Automated phishing domain detection targeting Bulgarian courier services, government e-portals, and toll payment services
Detectopod is an automated threat intelligence system that monitors the web for phishing domains impersonating Bulgarian courier and logistics companies (Econt, Speedy, BulgariaPost), the Bulgarian Ministry of Interior e-services portal (e-uslugi.mvr.bg), and the TollPass / Vinetki toll payment services (tollpass.bg, vinetki.bg). The system runs continuously via GitHub Actions and maintains a public threat feed.
Detectopod identifies phishing domains that:
- Impersonate Bulgarian courier brands (Econt, Speedy, BulgariaPost, etc.)
- Impersonate Bulgarian government e-services β specifically the MVR portal (
e-uslugi.mvr.bg) - Impersonate Bulgarian toll/vignette payment services β TollPass (
tollpass.bg) and Vinetki (vinetki.bg) - Use suspicious TLDs (
.cfd,.tk,.sbs,.cam,.shop,.autos,.life,.one,.cc, etc.) - Deploy on free hosting platforms (Cloudflare Pages, Firebase, Heroku, Netlify, Vercel)
- Exhibit classic phishing patterns (e.g.,
speedy.bg-pk.cfd,mvrbg.sbs,e-uslugicye.top,tollpassapp.top)
- Multi-Source Detection: Queries URLScan.io, Google CT logs, and Cloudflare CT logs
- Automated Scanning: Runs weekly via GitHub Actions
- Smart Scoring: ML-enhanced scoring system (0-100) based on domain patterns
- LLM Analysis: AI-powered review using Gemini 3.5 Flash to reduce false positives
- Public Threat Feed: JSON feed of detected domains updated in real-time
- Zero Infrastructure: Fully serverless using GitHub Actions
Total Domains Detected: 305
Last Scan: 2026-08-31 19:03:58 UTC
Domains Processed: 6,802
Detection Rate: 2.7%
βββββββββββββββββββ
β URLScan.io API ββββ
βββββββββββββββββββ β
β
βββββββββββββββββββ β ββββββββββββββββββββ
β Google CT Logs ββββΌβββββΆβ detectopod.py β
βββββββββββββββββββ β β (Main Scanner) β
β ββββββββββββββββββββ
βββββββββββββββββββ β β
β Cloudflare CT ββββ β
βββββββββββββββββββ β
βΌ
ββββββββββββββββββββ
β Scoring Engine β
β - Keyword match β
β - Pattern detect β
β - TLD analysis β
ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββ
β LLM Analyzer β
β (Claude S. 4.5) β
ββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββ
β Threat Feed β
β phishing_feed.jsonβ
βββββββββββββββββββββ
- Python 3.10+
- URLScan.io API key (free tier available)
- OpenRouter API key (for LLM analysis, optional)
-
Clone the repository
git clone https://github.com/yourusername/detectopod.git cd detectopod -
Install dependencies
pip install -r detection/requirements.txt pip install cryptography # For CT log support -
Set environment variables
export URLSCAN_API_KEY="your_urlscan_api_key" export OPENROUTER_API_KEY="your_openrouter_key" # Optional
-
Run the scanner
# Quick scan (URLScan.io only) python detection/detectopod.py --sources urlscan # Full scan (all sources) python detection/detectopod.py --sources urlscan google cloudflare # Time-limited scan python detection/detectopod.py --duration 300 # 5 minutes
# Scan using URLScan.io only (recommended for quick tests)
python detection/detectopod.py --sources urlscan
# Comprehensive scan using all sources
python detection/detectopod.py --sources urlscan google cloudflare
# Run for specific duration
python detection/detectopod.py --duration 600 --sources urlscan# Analyze last 24 hours of detections
python detection/llm_analyzer.py --days 1 --max-analyze 50
# Analyze with custom threshold
python detection/llm_analyzer.py --min-score 80 --max-analyze 100The threat feed is automatically updated at feed/phishing_feed.json:
[
{
"domain": "speedy.bg-pk.cfd",
"score": 100,
"detected_at": "2026-01-29T18:11:25.161773",
"source": "urlscan.io-.cfd"
},
{
"domain": "mvrbg.sbs",
"score": 100,
"detected_at": "2026-05-08T12:00:00.000000",
"source": "urlscan.io-.sbs"
}
]- Frequency: Every Monday at noon UTC
- Sources: URLScan.io + Google CT + Cloudflare CT
- Timeout: 20 minutes
- Auto-commit: Updates feed automatically
- Frequency: Every Monday at 2 PM UTC (2h after detection)
- Model: Claude Sonnet 4.5 via OpenRouter
- Purpose: Validate detections and remove false positives
- Max domains: 1000 per run (BYOK, no artificial cap)
| Factor | Weight | Example |
|---|---|---|
| Bulgarian courier brand present | +35 | speedy, econt, bgpost |
| Geographic indicator | +15 | .bg, bulgaria, bg- |
| Suspicious TLD | +30 | .cfd, .tk, .sbs |
| Free hosting platform | +25 | .pages.dev, .web.app |
| Brand + geo + suspicious TLD | +45 | speedy.bg-pk.cfd |
| Brand + suspicious TLD | +25 | econt-paydelivery.cfd |
| Brand + free hosting | +40 | speedy-37a.pages.dev |
| Brand + geo + free hosting | +30 | econt-bg-xxx.web.app |
| Multiple hyphens (with brand) | +8 each | speedy-trans-bg |
| Random alphanumeric patterns | +12 | g63829, 37a |
| Phishing keywords | +15 | payment, verify, secure |
| Factor | Weight | Example |
|---|---|---|
| MVR / mvrbg / e-uslugi present | +40 | mvr, mvrbg, e-uslugi |
| Geographic indicator | +15 | bggov, govbg, bg- |
| Suspicious TLD | +30 | .sbs, .cam, .autos, .shop |
| Brand + geo + suspicious TLD | +45 | mvr.bggov.cam |
| Brand + suspicious TLD | +25 | mvrbg.sbs |
| Brand + free hosting | +40 | mvr-bg.pages.dev |
| Factor | Weight | Example |
|---|---|---|
| tollpass / vinetki present | +40 | tollpass, vinetki |
| Geographic indicator | +15 | .bg, bulgaria, bg- |
| Suspicious TLD | +30 | .cam, .top, .cc |
| Brand + geo + suspicious TLD | +45 | tollpass.klgf.cam |
| Brand + suspicious TLD | +25 | tollpassapp.top |
| Brand + free hosting | +40 | tollpass-xxx.pages.dev |
Threshold: Domains scoring β₯80 are added to the feed.
Suspicious TLDs:
.cfd, .tk, .ml, .ga, .gq, .cf, .top, .xyz, .club, .online,
.site, .space, .click, .link, .live, .icu, .sbs, .cam, .shop,
.one, .autos, .life, .qpon, .uno, .ink, .cyou, .cc
Free Hosting:
Firebase (.web.app, .firebaseapp.com), Cloudflare Pages (.pages.dev),
Heroku (.herokuapp.com), Netlify (.netlify.app), Vercel (.vercel.app),
Render, GitHub Pages, and more.
Courier brands:
econt, speedy, bulgariapost, bgpost, samedaybg, boxnowbg,
cityexpressbg, expressonebg, dhl
Government brands (MVR):
mvr, mvrbg, e-uslugi, euslugi
Toll/vignette brands (TollPass / Vinetki):
tollpass, vinetki
Secondary (generic logistics):
tracking, delivery, shipment, parcel, payment, tax, fee,
customer-center
.bg, bulgaria, bg-, -bg, bggov, govbg, gov-bg, bg-gov
SCORE_THRESHOLD = 80 # Minimum score for feed inclusionRecent scan statistics:
- Domains scanned: ~1,800 per run
- Processing time: ~18 seconds
- Detection rate: ~5%
- False positive rate: <10% (with LLM validation)
- All API keys stored as GitHub Secrets
- No sensitive data in repository
- Read-only feeds (public access)
- Automated threat intelligence sharing
Contributions welcome! Areas for improvement:
- New detection patterns: Suggest additional phishing indicators
- Expanded coverage: Add more brands or government services
- Performance optimization: Improve scanning efficiency
- False positive reduction: Enhance scoring algorithms
MIT License - see LICENSE file for details.
- URLScan.io - Primary data source
- Certificate Transparency - CT log infrastructure
- OpenRouter - LLM analysis API
- Bulgarian cybersecurity community
- Issues: GitHub Issues
- Discussions: GitHub Discussions
This tool is for educational and defensive security purposes only. The threat feed is provided as-is without warranty. Always verify domains before taking action.
Status: π’ Active | Last Updated: 2026-05-08 | Version: 1.1