Context: This supplements Ben Polonsky's writeup with net-new findings from active infrastructure reconnaissance conducted 2026-03-28. All probing was passive/non-invasive against already-identified phishing infrastructure.
The article identified OpenResty 1.29.2.1 as the web server. Behind it sits a second layer: