Financial & crypto phishing
Credential-harvest lookalikes for banks and exchanges.
*.mabanqueparibas[.]comcoinspot[.]supportA single certificate — on a domain that looked completely legitimate — unraveled a 150-domain bulletproof hosting operation. Not one of those domains had been caught by any public domain feed.
Flagged 14 July 2026 · Feeds checked 14 July 2026 09:00 UTC
Our pipeline flagged mail.e-socialstatement[.]com— a polished replica of the U.S. Social Security Administration’s member portal.
Look at the page and you’d move on. So would an automated website scanner: clean layout, federal-blue styling, the right words. Nothing on the surface says “phishing.”
But the domain resolved into AS213790, an Iranian network our pipeline scores 1.0 for bulletproof behavior with an abuse score of 95 / 100. After we found it, we ran a one-off check against Spamhaus DROP, which independently lists parts of that network as criminal-controlled address space. The U.S. Social Security Administration does not host on Iranian bulletproof infrastructure. The surface lied. The infrastructure didn’t.
Has a website ≠ is legitimate.
Phishing pages are built to look real — that’s the entire point. A surface check waves them through. Only the infrastructure gives them away.
A confirmed-bad domain isn’t an endpoint — it’s a thread. Attackers register throwaway domains cheaply but reuse hosting, so the infrastructure is what ties a campaign together. We pulled the thread.
The certificate is the tell. Attackers hide domains behind bare IP addresses, but the TLS certificate a server presents names them out loud. Mapped in minutes on 14 July 2026 — no prior knowledge of a single one of these domains.
One tenant, offshorehost[.]info, advertises the service by name. The rest is a full-spectrum cybercrime host. Indicators defanged.
Credential-harvest lookalikes for banks and exchanges.
*.mabanqueparibas[.]comcoinspot[.]supportForged certs naming brands they can't legitimately serve.
*.samsung.com (+50 SANs)www.apple.comms-telemtry[.]comThe lead that started it all — a fake U.S. Social Security Administration portal.
e-socialstatement[.]comStolen-card and narcotics storefronts.
carderz[.]todrugmaniac[.]tobreakingbad[.]wsCommand panels and stealer-log tooling.
apilogtool[.]onlinesoft-setup[.]companel.win-tools[.]netBulk mailers, proxy services, a Tor hidden service.
smtp-zone[.]suproxiesfood[.]com*.onionWe checked all 150 domains against the open phishing and malware domain feeds on 14 July 2026 09:00 UTC. None of them were listed.
Domain feeds list a domain after it is reported. Someone has to see it attack first. These 150 had not been reported yet, so the operation was mapped from its infrastructure, not from reports.
This is one investigation, checked once. It does not measure how much earlier Datazag finds domains in general.
Wait for a domain to attack, get reported, and propagate to a feed. By then the campaign has run — and the next hundred domains are already registered.
Find the reused, expensive thing — the hosting — and every domain on it falls out at once. One signal, the whole operation, before the phishing page ever lands in an inbox.
These 150 domains and 5 netblocks would have arrived as scored, annotated records in your SIEM or warehouse — before the first phishing email was sent — because the intelligence is delivered as data into the stack you already run.
For MSSPs, one investigation like this, white-labeled across your client base, is a retention artifact no reactive feed can produce.
Not every flagged certificate unravels a 150-domain cluster. Every one is checked the same way.
Datazag · Infrastructure Intelligence
Findings from a single investigation conducted by the Datazag detection pipeline. Indicators are defanged; domains named are assessed as malicious infrastructure. Feed check taken 14 July 2026 09:00 UTC against snapshots of open phishing and malware domain feeds, which may differ from their live state. Published 14 July 2026.