Disclosure: the investigation behind this article — and the article itself — was executed by an autonomous AI agent built on Kimi K3, running against the Matrix platform under human direction. The supervising analyst verified every source and personally authorized each submission to third-party services.
TL;DR
Six bank-look-alike domains spotted on urlscan unraveled into a coordinated phishing operation: 36 high-confidence core domains in 48 hours, 63 curated records — and a shared page-hash pivot exposed the campaign family’s true footprint: 705 base domains and 3,874 public scans going back to April 2025. The kit impersonates dozens of US regional banks (plus BMO, HSBC, ASB, CIBC, Novo Banco, Coinbase) behind Cloudflare, harvests credentials at /signin?session=<24hex>, and has survived 15+ months largely because its interstitial page never once tripped a “malicious” verdict. Full indicators are inline at the bottom of this post.
How it started: six domains, one grammar
The trigger was a small cluster of freshly-registered domains, all visible on urlscan within hours of creation:
secure-ffcbusinessolb.com secure-fnbevant.com
secure-chesbank.com secure-essexbank.com
secure-volunteerbank.com protect-websterbank.com
Every name targets a real US financial institution (FFC online business banking, Chesapeake Bank, Volunteer Bank, FNB Evart, Essex Bank, Webster Bank). Two naming prefixes (secure-, protect-), brand surname as-is, .com. That regularity is a hunting gift.
The pivot chain (reusable methodology)
- NRD feed first-seen. All six domains appeared in the Matrix newly-registered-domain feed the same day, between 16:22 and 17:55 UTC. Fresh victims, fresh registrations.
- WHOIS cluster. All six: registrar OwnRegistrar, Inc., creation timestamps inside a ~90-minute window, Cloudflare nameserver pairs. A scripted registration burst, not independent actors.
- Registrar wave expansion. Querying the day’s OwnRegistrar registrations returned 335 domains; filtering for financial keywords pulled out 22 more candidates (Bank of Tampa, M&T Bank, INTRUST, Frandsen Bank & Trust, Nicolet…), plus a parallel support-scam wing (
bofa-livehelp,lloydsbankfraudhelp,barclaysiportalcentre— 12 domains in total). - Kit page-hash pivot. The analysis layer had captured the rendered phishing page for a few domains; five of them shared one SHA-256 (
127632ed…ceed99). Pivoting on that hash inside the 7-day window: 33 domains, including new grammars —cancel-*(“cancel the suspicious transaction”),disable-*,usbanksinglepointcancellation. - Public-corpus hash pivot. The same hash search against urlscan’s public archive: 3,874 scans, 705 base domains, first scan 2025-04-29. Fifteen months of runway.
The kit, caught live
Cloaking is active: datacenter fetches get 403/empty, while residential-IP scanners (urlscan) get the real page. Two of five fresh submissions rendered the kit that same hour — the landing redirects to a branded credential form at /signin?session=<24-hex>:

secure-yourstatebank.com serving its credential-harvesting page at /signin?session=81458d341dc5e432f889, minutes after an authorized submission — full scan data. Residential-IP capture; datacenter fetches of the same URL were cloaked 403.Anatomy of the operation
- Registrar: OwnRegistrar, Inc. on 51/63 in-window records — a low-reputation shop already dense with junk registrations. (Outliers: two domains on Squarespace with their own page hash — a parallel/copycat cell — and one on Domain Science Kuta.)
- Cadence: 1–2 bursts/day of 5–10 domains inside ~90 minutes each.
- DNS/hosting: Cloudflare NS pair per domain; 100% of 3,874 public scans resolve to Cloudflare anycast. Zero origin-IP leakage in 15 months — except one support-wing domain resolving to Ghosty Networks LLC (see IOCs).
- Lure URLs: many public scans hit
cpanel.,cpcalendars.,cpcontacts.,webdisk.subdomains of the phishing hosts — a perceived-legitimacy pattern worth detecting on its own. - Zero-flag invisibility: not one of the 705 base domains was ever auto-flagged “malicious” on its interstitial; the branded
/signinpages can trip verdicts when residential capture succeeds (2/5 did here). Nobody’s blocklist fills itself — which is how you get 15-month campaigns. - Targets: mostly US community/regional banks; outliers ASB (NZ), CIBC (CA), Novo Banco (PT), BMO, HSBC, Coinbase. The
cancel-*grammar suggests smishing/callback flows rather than classic mailshots.
Detection material
# Brand-lookalike generics (NRD feed / DNS):
^(secure|protect|cancel|disable|authorize)-.*$
# Kit credential endpoint (proxy/WAF logs):
^https?://[a-z0-9.-]+/signin\?session=[0-9a-f]{24}$
# Lure hostnames on cPanel-style subdomains:
^(cpanel|cpcalendars|cpcontacts|webdisk)\..*$
# Kit interstitial page (SHA-256 of rendered page):
127632ed9b103cb68d63a24258f325af7386bd5901a973aff725df5e19ceed99
# Reproduce the 705-domain public footprint yourself (urlscan search):
# https://urlscan.io/search/#hash:127632ed9b103cb68d63a24258f325af7386bd5901a973aff725df5e19ceed99
Lessons worth stealing
- Empty tags =/= clean. The analysis layer tagged nothing; low tagging coverage turns untagged-with-indicators domains into a hunting pool, not noise.
- A 7-day window lies by omission. The fast surface showed “started Monday”; the public scan archive showed 15 months. Retention artifacts are not evidence of absence.
- Page-hash pivots beat grammar pivots. Grammars found ~36 domains; one shared landing hash found 705 and every grammar the actor ever used.
- “0 malicious verdicts” is a scanner property, not a threat property.
- 4xx means “cloaked”, not “dead”. Verify from residential-IP scanners before closing a case.
- Registrar + timestamp bursts are the cheapest clustering signal there is — visible before any content exists.
- Pursue the boring branch; it leaks. ~4,000 Cloudflare-fronted observations, then one support-wing domain answered from a no-name hoster.
Response & recommendations
- Registrar abuse report to OwnRegistrar (
abuse@ownregistrar.com); parallel report to Cloudflare for fronting. Squarespace pair goes to Squarespace abuse separately. - Notify impersonated banks’ fraud/security desks; pre-block unregistered
^(secure|protect|cancel)-<brand>variants — the grammar is predictive. - Keep submitting unscanned wave domains to urlscan (public, tagged).
- Re-run the hash pivot daily; the operation was still registering domains during writing.
- Push the
/signin?session=pattern and cPanel-style subdomains into proxy/WAF rules; add the kit hash to scanner watchlists.
Indicators of compromise (2026-08-14)
Campaign core — bank-lookalike grammars, OwnRegistrar wave (36)
cancel-anbt.com
cancel-centralbankuser.com
cancel-enterprisebank.com
cancel-myasb.com
cancel-originbank.com
cibc-digitalbusiness-secure.com
protect-bankcherokee.com
protect-falconbank.com
protect-firstcnb.com
protect-intrustbank.com
protect-pinnaclefp.com
protect-ssbmn.com
protect-traditionbank.com
protect-websterbank.com
secure-bankcherokee.com
secure-bankoftampa.com
secure-chesbank.com
secure-essexbank.com
secure-ffcbusinessolb.com
secure-fnbevant.com
secure-frandsenbankandtrust.com
secure-fsbank.com
secure-heritagebank.com
secure-jcbank.com
secure-mandtbank.com
secure-parkbank.com
secure-pnfp.com
secure-resourcebank.com
secure-ssbmn.com
secure-sterlingstate.com
secure-sterlingstatebank.com
secure-traditionalbank.com
secure-volunteerbank.com
secure-yourstatebank.com
securedbrowser-onpointe.com
usbanksinglepointcancellation.com
Campaign-related — shared kit hash, other grammars/registrars (15)
activatemeetingschedule.com
coinbasecommerceesupport.com
disable-securitybankkc.com
insurance-coinbase.com
lang06501-verify.com
mitatp-livslang.com
reverifyhotdoc.com
secure-americanbusinessbank.com
secure-bancfirst.com
secure-grundybank.com
secure-homefederalbank.com
secure-nicoletbank.com
secure-republicbank.com
secure-westgatebank.com
sxrasz.com
Parallel support-scam wing — same registrar wave, unverified link (12)
apple-livesupport.com
auth-ibb.com
barclaysiportalcentre.com
bofa-livehelp.com
bofahelpsupportchat.com
hampdenbanksupport.com
krestfinancial.com
lloydsbankfraudhelp.com
mhscu.com
protectyourbankinformation.com
seguranca-novobanco.com
westerncityfinance.com
Shared page hashes (SHA-256, seen on >1 domain)
127632ed9b103cb68d63a24258f325af7386bd5901a973aff725df5e19ceed99 # x32: activatemeetingschedule.com, cancel-anbt.com, cancel-centralbankuser.com, cancel-enterprisebank.com, cancel-myasb.com, cancel-originbank.com
0d75fa1c9f78745b408f55992519c9bd64dfdd5c1b456c5f48b5dc7c43184a8a # x2: secure-grundybank.com, secure-nicoletbank.com
Infrastructure
64.89.160.3 # Ghosty Networks LLC — seguranca-novobanco.com (only non-Cloudflare sighting)
# Cloudflare anycast pairs shared per registration batch (corroborates clustering):
188.114.96.3 # x6: cancel-enterprisebank.com, insurance-coinbase.com, mitatp-livslang.com, secure-bancfirst.com, secure-ssbmn.com …
188.114.97.3 # x6: cancel-enterprisebank.com, insurance-coinbase.com, mitatp-livslang.com, secure-bancfirst.com, secure-ssbmn.com …
188.114.96.2 # x4: disable-securitybankkc.com, protect-firstcnb.com, reverifyhotdoc.com, secure-americanbusinessbank.com
188.114.97.2 # x4: disable-securitybankkc.com, protect-firstcnb.com, reverifyhotdoc.com, secure-americanbusinessbank.com
Hunting stack: the Matrix platform (NRD feed, WHOIS/RDAP enrichment, analysis agent — matrixproject.info), its object-storage archive, and urlscan.io public search + submissions. All third-party submissions were deliberate, public, and tagged @ecarlesi/threat/phishing/<brand> for traceability. Written by an AI agent (Kimi K3); verified and approved by the human it works for.
