OctopuShield OCTOPUSHIELD

Sample report

What you receive when we find one.

This is a complete finding report, filled with synthetic data. Nothing here is a real customer or a real detection — it shows the shape and the depth of what lands in your inbox.

DEMO / SYNTHETICInvented domain, invented figures. Not a customer, not a live finding. Addresses shown are from the RFC 5737 documentation ranges — they point at no real server.

The finding

OS-F-2026-08-19-0417

northbay-login.top

60 85 91 / 100

Pre-score from deterministic signals — no model call

digest 60 · instant 85

Brand
Northbay
First seen (UTC)
2026-08-19T14:32:10Z
Source
early signal
Status
Unverified (T0)

What we found

northbay-login.top

Brand: Northbay

How sure we are

91 / 100

Unverified (T0)

What to do now

Registrar abuse

Where to send it · free · typically hours to 72 h · the fastest route

Source, timestamp, record reference and reasoning in one file — ready to send to the registrar or hosting provider.

Evidence summary

  • Character substitution against a monitored brand+40
  • Domain registered within the last 7 days+25
  • Address went live minutes ago+15
  • Login keyword appended to the brand name+11
  • Total91/100

Your own domain health

Weaknesses in your own address. Separate from the impersonation hunt: there is no fake address here — it is your own address that can be taken over.

Last measured: 2026-08-19T06:00:00Z

Email sending authority

Weak setting

musteri-ornek.com

Anyone can send email in the name of this address.

No sending-authority record (SPF) is defined at all, so the receiving server cannot reject forged mail.

How to fix it
Where
Your domain control panel → DNS records
Record type
TXT
Name
@
Value
v=spf1 -all

Caution: This record means “no email is ever sent from this address”. If you do send email from it, do not use this exact value; first establish which server sends on your behalf.

Mail server

Unclaimed delegation

musteri-ornek.com

Your mail server points to an address that no longer exists.

The MX target does not resolve and its parent domain appears unregistered: someone else can register that name and receive your incoming mail.

How to fix it
Where
Your domain control panel → DNS records
Record type
MX
Name
@
Value
Delete the unresolvable record, or point it at your working mail server

Caution: If you do not receive mail, deleting the record outright is cleanest. If you do, enter the current server name your provider gave you.

Name server

No problem

musteri-ornek.com

All of your name servers are working.

Subdomain

Not checked

*.musteri-ornek.com

Your subdomains were not scanned.

This check sends a real request to your subdomains, so it is never run without your permission.

How to fix it
Where
Admin panel → Monitored sites
Record type
Checkbox
Name
Subdomain scanning
Value
This domain is mine, you may scan my subdomains

Caution: Scanning starts the moment you confirm. Without confirmation this line stays “not checked” — it is never counted as “clean”.

What was checked, what could not be

Last measured: 2026-08-19T06:00:00Z

Checked 5

  • Fake domain huntcertificate logs · continuous
  • Name servertwo independent resolvers
  • Mail servertwo independent resolvers
  • Email sending authoritytwo independent resolvers
  • Fake mobile appiOS app store

Could not check 6

  • Subdomain takeoverawaiting your ownership confirmation
  • Fake advertisingMeta access awaiting identity verification
  • Fake social accountaccess key not configured
  • Instagram · Facebook account scanno public search interface; a business application is required
  • LinkedInplatform terms forbid automated scanning
  • Google Play · Google adsno public search interface

A channel that could not be checked does not mean “clean”. The product can only say “you are clean” once every channel has been looked at.

Open the full technical detail

Why it was flagged

Score breakdown Which signal contributed how many points
  • Character substitution against a monitored brand +40
  • Domain registered within the last 7 days +25
  • Address went live minutes ago +15
  • Login keyword appended to the brand name +11
  • Total 91

Network and location

IPv4
198.51.100.47 · 198.51.100.48
IPv6
2001:db8:4f2a::1
ASN
AS64512 · EXAMPLE-TRANSIT (belgeleme ASN'i)
Reverse DNS
web-047.pool.example-host.invalid
Hosting
Example Hosting B.V.
CDN
yok
Country
Hollanda (NL)
City
Amsterdam
Region
Noord-Holland
Coordinates
52.37 N, 4.90 E
Time zone
Europe/Amsterdam (UTC+02:00)
Monitoring zone
eu-west-1

Open services

PortStateServiceBanner
443openhttpsnginx
80openhttpnginx (301 → https)
22closedssh—
25filteredsmtp—

Permanent public record

LogIndexTree sizeTimestampType
kamu kaydı A1,284,739,6211,284,739,7442026-08-19T14:31:58Zön kayıt
kamu kaydı B984,112,307984,112,4112026-08-19T14:32:03Zkayıt
kamu kaydı C447,290,183447,290,2662026-08-19T14:32:07Zkayıt

Publication record

Common name
northbay-login.top
Issuer
Örnek Sağlayıcı (belgeleme)
Serial
04:9f:2a:c1:88:e0:31:7b:aa:42
Signature
—
Key
—
Validity
90 days
Valid from
2026-08-19T14:28:00Z
Valid to
2026-11-17T14:27:59Z
Fingerprint
9f3c:41ab:77de:0025:b8a1:6f9c:22e4:1d70

Subject alternative names

  • northbay-login.top
  • www.northbay-login.top
  • secure.northbay-login.top
  • *.northbay-login.top

DNS records

TypeNameValueTTL
Anorthbay-login.top198.51.100.47300
Anorthbay-login.top198.51.100.48300
AAAAnorthbay-login.top2001:db8:4f2a::1300
NSnorthbay-login.topns1.example-dns.invalid86400
NSnorthbay-login.topns2.example-dns.invalid86400
MXnorthbay-login.top10 mail.example-host.invalid3600
TXTnorthbay-login.topv=spf1 include:_spf.example-host.invalid ~all3600
CAAnorthbay-login.top0 issue "example-ca.invalid"3600
SOAnorthbay-login.topns1.example-dns.invalid. abuse.example-dns.invalid. 20260819013600

Registration (RDAP)

Registered
2026-08-17T09:14:22Z
Age at detection
2 days
Registrar
Example Registrar Inc.
IANA ID
IANA 9999
Abuse e-mail
abuse@example-registrar.invalid
Abuse phone
+31 20 000 0000
Updated
2026-08-19T14:20:11Z
Expires
2027-08-17T09:14:22Z
Status
client transfer prohibited · ok

HTTP transaction

StepURLStatusLocation
1http://northbay-login.top/301https://northbay-login.top/
2https://northbay-login.top/302https://northbay-login.top/signin
3https://northbay-login.top/signin200—

Header

HeaderValue
servernginx
content-typetext/html; charset=utf-8
content-length18442
x-powered-byPHP/8.2.4
set-cookiesid=…; Path=/; HttpOnly
strict-transport-security— (yok)
content-security-policy— (yok)

Content fingerprint

Page title
Northbay · Secure Sign In
Size
18,442 bytes
Form target
https://northbay-login.top/api/auth
Form fields captured
email · password · otp

SHA-256 3f9a71c0d84e5b6621ff90ac3e1748d95b7a2c08e4f16d3b9c05a7e2d418c21b

Assets

  • logo.svg (bit-for-bit identical to the legitimate site)
  • app.css
  • app.js

What happened, when

Time axis of the chain real intervals, not evenly spaced 14:28:00 14:31:58 14:33:41 +238s+62s real intervals, not evenly spaced
Time axis of the chain
14:28:00yayin.basladi örnek sağlayıcı
14:31:58kamu.kaydi kamu kaydı A #1284739621
14:32:03kamu.kaydi kamu kaydı B #984112307
14:32:07kamu.kaydi kamu kaydı C #447290183
14:32:10sistem.okudu izleme birimi
14:32:10oncelik.hesaplandi 91 / 100
14:33:12ad.cozuldu 2 A · 1 AAAA · 2 NS · 1 MX
14:33:19kayit.bilgisi Example Registrar Inc.
14:33:30adres.durumu 200 · 3-hop redirect
14:33:33icerik.ozeti sha256:3f9a…c21b
14:33:41report.generated OS-F-2026-08-19-0417

Every step carries its own timestamp — nothing is reconstructed afterwards.

  1. 14:28:00 yayin.basladi örnek sağlayıcı
  2. 14:31:58 kamu.kaydi kamu kaydı A #1284739621
  3. 14:32:03 kamu.kaydi kamu kaydı B #984112307
  4. 14:32:07 kamu.kaydi kamu kaydı C #447290183
  5. 14:32:10 sistem.okudu izleme birimi
  6. 14:32:10 oncelik.hesaplandi 91 / 100
  7. 14:33:12 ad.cozuldu 2 A · 1 AAAA · 2 NS · 1 MX
  8. 14:33:19 kayit.bilgisi Example Registrar Inc.
  9. 14:33:30 adres.durumu 200 · 3-hop redirect
  10. 14:33:33 icerik.ozeti sha256:3f9a…c21b
  11. 14:33:41 report.generated OS-F-2026-08-19-0417

What each step means

  1. 01
    Address first entered the public recordthe record's first validity moment
  2. 02
    The entry lands in a public sourcethe log's own timestamp — this is what we measure against
  3. 03
    The system reads the entry79 s median across 6,115 measured records
  4. 04
    Live verification completedDNS, RDAP, HTTP and content hash captured

Related findings

DomainIPCountryScoreFirst seen
northbay-secure.info198.51.100.47NL742026-08-19T14:31:22Z
n0rthbay.com203.0.113.19US882026-08-18T22:07:41Z
northbay.com.verify.top192.0.2.88DE692026-08-18T11:52:03Z
northbay-account.click198.51.100.47NL812026-08-17T18:33:57Z
northbay-verify.live203.0.113.19US772026-08-16T09:11:40Z

Where the cluster resolves

  • Hollanda NL 3
  • ABD US 2
  • Almanya DE 1
  • Singapur SG 1
  • Brezilya BR 1

Live verification

Measured at report time — this is the half that makes a takedown request succeed.

CheckResult
DNSresolves · 2 A records · 1 MX
RegistrarExample Registrar Inc.
Registered2026-08-17 (2 days before detection)
HTTP200 · nginx · 1 redirect
Content hash3f9a…c21b

Evidence package

Evidence completeness What the package contains and what it does not — 10/12

10 / 12 · %83

  • Domain and subdomains included
  • First-seen timestamp (UTC) included
  • Source reference included
  • Name and alternative names on record included
  • Signals behind the score included
  • Your legitimate domains included
  • DNS records (A/NS/MX) included
  • Registration date and registrar included
  • HTTP status and redirect chain included
  • Page content SHA-256 included
  • Independent third-party timestamp not available
  • Your identity / authorisation to report not available

The last two are yours to add: an abuse report needs the reporter's identity, and an independent archive link makes the timestamp harder to dispute.

What you can do next

Registrar abusefree · typically hours to 72 h · the fastest route
Hosting providerfree · needed when the registrar is slow
CDN (if fronted)free · they forward to the real host, they do not suspend
National CERTfree · restricts reachability within one country, not worldwide
UDRP / disputepaid · weeks · only when you want the domain itself

We do not file these for you. The package is built so that you — or your lawyer — can file them without chasing data.

Why a screenshot is not enough

A screenshot can be edited and its capture time cannot be proven. A public records entry cannot be altered after the fact, and a content hash lets anyone check later that the page has not changed. That is the difference between a claim and evidence.