2026-08-19. NCSC notified of action taken. Awaiting SYNLINQ/Websupport response.
RIPE NCC Abuse (AS44486)
abuse@ripe.net
AS44486 abuse contact failure: 499 phishing domains hosted, indicating systemic abuse processing failure.
BSI Germany (Federal Office for Information Security) ✓ Sent 2026-08-19
buerger-cert@bsi.bund.de
German-language report: Frankfurt AS44486 hosting 499-domain multi-EU PhaaS. DKB (16 domains) and Commerzbank targeted from German network. Full infrastructure details including Docker deployment method and HSTS evidence.
Belfius Bank Security
phishing@belfius.be
Brand impersonation across 6 phishing domains. Belgian retail bank customer credential theft.
EC3 / Europol ✓ Sent 2026-08-19
ec3@europol.europa.eu
Cross-border EU PhaaS: 6 countries targeted (NL, BE, DE, AT, IT, SE), 499 domains, Frankfurt infrastructure, MITRE ATT&CK mapped.
Investigation Method
01
Target acquisition: scam_hunter.py returned spotify-accounts-login.callora.cz as a phishing hit from PhishTank. HTTP HEAD confirmed live (200 OK, 5200 bytes, PleskLin).
02
DNS resolution: dig callora.cz returned two A records: 185.158.133.1 (legitimate SK web) and 91.218.65.223 (phishing server). The phishing subdomain resolves only to 91.218.65.223.
03
WHOIS: callora.cz registered 2026-01-20 via Websupport.sk, MG REAL s.r.o., Liptovský Mikuláš, Slovakia. Nameservers: ns1-3.websupport.sk. Root domain is a legitimate AI receptionist company.
04
Reverse-IP pivot: HackerTarget reverse IP on 91.218.65.223 returned 499 co-hosted domains. File saved to /tmp/osint-scratchpad/014-reverseip.txt for analysis.
05
Brand analysis: Parsed 499-domain list for brand keywords. Confirmed multi-country targeting: ING (NL), DKB/Commerzbank (DE), Belfius (BE), ICS Cards (NL), Klarna (SE), EasyBank (AT), isybank (IT), CJIB Dutch gov, DHL, Spotify, Zoho, PayPal.
06
Docker pattern identification: Second category of subdomains: adjective-scientist naming (admiring-bohr, condescending-euler). Confirmed Docker Engine default name generator. Each = one running container with a Plesk-provisioned subdomain.
07
Gateway domain pivot: Cross-referenced non-*.plesk.page domains in list. Found callora.cz, mojesvetielko.sk, stastna-hvezda.com, spolbyt-group.com — all Websupport.sk nameservers, all resolving to 91.218.65.223. Each carries 1-3 phishing subdomains including Dutch CJIB government impersonation.
08
ASN investigation: RIPE WHOIS on AS44486: Oliver Horscht t/a SYNLINQ, Frankfurt. Abuse contact: abuse@living-bots.net. PTR on 91.218.65.223 = plesk2.living-bots.net confirms this is a commercial Plesk node.
09
HSTS evidence: I probed accont-banking-belfuise-be.91-218-65-223.plesk.page via Chrome. HSTS enforcement with invalid certificate confirms prior valid HTTPS deployment — the phishing kit previously ran with a Let's Encrypt certificate, now rotated/expired.
10
Live HTTP probes: Most *.plesk.page domains return Plesk default page (kit rotation). HTTPS probes: HTTP 303 redirects from Belfius domains (SSL cert now mismatched, triggering HSTS error in browser). Plesk default pages return 5200 bytes consistently — infrastructure is live, kits are rotated.
IOC Table
| Type | Indicator | Context |
| IP | 91.218.65.223 | Phishing server, AS44486 synlinq.de Frankfurt DE |
| ASN | AS44486 | Oliver Horscht t/a SYNLINQ, Hanauer Landstrasse 328-330, 60314 Frankfurt |
| HOST | plesk2.living-bots.net | PTR record for 91.218.65.223 — Plesk node hostname |
| DOMAIN | spotify-accounts-login.callora.cz | Entry point, French Spotify credential phish (live 54 days) |
| DOMAIN | callora.cz | Legitimate SK domain, Websupport.sk, DNS abused to point to phish server |
| DOMAIN | cjib-inloggen.spolbyt-group.com | CJIB Dutch Government impersonation |
| DOMAIN | klarna-login.spolbyt-group.com | Klarna credential phish |
| DOMAIN | spolbyt-group.com | Gateway domain, Websupport.sk NS, Gransy registrar (2022) |
| DOMAIN | easybank-banking-login.stastna-hvezda.com | EasyBank Austria credential phish |
| DOMAIN | stastna-hvezda.com | Gateway domain, Websupport.sk NS, Gransy registrar (2020) |
| DOMAIN | spotify-login-com.mojesvetielko.sk | Secondary Spotify phish |
| DOMAIN | login-isybank-it.mojesvetielko.sk | isybank Italy credential phish |
| DOMAIN | mojesvetielko.sk | Gateway domain, Websupport.sk NS |
| DOMAIN | klarnaas.com | Klarna typosquat / credential phish |
| DOMAIN | klarrnas.com | Klarna typosquat / credential phish |
| EMAIL | abuse@living-bots.net | RIPE abuse contact for AS44486 |
| INFRA | 91.218.65.223/plesk.page wildcard | 499 phishing domains via *.91-218-65-223.plesk.page |
| PATTERN | admiring-* condescending-* dazzling-* adoring-* | Docker container auto-naming — automated kit deployment fingerprint |
| PATTERN | Websupport.sk NS on all gateway domains | Common Slovak registrar/host abused as phishing DNS layer |
Evidence — Infrastructure Analysis
Evidence 1 — Brand Distribution: 499-Domain Reverse-IP Pivot
HackerTarget reverse-IP pivot on 91.218.65.223 — 499 co-hosted phishing domains, brand breakdown, ASN info. Captured 2026-08-17.
Evidence 2 — Gateway Domain Network: Websupport.sk Abuse Pattern
Four Websupport.sk-nameserved gateway domains all resolving to 91.218.65.223 — HSTS cert mismatch as evidence of prior phishing operations. Captured 2026-08-17.
Evidence — Live Capture
Live Capture 1 — plesk2.living-bots.net Server Landing (91.218.65.223)
● PHISHING SERVER EXPOSED — Plesk server at 91.218.65.223, hosting 499 phishing domains. Captured 2026-08-17.
Live Capture 2 — callora.cz (Legitimate SK Company — Subdomain Abused)
● ABUSED HOST — callora.cz is a legitimate Slovak AI receptionist company. Operator added spotify-accounts-login.callora.cz A record pointing to 91.218.65.223. Captured 2026-08-17.
Live IOC Status
Loading...