sevinhub.comOSINT Portfolio › Case 014
Previous: Case 013 — MONOPOLY GUARD v3 PhaaS All Cases Next: Case 015 — Klarna Refund PhaaS
P1 Critical PhaaS Cluster Multi-Brand EU Banking 499 Domains SK Gateway Abuse

499-Domain EU PhaaS Cluster — ING · DKB · Belfius Belgium · CJIB · plesk2.living-bots.net

A single Frankfurt Plesk server at 91.218.65.223 (AS44486, Oliver Horscht t/a SYNLINQ) hosts 499 phishing domains impersonating ING Bank, DKB, Belfius Belgium, ICS Cards, Klarna, CJIB (Dutch Government), isybank Italy, EasyBank Austria, Commerzbank, DHL, Spotify and PayPal. Entry point: spotify-accounts-login.callora.cz — a live French-language Spotify credential phish deployed via a Slovak gateway domain. Infrastructure uses Docker container auto-naming for automated kit deployment. All gateway domains route through Websupport.sk nameservers.

91.218.65.223 AS44486 SYNLINQ plesk2.living-bots.net callora.cz Websupport.sk ING Bank NL Belfius BE DKB DE CJIB NL Gov Frankfurt DE
Server IP91.218.65.223
ASNAS44486 SYNLINQ
Hostnameplesk2.living-bots.net
Phishing Domains499+
Brands Targeted12+
Countries TargetedNL BE DE AT IT SE
Entry Domaincallora.cz
Discovered2026-08-17
● UPDATE — 2026-08-19 · NCSC-NL Active — Ticket #737568 — 2 Exchanges
NCSC-NL engaged — 2 PGP-signed exchanges. Ticket #737568 confirmed. Exchange 1: receipt acknowledged (SHA512). Exchange 2: NCSC requested direct contact with the German hosting provider (SYNLINQ, AS44486, abuse@living-bots.net) and DNS registrar (Websupport.sk, abuse@websupport.sk) before escalating internally. Abuse reports dispatched to both on 2026-08-19 per NCSC guidance. NCSC to be updated with outcome.
ⓘ Evidence note: Screenshots are cropped to remove the PGP cryptographic signature blocks (base64 ciphertext) — those contain no intelligence value and add visual noise. The -----BEGIN PGP SIGNED MESSAGE----- header and hash type (SHA512 / SHA256) are retained in each image as proof of cryptographic signing. Full signatures are on file.
● Exchange 1 — Receipt Confirmed · SHA512
NCSC-NL Exchange 1 — PGP-signed acknowledgment, ticket #737568
cert@ncsc.nl · 2026-08-19 08:58 · "We will get back to you within two working days."
● Exchange 2 — Action Tasked · SHA256
NCSC-NL Exchange 2 — PGP-signed follow-up requesting hosting/registrar contact
cert@ncsc.nl · 2026-08-19 10:28 · Requested direct contact with SYNLINQ + Websupport.sk.
Finding 1 — 499-Domain PhaaS Cluster via Reverse-IP Pivot

Entry domain spotify-accounts-login.callora.cz resolved to 91.218.65.223. A HackerTarget reverse-IP lookup on that address returned 499 co-hosted domains, all served from the same Plesk node plesk2.living-bots.net. The domain list contains systematic brand-impersonation naming targeting at least 12 financial institutions and services across six EU countries.

# Reverse-IP pivot $ curl "https://api.hackertarget.com/reverseiplookup/?q=91.218.65.223" | wc -l 499 # Confirmed hostname via PTR record $ host 91.218.65.223 223.65.218.91.in-addr.arpa = plesk2.living-bots.net. # Brand distribution (domains targeting each institution) ING Bank (NL) 76 ingbankee.* klant-omgeving.* loginen-banking-ag.* DKB (DE) 16 dkb-authentifizierung-dkdb-de.* dkbinge-banking-* Belfius Belgium 6 accont-banking-belfuise-be.* accontbankingbelfuius.* ICS Cards (NL) 6 formulier.ics.klantomgeving.* ics-klant-* Klarna (EU) 3 klarnaas.com klarrnas.com klarna-login.spolbyt-group.com Commerzbank (DE) 2 comrzocursing-blackwell.* DHL Logistics 2 account-dhll-international.* Spotify 2 spotify-accounts-login.callora.cz spotify-login-com.mojesvetielko.sk EasyBank (AT) 1 easybank-banking-login.stastna-hvezda.com CJIB (NL Gov) 1 cjib-inloggen.spolbyt-group.com isybank Italy 1 login-isybank-it.mojesvetielko.sk Zoho 1 billing-zoho-com.*
CJIB (Centraal Justitieel Incassobureau) is the Dutch government's Central Fine Collection Agency. cjib-inloggen.spolbyt-group.com impersonates a national government debt collection authority. This is among the highest-risk phishing vectors: victims believe they owe fines and pay fraudsters.
Finding 2 — Automated Docker-Based PhaaS Deployment

The reverse-IP domain list contains two categories: brand-impersonation domains (e.g. accont-banking-belfuise-be.91-218-65-223.plesk.page) and a second set with Docker container naming convention adjective-scientist names: admiring-bohr, condescending-euler, dazzling-mahavira, adoring-merkle, etc. These are Plesk-generated subdomains that correspond to running Docker containers on the phishing server. The naming convention is the Docker Engine default random name generator — this confirms the operator is deploying new phishing kits as Docker containers and Plesk auto-creates a subdomain for each.

# Docker container subdomains (auto-generated by Plesk per container) admiring-bohr.91-218-65-223.plesk.page # active container admiring-kapitsa.91-218-65-223.plesk.page # active container admiring-pasteur.91-218-65-223.plesk.page # active container adoring-merkle.91-218-65-223.plesk.page # active container condescending-euler.91-218-65-223.plesk.page # active container condescending-hamilton.91-218-65-223.plesk.page dazzling-hugle.91-218-65-223.plesk.page dazzling-mahavira.91-218-65-223.plesk.page goofy-elion.91-218-65-223.plesk.page # also: dkb-logins-apps.goofy-elion.91-218-65-223.plesk.page # Pattern: Docker name generator = adjective + famous scientist/mathematician # Each container = one PhaaS kit instance serving one brand's phishing pages # Operator spins new container → Plesk registers subdomain → kit is live in minutes

The co-existence of named containers as Plesk subdomains alongside brand-specific phishing domains on the same IP indicates a shared-infrastructure PhaaS model: the operator sells or rents kit instances per brand, each running in its own Docker container with a Plesk-provisioned subdomain.

Finding 3 — Websupport.sk Gateway Domain Network

The phishing server is reached not only via the wildcard *.91-218-65-223.plesk.page Plesk addresses but also through four externally registered domains, all with Websupport.sk nameservers and A records pointing to 91.218.65.223. This layer provides legitimacy — a branded domain looks less suspicious than a Plesk IP wildcard. The operator either compromised Websupport.sk-hosted accounts or created them specifically for this operation.

# All 4 gateway domains — Websupport.sk nameservers, all resolving to 91.218.65.223 callora.cz registrant: MG REAL s.r.o. / Mária Gajanová, Liptovský Mikuláš, SK created: 2026-01-20 registrar: REG-WEBSUPPORT nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk A record: 91.218.65.223 (phish) + 185.158.133.1 (legit SK web) ABUSED SUBDOMAIN: spotify-accounts-login.callora.cz → 91.218.65.223 mojesvetielko.sk registrant: WS-2563304 (Websupport customer) nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk PHISHING: spotify-login-com.mojesvetielko.sk PHISHING: login-isybank-it.mojesvetielko.sk stastna-hvezda.com created: 2020-07-01 registrar: Gransy/regtons.com nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk PHISHING: easybank-banking-login.stastna-hvezda.com spolbyt-group.com created: 2022-09-12 registrar: Gransy/regtons.com nserver: ns1.websupport.sk / ns2.websupport.sk / ns3.websupport.sk PHISHING: klarna-login.spolbyt-group.com PHISHING: cjib-inloggen.spolbyt-group.com (Dutch GOVERNMENT impersonation)
callora.cz root domain is a legitimate Slovak AI receptionist service (CALLORA). The phishing subdomain was added to the domain's DNS by an attacker with access to the Websupport.sk DNS management panel. Mária Gajanová / MG REAL s.r.o. is a victim of account compromise, not an operator. Websupport.sk must be notified to remove the fraudulent subdomain A records.
Finding 4 — Live Spotify Credential Phish (French Language)

spotify-accounts-login.callora.cz served a French-language Spotify login credential phish (HTTP 200, 5200 bytes) during this investigation. The page replicated the Spotify login UI and posted credentials via process.php (302 redirect after submission). Server identity: nginx + PleskLin (x-powered-by: PleskLin), last-modified: 2026-06-24. The page was live for at least 7 weeks.

# Live probe — initial investigation $ curl -sI "https://spotify-accounts-login.callora.cz/" HTTP/2 200 server: nginx content-type: text/html content-length: 5200 x-powered-by: PleskLin last-modified: Wed, 24 Jun 2026 15:20:28 GMT # Kit deployed 2026-06-24, first discovered 2026-08-17 (54 days live) # Page characteristics (static analysis) Language: French (targets French-speaking Spotify users) Form action: process.php (relative POST) POST fields: email, password Response: 302 redirect (kill-chain continues server-side) # Current status (post-investigation rotation) $ curl -sI "https://spotify-accounts-login.callora.cz/" HTTP/2 200 content-length: 5200 # Plesk default page (kit rotated out)
Kit rotation is standard PhaaS operational security. The content was replaced with a Plesk default page after investigation activity. The subdomain remains active and can host a new kit immediately. The infrastructure persists even when specific kits are cycled.
Finding 5 — AS44486 Infrastructure + HSTS Proof of Prior Operation

The phishing server sits in AS44486, operated by Oliver Horscht trading as SYNLINQ, registered address Hanauer Landstrasse 328-330, 60314 Frankfurt, Germany. The abuse contact for AS44486 in RIPE is abuse@living-bots.net, operated by the same entity. This is commercial shared Plesk hosting, not a purpose-built bulletproof provider — but 499 phishing domains on one node indicates either chronic abuse report failure or insufficient abuse processing.

# ASN registration ASN: AS44486 Holder: Oliver Horscht is trading as "SYNLINQ" Address: Hanauer Landstrasse 328-330, 60314 Frankfurt, DE Abuse: abuse@living-bots.net PTR: plesk2.living-bots.net # Server fingerprint $ curl -sI "http://91.218.65.223/" Server: nginx Content-Length: 4839 Last-Modified: Tue, 18 Feb 2020 19:35:21 GMT # Plesk default installed 2020 # HSTS evidence from Belfius phishing domains $ chromium "https://accont-banking-belfuise-be.91-218-65-223.plesk.page/" ERR_SSL_PROTOCOL_ERROR (HSTS policy enforced) → "website sent back unusual and incorrect credentials" → HSTS preloaded during active phishing = prior valid TLS certificate was deployed # Kits previously ran HTTPS with valid Let's Encrypt certs; cert expired/rotated post-takedown # RIPE abuse contact $ whois -h whois.ripe.net AS44486 | grep "abuse-c" abuse-c: AR46113-RIPE → email: abuse@living-bots.net

MITRE ATT&CK mapping: T1583.001 (Acquire Domains — mass registration of phishing variants), T1583.003 (Virtual Private Server — Plesk commercial hosting), T1036.005 (Match Legitimate Name or Location — brand typosquatting), T1056.003 (Web Portal Capture — credential form exfil), T1071.001 (Web Protocols — HTTP/S C2), T1078.004 (Valid Accounts: Cloud Accounts — Websupport.sk account compromise for DNS pivot).

Reporting Targets
abuse@living-bots.net / SYNLINQ (AS44486) ✓ Sent 2026-08-19
abuse@living-bots.net
Primary hosting abuse: 499 phishing domains on single Plesk node. Request immediate suspension of 91.218.65.223 customer account. Reported per NCSC-NL #737568 guidance.
Websupport.sk (Slovak registrar/host) ✓ Sent 2026-08-19
abuse@websupport.sk
DNS abuse: fraudulent A records on callora.cz, mojesvetielko.sk, stastna-hvezda.com, spolbyt-group.com pointing to phishing server. Remove subdomain records immediately. Reported per NCSC-NL #737568 guidance.
CCB / SafeOnWeb Belgium ✓ Sent 2026-08-19
suspicious@safeonweb.be
Belfius Belgium impersonation across 6+ domains on EU server. Belgian financial institution targeting.
CJIB (Centraal Justitieel Incassobureau) Security
security@cjib.nl
Government agency impersonation: cjib-inloggen.spolbyt-group.com. Victims pay fake fines to criminals.
NCSC Netherlands ✓ ACTIVE — 3 Exchanges
cert@ncsc.nl · Ticket #737568 · PGP-signed (SHA256/SHA512) · 2026-08-19
Multi-Dutch-brand PhaaS: ING Bank, ICS Cards, CJIB government impersonation, DHL. Exchange 1: Initial report sent to security@ncsc.nl 2026-08-19. Exchange 2: PGP-signed receipt confirmed (cert@ncsc.nl, ticket #737568, SHA512). Exchange 3: NCSC requested direct hosting + registrar contact before escalating. Abuse reports confirmed sent to SYNLINQ (abuse@living-bots.net) and Websupport.sk (abuse@websupport.sk) 2026-08-19. NCSC notified of action taken. Awaiting SYNLINQ/Websupport response.
RIPE NCC Abuse (AS44486)
abuse@ripe.net
AS44486 abuse contact failure: 499 phishing domains hosted, indicating systemic abuse processing failure.
BSI Germany (Federal Office for Information Security) ✓ Sent 2026-08-19
buerger-cert@bsi.bund.de
German-language report: Frankfurt AS44486 hosting 499-domain multi-EU PhaaS. DKB (16 domains) and Commerzbank targeted from German network. Full infrastructure details including Docker deployment method and HSTS evidence.
Belfius Bank Security
phishing@belfius.be
Brand impersonation across 6 phishing domains. Belgian retail bank customer credential theft.
EC3 / Europol ✓ Sent 2026-08-19
ec3@europol.europa.eu
Cross-border EU PhaaS: 6 countries targeted (NL, BE, DE, AT, IT, SE), 499 domains, Frankfurt infrastructure, MITRE ATT&CK mapped.
Investigation Method
01
Target acquisition: scam_hunter.py returned spotify-accounts-login.callora.cz as a phishing hit from PhishTank. HTTP HEAD confirmed live (200 OK, 5200 bytes, PleskLin).
02
DNS resolution: dig callora.cz returned two A records: 185.158.133.1 (legitimate SK web) and 91.218.65.223 (phishing server). The phishing subdomain resolves only to 91.218.65.223.
03
WHOIS: callora.cz registered 2026-01-20 via Websupport.sk, MG REAL s.r.o., Liptovský Mikuláš, Slovakia. Nameservers: ns1-3.websupport.sk. Root domain is a legitimate AI receptionist company.
04
Reverse-IP pivot: HackerTarget reverse IP on 91.218.65.223 returned 499 co-hosted domains. File saved to /tmp/osint-scratchpad/014-reverseip.txt for analysis.
05
Brand analysis: Parsed 499-domain list for brand keywords. Confirmed multi-country targeting: ING (NL), DKB/Commerzbank (DE), Belfius (BE), ICS Cards (NL), Klarna (SE), EasyBank (AT), isybank (IT), CJIB Dutch gov, DHL, Spotify, Zoho, PayPal.
06
Docker pattern identification: Second category of subdomains: adjective-scientist naming (admiring-bohr, condescending-euler). Confirmed Docker Engine default name generator. Each = one running container with a Plesk-provisioned subdomain.
07
Gateway domain pivot: Cross-referenced non-*.plesk.page domains in list. Found callora.cz, mojesvetielko.sk, stastna-hvezda.com, spolbyt-group.com — all Websupport.sk nameservers, all resolving to 91.218.65.223. Each carries 1-3 phishing subdomains including Dutch CJIB government impersonation.
08
ASN investigation: RIPE WHOIS on AS44486: Oliver Horscht t/a SYNLINQ, Frankfurt. Abuse contact: abuse@living-bots.net. PTR on 91.218.65.223 = plesk2.living-bots.net confirms this is a commercial Plesk node.
09
HSTS evidence: I probed accont-banking-belfuise-be.91-218-65-223.plesk.page via Chrome. HSTS enforcement with invalid certificate confirms prior valid HTTPS deployment — the phishing kit previously ran with a Let's Encrypt certificate, now rotated/expired.
10
Live HTTP probes: Most *.plesk.page domains return Plesk default page (kit rotation). HTTPS probes: HTTP 303 redirects from Belfius domains (SSL cert now mismatched, triggering HSTS error in browser). Plesk default pages return 5200 bytes consistently — infrastructure is live, kits are rotated.
IOC Table
TypeIndicatorContext
IP91.218.65.223Phishing server, AS44486 synlinq.de Frankfurt DE
ASNAS44486Oliver Horscht t/a SYNLINQ, Hanauer Landstrasse 328-330, 60314 Frankfurt
HOSTplesk2.living-bots.netPTR record for 91.218.65.223 — Plesk node hostname
DOMAINspotify-accounts-login.callora.czEntry point, French Spotify credential phish (live 54 days)
DOMAINcallora.czLegitimate SK domain, Websupport.sk, DNS abused to point to phish server
DOMAINcjib-inloggen.spolbyt-group.comCJIB Dutch Government impersonation
DOMAINklarna-login.spolbyt-group.comKlarna credential phish
DOMAINspolbyt-group.comGateway domain, Websupport.sk NS, Gransy registrar (2022)
DOMAINeasybank-banking-login.stastna-hvezda.comEasyBank Austria credential phish
DOMAINstastna-hvezda.comGateway domain, Websupport.sk NS, Gransy registrar (2020)
DOMAINspotify-login-com.mojesvetielko.skSecondary Spotify phish
DOMAINlogin-isybank-it.mojesvetielko.skisybank Italy credential phish
DOMAINmojesvetielko.skGateway domain, Websupport.sk NS
DOMAINklarnaas.comKlarna typosquat / credential phish
DOMAINklarrnas.comKlarna typosquat / credential phish
EMAILabuse@living-bots.netRIPE abuse contact for AS44486
INFRA91.218.65.223/plesk.page wildcard499 phishing domains via *.91-218-65-223.plesk.page
PATTERNadmiring-* condescending-* dazzling-* adoring-*Docker container auto-naming — automated kit deployment fingerprint
PATTERNWebsupport.sk NS on all gateway domainsCommon Slovak registrar/host abused as phishing DNS layer
Evidence — Infrastructure Analysis
Evidence 1 — Brand Distribution: 499-Domain Reverse-IP Pivot
499-domain brand distribution analysis
HackerTarget reverse-IP pivot on 91.218.65.223 — 499 co-hosted phishing domains, brand breakdown, ASN info. Captured 2026-08-17.
Evidence 2 — Gateway Domain Network: Websupport.sk Abuse Pattern
Websupport.sk gateway domain infrastructure
Four Websupport.sk-nameserved gateway domains all resolving to 91.218.65.223 — HSTS cert mismatch as evidence of prior phishing operations. Captured 2026-08-17.
Evidence — Live Capture
Live Capture 1 — plesk2.living-bots.net Server Landing (91.218.65.223)
plesk2.living-bots.net server landing page
● PHISHING SERVER EXPOSED — Plesk server at 91.218.65.223, hosting 499 phishing domains. Captured 2026-08-17.
Live Capture 2 — callora.cz (Legitimate SK Company — Subdomain Abused)
callora.cz legitimate company website
● ABUSED HOST — callora.cz is a legitimate Slovak AI receptionist company. Operator added spotify-accounts-login.callora.cz A record pointing to 91.218.65.223. Captured 2026-08-17.
Live IOC Status
Loading...
Previous: Case 013 — MONOPOLY GUARD v3 PhaaS Next: Case 015 — Klarna Refund PhaaS
SevinOS BLE Radar