October 10, 2026
Operation Section Sign: The Fake MMDA Fine Portal That Warns You About Fake MMDA Fine Portals
Subscribe at my self-hosted Blog as the medium presence will eventually disappear:

By Sigmund Brandstaetter CISSP, CCSP, CISM, OSCP, CEH
17 min read
Operation Section Sign: a fake MMDA NCAP fine portal A traffic fine text from MMDA§NCAP, one GSM-7 byte off the real sender ID, led to a 16-hour-old portal with a live…
A traffic fine text from "MMDA§NCAP" arrived five days after camera enforcement returned to Metro Manila. The sender ID gave away how it was built, the domain was sixteen hours old, any plate number came back guilty, and the page itself carried a scam warning pointing to a second scam domain. My own scanner was shown a 9-byte 404.
The text came in at 11:32 on a Saturday morning. A traffic fine, about to expire. A link to settle it. A warning that missing the due date would bring "substantial late payment penalties." Then a second line, a few seconds later: the ticket is now being sent to you.
The sender ID read MMDA§NCAP.
That one character is the most interesting thing in the whole campaign, so it gets its own section. Everything else is a clean, fast, by-the-numbers smishing operation riding a news cycle.
The § is an underscore that lost its translation
The MMDA's real NCAP text notifications come from the sender ID MMDA_NCAP, with an underscore. The agency has said so repeatedly in its public warnings.
So why does the fake one show a section sign?
Because of how SMS encodes text. Most SMS uses the GSM 03.38 default alphabet, a 7-bit character set that does not line up with ASCII above the basics. In ASCII, the underscore is byte 0x5F. In the GSM 7-bit alphabet, 0x5F is §, the section sign. The GSM underscore lives at 0x11.
Somebody typed MMDA_NCAP. Whatever pushed the message out wrote the raw ASCII byte into a GSM-7 field without mapping it, and the phone rendered 0x5F the way the GSM table says to: as §.
That is a well-known charset bug in SMS gateway software, and normally a carrier's message center does the translation for you. Seeing it on a spoofed government sender ID tells you two things:
- The operator was trying to clone the real sender ID exactly, not a lookalike. The § is an accident, not a design choice.
- The message took a path where nobody translated the charset. That fits a sending stack that sits outside the normal carrier pipeline. Philippine telcos and the NTC have spent two years warning about portable fake cell towers (IMSI catchers, "SMS blasters") that push spoofed sender IDs straight to phones in range, bypassing the carriers' link filters entirely. A link-bearing SMS under a spoofed government alphanumeric ID is exactly what those devices are bought for.
I cannot prove from one handset which route this message took. But the § is a fingerprint worth collecting: if you see it on other spoofed sender IDs, you are probably looking at the same class of sending equipment.
Timing: five days after NCAP came back
This lure did not arrive in a vacuum.
The MMDA has run its own No Contact Apprehension Policy on major roads since the Supreme Court partially lifted its 2022 restraining order in May 2025. In June 2026 the Court dismissed the remaining petitions against the city ordinances, and on Monday, October 5, 2026, NCAP returned in Manila, Quezon City, Parañaque, Muntinlupa and San Juan under the Metro Manila Traffic Code of 2023. It was front-page news all week.
The domain behind this text was registered four days later.
The fake NCAP fine scam itself is not new. Through July and August 2026 the MMDA issued warning after warning, asked the NBI to investigate after more than 180 people paid fake fines, and said the scammers rebuild their sites as fast as they get blocked. What the restart did was hand them a fresh reason for every motorist in Metro Manila to believe a camera may have caught them.
Two lines from the MMDA's own warnings are worth keeping next to the screenshot:
- Official NCAP texts contain no links.
- There is no late payment penalty for NCAP violations.
The SMS fails both tests in its first sentence.
Infrastructure: sixteen hours old
From registration to a phone in Manila: about sixteen hours. From certificate to SMS: about fifteen.
The rest of the record:
- A record:
43.157.225.99, inside43.157.224.0/19, AS132203, Tencent (TENCENT-NET-AP-CN). No PTR. - SOA:
ns1.domainnamens.com. hostmaster.wdomain.com., serial2026100903. - Certificate: one cert, one name. Nothing to pivot on in CT.
- urlscan: no prior scan before mine.
Every one of these is unremarkable alone. Together they are a familiar shape. Palo Alto Networks' Unit 42 found that roughly two thirds of the root domains in the global Smishing Triad toll and delivery campaigns were registered through Dominet (HK). Silent Push reported the bulk of that group's phishing domains sitting on Tencent AS132203 and Alibaba. A Dominet registration, Chinese nameservers, Tencent hosting, a one-name Let's Encrypt cert and a government fine lure is the template.
That is a pattern match, not an attribution. The Smishing Triad ecosystem is phishing-as-a-service: kits, domains, hosting and SMS delivery are sold separately on Telegram, and many crews buy the same parts. What I can say is that this campaign was assembled from the same supply chain.
The portal
Loaded from a Philippine connection, the site is a credible MMDA page: the agency masthead, a Bagong Pilipinas badge, and a "Traffic Violation Inquiry" form asking for exactly two things, a plate number and a mobile number.
The mobile number is the quiet part. It confirms a live, registered number tied to a vehicle owner, and in other kits from this ecosystem it is where the one-time-password relay starts.
I entered 123456. Not a valid Philippine plate format. The portal labeled it a "Verified Plate Number" and returned a recorded violation:
- Notice of Violation No.
N26-55-104895 - Type: Use of Mobile Phone While Driving, "captured by electronic enforcement camera"
- Date of apprehension:
05/10/2026 - Legal basis: R.A. №10913, Sec. 4, the Anti-Distracted Driving Act of 2016
- Demerit points: 1
- Jurisdiction: Metro Manila
There is no lookup. Every plate is guilty.
Three details are worth a second look.
The date. 05/10/2026 reads as May 10 to most Filipino motorists, who write month first. The payment page settles which one the kit means: it shows a deadline of 11/10/2026 and says the fine is "about to become overdue." I saw that on October 10. Only day first makes that work, so the deadline is October 11, one day out, and the apprehension date is October 5, 2026, the day NCAP restarted. The kit writes dates the European way, which fits the French lang attribute in the page source further down.
The law is real, the fine is not. Section 4 of RA 10913 is the section that defines distracted driving, and a phone-while-driving camera catch is a plausible NCAP violation. The real first-offense fine under Section 8 of that law is ₱5,000.
The portal asks for ₱1,000.00, which it calls a "fixed amount under NCAP guidelines." That is a fifth of what the law it cites actually imposes. It is also exactly the figure the MMDA chairman gave in August when he described what the fake NCAP portals typically demand. The scammers price the fine low on purpose: ₱1,000 is small enough to pay without asking anyone, and small enough that a careful motorist might not bother contesting it.
The scam warning. Right under the plate, in a highlighted box, the page tells you there have been SMS phishing attempts impersonating "our official website," and asks you to verify the only official site:
https://www.mmda-ncaplto[.]lol
That is not an MMDA domain. The real NCAP lookup is mayhulika.mmda.gov.ph, and government sites in the Philippines sit under .gov.ph. A fake portal warning you about fake portals, then naming a second fake, does two jobs: it borrows the agency's own anti-scam messaging for credibility, and it hands the victim a backup domain for when the first one gets blocked.
Below the button sits a list of consequences for not paying: LTO alarm on the plate, blocked registration renewal, demerit points, blocked LTO transactions. The unsettling part is that most of these mirror how real NCAP enforcement works, which is why they persuade. The one thing the real system does not have is the threat in the SMS: a late payment penalty.
"Continue to Online Payment" does not leave the site. There is no payment link, no redirect to a gateway, and the address bar still reads https://mmdancap[.]net with no path or hash. The kit swaps in an "Online Payment of NCAP Violation Fine" page inside the same single-page app. It shows the plate, the violation, a new NOV number, the deadline and ₱1,000.00, then offers two choices:
- E-Wallet: GCash, Maya, GrabPay
- Bank Card: Visa, Mastercard, Amex, JCB, labeled "Credit, Debit, Savings, Prepaid"
Whatever you type next goes to the operators, not to a payment processor. The e-wallet option matters most locally. A card number can be cancelled. An e-wallet login, MPIN and OTP hand over the account itself, which is what the MMDA chairman meant when he warned that paying a fake fine likely exposes your e-wallet.
The NOV number changed, too. My first inquiry returned N26-55-104895. The second returned N26-67-090182. The kit generates a fresh, official-looking reference for each lookup, so there is no fixed number to blocklist or search for.
What my scanner saw: nothing, on purpose
I ran mmdancap.net through FalconEye's Phishing Kit Scanner with the deep kit report on. It came back clean:
- HTTP 404,
nginx,text/plain, 9 bytes - Bare profile and browser profile both served the identical response (same body hash,
0019dfc4b32d63c1392aa264aed2253c) - No JavaScript bundle fetched, no socket path, no operator console
- Bundle signature score 0/53, live host score 0/51
The generated analyst summary went one step further and called the site non-functional or under construction.
It was neither. At the same moment, a Philippine browser was getting the full portal. The server decides who it is talking to before it serves a single byte of the kit, and anyone who is not a likely victim gets a 9-byte "not found." Since both of my request profiles got the same answer, the gate is almost certainly on the connecting network rather than the user agent: the scanner's datacenter address simply isn't on the guest list.
That is the lesson I want practitioners to take from this one. A fresh domain that returns a tiny 404 to your tooling is not a dead domain. Sixteen hours after registration, with a certificate issued an hour after the domain, a 404 is far more likely to be a fence than an empty server. The response to cloaking is a browser collector: pull the page and its bundles from a browser that sits inside the fence, then analyze offline.
The page source is an empty shell
Viewing source on the live portal from a PH browser gives you this, before submitting the form and after:
<!DOCTYPE html>
<!-- render 5aeb5e -->
<html lang="fr" translate="no" data-skinbcn="base">
<head>
<meta name="format-detection" content="telephone=no">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<link crossorigin="anonymous" rel="stylesheet" href="/wg026_ph/2E4B33583.css">
<script type="module" crossorigin src="/s/5a2f/e10d4/index-57e948acef1.js"></script>
<link crossorigin="anonymous" rel="stylesheet" href="/s/5a2f/e10d4/index-877985f1e418.css">
...
<body class="theme-tyovxm" data-toneymd="jxzk70">
<div class="panel-u8ika" data-tone2yf="2ck6in"><div class="content-xi1v4"><div id="view-91rctx"></div></div></div>
</body>
</html><!DOCTYPE html>
<!-- render 5aeb5e -->
<html lang="fr" translate="no" data-skinbcn="base">
<head>
<meta name="format-detection" content="telephone=no">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<link crossorigin="anonymous" rel="stylesheet" href="/wg026_ph/2E4B33583.css">
<script type="module" crossorigin src="/s/5a2f/e10d4/index-57e948acef1.js"></script>
<link crossorigin="anonymous" rel="stylesheet" href="/s/5a2f/e10d4/index-877985f1e418.css">
...
<body class="theme-tyovxm" data-toneymd="jxzk70">
<div class="panel-u8ika" data-tone2yf="2ck6in"><div class="content-xi1v4"><div id="view-91rctx"></div></div></div>
</body>
</html>The before and after are byte-for-byte the same, and that is the point. This is a single-page app. The MMDA masthead, the form, the "verified" plate, the violation table and the payment flow are all drawn in the browser by index-57e948acef1.js. The HTML never changes because the HTML is just a mount point.
What the shell does tell us:
lang="fr"on a Philippine government lure. The template was not written for this country. It was localized, and somebody forgot the root attribute. French-language traffic fine lures are a staple of the same kit ecosystem./wg026_ph/in the stylesheet path reads like a template or campaign ID with a country suffix. Other countries likely get other suffixes from the same build.- Randomized class and attribute names (
theme-tyovxm,panel-u8ika,data-skinbcn,data-toneymd) and arender 5aeb5ecomment that look like per-render tokens. That is anti-fingerprinting: it breaks naive HTML signatures across domains. Worth confirming by loading the page twice and diffing. - Hashed module assets under short random directories (
/s/5a2f/e10d4/), the output of a modern bundler. format-detection telephone=noanduser-scalable=no: built for phones first.
The real kit is the bundle. I collected it from a browser inside the fence with FalconEye's browser collector, then tore it down offline.
What the kit actually is
Fed the real bundle instead of the 9-byte decoy, the picture changes completely. This is not a static form that emails you a card number. It is a bundled Vue 3 single-page app with a live operator console, built to beat SMS and app-based 3-D Secure in real time.
Three things set it apart from a plain skimmer:
- It leaks every keystroke as you type, not on submit. A victim who types a card number and then backs out has already lost it.
- It holds a live WebSocket to an operator who watches the card data arrive and pushes the victim from screen to screen by remote command.
- It carries an operator-templated challenge page that can imitate any bank's OTP, in-app-approval or QR screen on the fly.
Put together, that is a kit designed to defeat two-factor authentication while you watch a spinner. The operator replays your card against the real bank in a parallel tab. When the bank fires a one-time code or a push approval, the operator steers you to the matching capture screen and relays your answer back. It is monetising the whole transaction, not just the card number. That makes it materially more dangerous than the Paper Rabbit kit, which harvested and moved on.
The funnel
The router lays out the whole path: home → pay → card → one of several challenge views → success. Transitions from the card screen onward are not automatic. They wait on the operator, whose commands decide which challenge appears and when the fake receipt is shown.
How it tracks you
On first load the kit mints a UUID v4 and pins it across four stores so your session survives reloads and closed tabs: sessionStorage, localStorage, a cookie named token with a roughly 400-day lifetime (max-age=34560000), and an IndexedDB database TokenDB (v2, store tokens, key userToken). Every request then carries that token three ways at once, as a Token header, an X-Token header and a token query parameter, so the backend can tie your keystrokes, your card submission and your OTP to one session in the console, even across reconnects.
How the data leaves
Every field across the funnel (plate, phone, cardholder, card number, expiry, CVV, every OTP box) fires an input_text event on each keystroke. The kit sends it two ways for reliability: debounced over the live WebSocket (around 300 ms) and, in the non-Socket.IO mode, an HTTP fallback POST to /qYvdObKPFD/api/input (around 1000 ms). The bootstrap call is a POST to /qYvdObKPFD/api, whose response carries the per-victim token, a mode flag, an isBlock flag and a custom JSON blob that themes the fake page (fine amount, notice text, the e-wallet "maintenance" message, decline strings). isBlock immediately bounces the visitor to the real mmda.gov.ph, which doubles as analyst and geo evasion. The live channel is a WebSocket at wss://<host>/ws?token=<uuid>.
The operator commands
The damning part is inbound. The server pushes a result_type message and the victim's screen switches on command:
The sequence of these commands tracks exactly what the attacker is doing on the real bank site in parallel.
Card capture and the 3-D Secure relay
The card view takes cardholder, full PAN, expiry and CVV, with light client-side validation (length, expiry not past, 3 to 4 digit CVV) and BIN-based brand detection across Visa, Mastercard, Amex, UnionPay, Discover, JCB, Diners, Maestro and Mir, purely to improve data quality for the operator. The e-wallet options (GCash, Maya, GrabPay) are shown and then forced into an "under maintenance" state, so the only working path is a bank card, because an e-wallet would not expose a PAN. On submit the client sends a submit_card event over the live channel and shows a fake processing modal ("Encrypting card information", "Waiting for bank authorization", invented transaction ID, fake "PCI-DSS Certified" badges) that exists only to buy the operator time at the real bank.
The three challenge paths (submitValidCode for SMS, submitAppValidCode for app approval, and a fully operator-templated custom view) let the panel reproduce whatever the real bank throws up. The custom view is the worst of it: its HTML, labels, button text and CSS all come from operator config, and it injects that HTML into a shadow DOM and executes any <script> tags inside it. That is operator-controlled script in the victim's browser, scoped to the phishing origin.
Attribution signals
This is a reusable, re-skinnable platform, not a one-off page.
- Leftover campaigns in the same build. The i18n bundle and residual components carry strings for other countries: a Cyprus "JCC Smart" card flow, a euro toll-payment variant (50 / 150 EUR tiers), and DHL-style payment CSS. The PH portal is one skin over a shared engine.
- The developer's language. The app bootstraps
vue-i18nwith the default locale set tobg(Bulgarian), and the address-form validation strings are in Bulgarian even though the victim copy is Tagalog and English. Bulgarian left in the shipped build points to the author's working language, consistent across the multi-region campaigns. wg026_phreads as a campaign or worker ID (wg026) bound to the Philippines target. Hunting thewg0NN_<cc>pattern across hosts is a plausible way to enumerate sibling campaigns.
The best pivots, since the domains are never search-indexed, are the admin path /qYvdObKPFD/, the asset namespace /wg026_ph/, the build directory /s/5a2f/e10d4/, the TokenDB / userToken schema, and the socket event names. Run those through urlscan, VirusTotal and crt.sh, not a web search.
This remains a supply-chain match to the Smishing Triad ecosystem, not a named-actor attribution. The Bulgarian locale and the shared multi-region engine point to one kit author or crew; who bought and ran the PH instance is a separate question the infrastructure alone does not answer.
Still open
- Neighbours on
43.157.225.99and other domains onns1/ns2.domainnamens.com. - The
wg0NN_<cc>pattern across other hosts, to map sibling campaigns from the same crew.
If you got this text
- Do not tap the link. The MMDA does not put links in NCAP texts.
- Check violations only on mayhulika.mmda.gov.ph, the eGovPH app, or your city's own NCAP portal for LGU violations.
- There is no late payment penalty on NCAP. Any text threatening one is a scam.
- If you entered card or e-wallet details, call your bank or e-wallet provider now, then report to the MMDA hotline 136, the CICC hotline 1326, or the PNP Anti-Cybercrime Group.
- If you entered your mobile number, expect follow-up calls or texts asking for an OTP. Never give it.
Indicators
# Lure
SMS sender ID MMDA§NCAP (spoof of MMDA_NCAP; § = ASCII 0x5F rendered as GSM-7)
SMS received 2026-10-10 11:32 PHT
# Domains
mmdancap.net primary portal
mmda-ncaplto.lol "official site" named inside the portal
# Registration (mmdancap.net)
Registrar Dominet (HK) Limited
Registered 2026-10-09 11:18 UTC
Expires 2027-10-09 11:18 UTC
Nameservers ns1.domainnamens.com, ns2.domainnamens.com
SOA ns1.domainnamens.com. hostmaster.wdomain.com. 2026100903
# Hosting
A 43.157.225.99 (no PTR)
Netblock 43.157.224.0/19
ASN AS132203 TENCENT-NET-AP-CN
# TLS
Issuer Let's Encrypt
Issued 2026-10-09 12:24 UTC
SANs mmdancap.net (single name)
# Cloak response (non-PH)
HTTP 404, nginx, text/plain, 9 bytes, body hash 0019dfc4b32d63c1392aa264aed2253c
# Kit shell (PH response)
/wg026_ph/2E4B33583.css
/s/5a2f/e10d4/index-57e948acef1.js
/s/5a2f/e10d4/index-877985f1e418.css
html lang="fr" data-skinbcn="base"
# Lure content
NOV numbers shown N26-55-104895, N26-67-090182 (generated per inquiry, any plate)
Payment methods E-Wallet (GCash, Maya, GrabPay), Bank Card (Visa, MC, Amex, JCB)
Payment page URL https://mmdancap.net (in-app view, no route change)
Apprehension date 05/10/2026 (DD/MM, = Oct 5, NCAP restart day)
Payment deadline 11/10/2026 (DD/MM, = next day when viewed)
Amount demanded PHP 1,000.00
Cited law R.A. No. 10913, Sec. 4
# Bundle
File index-57e948acef1.js (build-stamped 2026-08-25)
SHA-256 846e2223c50f6e2e1a5cb2192ea9487b3f52d64d402d9c6c5f058bfd43664cdb
Stack Vue 3.5.3, Pinia, vue-router (history mode), vue-i18n 10.0.4, axios 1.7.7, socket.io-client
# Kit endpoints
Bootstrap (POST) /qYvdObKPFD/api
Keystroke exfil (POST) /qYvdObKPFD/api/input
Live channel wss://<host>/ws?token=<uuid>
# Socket events
Client to operator login, input_text, submit_card, submitValidCode, submitAppValidCode
Operator to client result_type: otpValid, appValid, customOtpValid, otpFail, appFail,
success, back, reject, kickOut, block, reload, refresh
# Victim tracking
IndexedDB TokenDB (v2), store "tokens", key "userToken"
Cookie token, max-age=34560000 (~400 days)
Token transport Token header + X-Token header + token query param
# Server-side cloak
Bootstrap flag isBlock / isFirst (isBlock redirects to real mmda.gov.ph)
# Attribution
i18n default locale bg (Bulgarian); Bulgarian address-form validation strings
Residual campaigns JCC Smart (Cyprus), euro toll (50/150 EUR), DHL payment CSS
Campaign namespace /wg026_ph/ (wg0NN_<cc> worker/campaign pattern)# Lure
SMS sender ID MMDA§NCAP (spoof of MMDA_NCAP; § = ASCII 0x5F rendered as GSM-7)
SMS received 2026-10-10 11:32 PHT
# Domains
mmdancap.net primary portal
mmda-ncaplto.lol "official site" named inside the portal
# Registration (mmdancap.net)
Registrar Dominet (HK) Limited
Registered 2026-10-09 11:18 UTC
Expires 2027-10-09 11:18 UTC
Nameservers ns1.domainnamens.com, ns2.domainnamens.com
SOA ns1.domainnamens.com. hostmaster.wdomain.com. 2026100903
# Hosting
A 43.157.225.99 (no PTR)
Netblock 43.157.224.0/19
ASN AS132203 TENCENT-NET-AP-CN
# TLS
Issuer Let's Encrypt
Issued 2026-10-09 12:24 UTC
SANs mmdancap.net (single name)
# Cloak response (non-PH)
HTTP 404, nginx, text/plain, 9 bytes, body hash 0019dfc4b32d63c1392aa264aed2253c
# Kit shell (PH response)
/wg026_ph/2E4B33583.css
/s/5a2f/e10d4/index-57e948acef1.js
/s/5a2f/e10d4/index-877985f1e418.css
html lang="fr" data-skinbcn="base"
# Lure content
NOV numbers shown N26-55-104895, N26-67-090182 (generated per inquiry, any plate)
Payment methods E-Wallet (GCash, Maya, GrabPay), Bank Card (Visa, MC, Amex, JCB)
Payment page URL https://mmdancap.net (in-app view, no route change)
Apprehension date 05/10/2026 (DD/MM, = Oct 5, NCAP restart day)
Payment deadline 11/10/2026 (DD/MM, = next day when viewed)
Amount demanded PHP 1,000.00
Cited law R.A. No. 10913, Sec. 4
# Bundle
File index-57e948acef1.js (build-stamped 2026-08-25)
SHA-256 846e2223c50f6e2e1a5cb2192ea9487b3f52d64d402d9c6c5f058bfd43664cdb
Stack Vue 3.5.3, Pinia, vue-router (history mode), vue-i18n 10.0.4, axios 1.7.7, socket.io-client
# Kit endpoints
Bootstrap (POST) /qYvdObKPFD/api
Keystroke exfil (POST) /qYvdObKPFD/api/input
Live channel wss://<host>/ws?token=<uuid>
# Socket events
Client to operator login, input_text, submit_card, submitValidCode, submitAppValidCode
Operator to client result_type: otpValid, appValid, customOtpValid, otpFail, appFail,
success, back, reject, kickOut, block, reload, refresh
# Victim tracking
IndexedDB TokenDB (v2), store "tokens", key "userToken"
Cookie token, max-age=34560000 (~400 days)
Token transport Token header + X-Token header + token query param
# Server-side cloak
Bootstrap flag isBlock / isFirst (isBlock redirects to real mmda.gov.ph)
# Attribution
i18n default locale bg (Bulgarian); Bulgarian address-form validation strings
Residual campaigns JCC Smart (Cyprus), euro toll (50/150 EUR), DHL payment CSS
Campaign namespace /wg026_ph/ (wg0NN_<cc> worker/campaign pattern)Detection and hunting
- Network. A browser that POSTs to
/<random>/apiimmediately on load, then openswss://.../ws?token=<uuid>with a 2-second heartbeat, is the core behavioural signature. Theinput_textandsubmit_cardframe names on that socket, or a POST to.../api/inputcarrying{type, key, text}, confirm it. A non-gov.phhost rendering MMDA / NCAP branding is a strong content signal. - Browser artefacts. IndexedDB
TokenDB(storetokens, keyuserToken) or a long-livedtokencookie alongside MMDA-themedlocalStoragekeys (plateNumber,invoiceNumber,cardType) marks a visited session. - Hunt strings for proxy and scan logs:
wg026_ph,/qYvdObKPFD/,/s/5a2f/e10d4/,TokenDB,userToken, and the socket event names above. Run the paths through urlscan, VirusTotal and crt.sh, not open-web search, since the domains are never indexed.
Reporting and takedown
What can be done in such a case, this has been automatically done by FalconEye but just for reference:
- Registrar and host. File abuse for
mmdancap.netwith Dominet (HK) and with Tencent for43.157.225.99. Cloaking means a headless fetch will not reproduce the page, so attach the live browser capture and note the real-time card-and-OTP theft. - CERT-PH / NCERT. Report as an active financial-fraud phishing campaign targeting Philippine motorists.
- MMDA (hotline 136, official social accounts) and the CICC (hotline 1326): they already run NCAP-scam advisories and can fold this domain in.
- GCash fraud team. The MMDA has said it coordinates with GCash on these payments, so GCash is an established channel for tracing victim fund flow.
- Card schemes and issuers. Because the kit relays live 3-D Secure, treat any captured session as a full account-takeover attempt, not just PAN exposure. Advise exposed victims to call their bank, block the card, and ignore any push or OTP they did not start.
- Blocklists. Submit to urlscan, VirusTotal, PhishTank and Google Safe Browsing to shorten the smishing window.
Do not submit the card form from a real browser, even with junk. A submit fires submit_card on the live socket and registers in the operator console.
Sources
- MMDA warns public against fake NCAP traffic violation emails, DZRH, Jan 2026 (official sender IDs, no links, mayhulika.mmda.gov.ph)
- MMDA: Don't fall for 'NCAP' text scams, Inquirer, Jul 2026
- MMDA probes NCAP scams, Philstar, Aug 2026 (180+ complaints, no late fines)
- MMDA chair taps NBI to probe scam using NCAP, Inquirer, Aug 2026
- MMDA warns public anew over fake NCAP violation texts, payment links, Daily Tribune, Aug 2026
- NCAP implementation starts in parts of Metro Manila today, October 5, 2026, GMA News
- PNP backs resumption of NCAP in Metro Manila, Manila Times, Oct 2026 (June 3 SC decision)
- MMDA: NCAP resumes on Monday, May 26, 2025, GMA News
- Republic Act №10913, Supreme Court E-Library
- The Smishing Deluge: China-Based Campaign Flooding Global Text Messages, Unit 42
- China-based SMS Phishing Triad Pivots to Banks, Krebs on Security, Apr 2025 (Silent Push: Tencent AS132203, Alibaba)
- ON THE LATEST SPOOFING INCIDENT USING GLOBE SENDER ID, Globe statement via The Post, Jan 2025 (IMSI catchers)
- Smart, NTC collaborate vs use of fake cell towers, Philstar
- Appendix: The 7 bit default alphabet of GSM phones, Ozeki (GSM 03.38: 0x5F = §, 0x11 = _)
Reach out if you have questions or comments or want to collaborate
Reach out on session at Session ID: 059db238ab37c3d92615c5cc24b694da29c598cc13e27886053722404118e14271
FalconEye - Free OSINT Investigator's Toolkit Free self-hosted OSINT toolkit with 13 modules: crypto wallet tracer, phishing kit fingerprinting, domain intelligence…
OSINT and Cybersecurity Blog Stories around OSINT, Cybersecurity, Threat Intelligence, and other related topics.
OSINTPH: Digital Forensics & Cybersecurity Consulting Open source intelligence, digital forensics, and cybersecurity consulting from Bangkok and Manila, working with clients…
CyberNewsPH - Philippine Cybersecurity & Data Privacy News CyberNewsPH - Philippine Cybersecurity & Data Privacy News. Aggregated threat intelligence, breach alerts, NPC…