Phishing Tale
I don't think I've pubicly shared about AUP violations before. This was such an unusual case that I thought I'd share it.
Keeping out abuse is tricky with SporeStack. The easiest tunable is the minimum new token deposit. At $25, abusers tend to flood in. They're not risking a whole lot. At $250 it keeps a lot of the abuse at bay, but understandably keeps away a lot of possible customers.
At $100, where it's at currently, it seems to be a healthy balance with fairly little abuse. I still wish it could be lower, but I haven't found another solution to the problem.
I've seen all kinds of abuse. Mass port scanning, spam (back when we allowed SMTP by default), traditional phishing, malware hosting, botnet controllers, and more.
I had hoped that SporeStack might be used for edgy blogs, or people who just don't want to provide a full name, address, and credit card just to have a server on the Internet. And I think for many, that's the case. Unfortunately, the double edged sword is that it can make it easier for malicious actors to get started.
Anyway, the tale I had in mind.
A Phisher is Found
I know what most phishing sites look like. This was unique.
The first complaint came in on 2025-10-17. A Windows tech support email linking to a legitimate looking website.
Here's an archive link that I took: https://archive.is/isJYb
"Cross, Art Excavation"
At first glance, looks like a normal business.
But there's more!
Norge Cleaning Center: https://archive.is/Z72DG
Gretna Plating & Polishing: https://archive.ph/4zEhI
The domains do look a bit funny.
The clever thing is that it's an AI-written website, that looks like a legitimate business (at first glance) and it gains credibility with search engines. Then, the somewhat reputable site is used for phishing. I think it would even only respond to the phishing link for a limited time, or under certain circumstances, and otherwise return the "legitimate" site.
I think there were about 67 of these servers right under my nose...
I personally don't have a moral issue with DMCA violations, though it's something I have to address. But making fake websites to gain credibility and ultimately try to steal data, identity, or distribute malware is not right. Clever, yes, but it's certainly not something I wish to be profiting from.
This whole experience has pushed my mindset that maybe automation and daily/hourly billing isn't such a great thing. It certainly has good uses, and is used by legitimate customers, but I feel like it is often like an hourly motel. It doesn't always attract the best customers.