Anatomy of a Phishing Campaign Impersonating OVHcloud Support

Phishing campaigns are designed in a way to gain trust of the victims. For this reason most of the phishing campaigns rely on recognizable brand or name impersonation to make malicious messages appear legitimate.

Recently we investigated a phishing attack campaign which impersonating OVHcloud support for malicious messages. The attack was using a .eu domain for the phishing URL and two .sk domains for sending the phishing email. During the investigation we tried to access the provided URL but it was returning HTTP 403 Forbidden message.

The Phishing Lure and URL Structure

The phishing emails were mostly written in French and claiming that the services associated with the recipient's domain had been suspended because of a payment issue. It urged the recipent to renew immediately through a button presented as an OVHcloud action.

Phishing Email

Here are some observed URLs

https://enra4yuwsg.vcstrading.eu/?id=knightsquad.academy&token=53246646afadfeb4a5afe4
https://2vm2ftgbkx.vcstrading.eu/?id=knightsquad.academy&token=53246646afadfeb4a5afe4
https://5c4o76fs33.vcstrading.eu/?id=knightsquad.academy&token=53246646afadfeb4a5afe4

After analyzing multiple emails we observed different randomly generated subdomains under vcstrading.eu. The URL parameters included the targeted domain and a token value. During the investigation, all the supplied URLs returned HTTP 403 Forbidden. The main domain itself appeared parked or reserved and used Combell nameservers:

ns3.combell.net
ns4.combell.net

When we visited the main domain it shows the default domain parking page of Combell Combell Parking Page

Tracing the Sender

Since the supplied phishing URL did not reveal any useful content during our investigation, we shifted our focus to the sender infrastructure. The phishing emails were sent using two .sk domains: enekon.sk and catpower.sk and used emails are contact@catpower.sk and contact@enekon.sk .

We examined the full email headers and identified two IP addresses 109.236.82.9 and 188.165.153.22 as the mail server that directly delivered the message. We also reviewed the DNS configuration of both enekon.sk and catpower.sk and found that they use WebSupport nameservers. WebSupport is a Slovakia-based web hosting and domain services provider.

When we accessed both domains directly, they returned the default NGINX 403 Forbidden page, with no publicly accessible website content.

We gathered additional information about the sending IPs, 109.236.82.9 and 188.165.153.22. The first IP is associated with WorldStream B.V., a Netherlands-based cloud infrastructure provider, while the second is associated with OVH SAS.

Although the sender domains enekon.sk and catpower.sk were using WebSupport nameservers, the phishing emails were delivered through infrastructure linked to both WorldStream B.V. and OVH SAS. Based on these findings, we reported the activity to both providers for further investigation.

If you receive a similar email claiming to be from OVHcloud Support, do not interact with the message or open any links it contains. Instead, access the OVHcloud Control Panel directly and verify whether there are any genuine service, billing, renewal, or account-related notifications. Even if the email appears convincing or references your actual domain, always verify the issue through the official OVHcloud dashboard before taking any action.

Written By
Photo of Md. Moniruzzaman Prodhan

Md. Moniruzzaman Prodhan

Director, Security Research & Programs

A cybersecurity professional working across training, security assessments, and research. Founder of the Knight Squad community and Director, Security Research & Programs at Knight Squad Academy. Has delivered cybersecurity training for multiple government agencies in Bangladesh, with hands-on experience in VAPT/penetration testing, malware analysis, reverse engineering, and AI security testing. Actively involved in responsible vulnerability research, including 0-day hunting, and contributes to the community as an event director and CTF challenge creator for KnightCTF and BDSec CTF.