How to take down sites hosting CSAM

stencildosage

Newbie
Joined
Dec 12, 2025
Messages
0
Reaction score
3
i'm trying to take down a site hosting CSAM (child sexual abuse material) but none of the hosting providers respond to inquiries as they're using bulletproof hosting, Cloudflare reports are ignored too

they're on BuyVM and PRQ for domain services, i think they just ignore abuse reports that don't come with a warrant, what's the best way forward?
 
Contact Homeland Security Investigation. Those websites are likely already on their radar/and or being used as honeypots that they have already seized to catch the perpetrators that look at that. HSI/FBI do seize those domains and learn who the users are and make arrests they shut them down.

They use a new type of search warrant that downloads malware onto computers which can bypass VPN/TOR and find the users real IP address while searching their connected devices for illegal materials, prior to getting a search warrant to search their homes and seize devices.

Report the websites to authorities. Let them do their jobs. You may be getting ignored because of what I mentioned.
 
I think they're now owned by Cloudzy. So the team at Cloudzy should listen. Have you tried reaching out to them?
i contacted Cloudzy since they were listed on the BuyVM contact page, but they said that since it's behind Cloudflare they don't know which customer is behind the VM, convenient excuse but fair enough, at least i got a response there

BuyVM and PRQ never responded to my email and contact form submissions
If they're on BuyVM, maybe you can ping Francisco directly?
has he got an email that is not [email protected] i should cc?
 
i contacted Cloudzy since they were listed on the BuyVM contact page, but they said that since it's behind Cloudflare they don't know which customer is behind the VM, convenient excuse but fair enough, at least i got a response there

BuyVM and PRQ never responded to my email and contact form submissions

has he got an email that is not [email protected] i should cc?
There’s ways to find their server ip. If they have a mail server it won’t be behind CF. You can’t do that. With your terminal ping mail.domain.com and other mail server subdomains. You might get lucky. I’ve found many websites real ip just like that. There’s a lot of scammers in my niche. I get them taken down just like that.
 
@nicenic they have a domain from you guys, as well, hosting CSAM

i sent two reports but you didn't get back to me, i suspect because the instructions are hard to follow, how can i get in touch?
Dear stencildosage,

Thank you for bringing to our attention the domain names mentioned here. To proceed with a proper investigation, please provide your ticket number. Our abuse team will promptly review the submitted cases and take appropriate action based on our findings.

Best regards,
NiceNIC.NET Abuse Team
ICANN, Verisign & HKIRC Accredited Registrar
Domains | Business Email | SSL Certificates | Hosting | API Integration
 
please provide your ticket number.
i submitted normal abuse reports, and these did not give me a ticker number

i have now created a normal ticket with category "other inquiries" and detailed the abuse, explained how to access it and sent a number of offending urls, please take a look.

Ticket ID: 490386
 
i submitted normal abuse reports, and these did not give me a ticker number

i have now created a normal ticket with category "other inquiries" and detailed the abuse, explained how to access it and sent a number of offending urls, please take a look.

Ticket ID: 490386
Thank you for your time. Our abuse team is expediting the review for you.
 
I have an immense amount of respect for you for being so determined about this.
thank you, in fact i can report that some of the domains were taken down, the nicenic one included

i think more will pop up, but i'll keep reporting them now that i've seen some success ;)

i think i figured out the modus operandi to take action against these type of sites, but i appreciate your offer of help
 
thank you, in fact i can report that some of the domains were taken down, the nicenic one included

i think more will pop up, but i'll keep reporting them now that i've seen some success ;)

i think i figured out the modus operandi to take action against these type of sites, but i appreciate your offer of help
I battled a scammer in my niche for a couple of years that was setting up pure scam ecom websites that would just take peoples crypto and they would not receive their purchase (very stupid purchase). I was getting them taken down by reporting their use of copyrighted content. They were scraping me and my legit competitors. What you are doing can be automated potentially. I did.

What entities are you reporting to?
 
I battled a scammer in my niche for a couple of years that was setting up pure scam ecom websites that would just take peoples crypto and they would not receive their purchase (very stupid purchase). I was getting them taken down by reporting their use of copyrighted content. They were scraping me and my legit competitors. What you are doing can be automated potentially. I did.

What entities are you reporting to?

I'd be happy to prep an automation for this.
 
Well I’m not looking at any of that stuff but I would absolutely be happy to provide assistance or guidance for the automation of identifying and reporting to registry and/or hosting.

The operation is pretty simple. Scrape daily like you’d scrape for anything using the common footprints, confirm the site is or likely is the content you want to report, get url, check Whois, submit complaint to registrar, and hosting.

Just make a list manually of the contact forms in the beginning as it goes, and create the script for contact form submission for each or search with Xpath for form fields avoiding honeypot fields. Integrate something like Xevil, and capmonster cloud to solve the captchas on the form if any.

Use the same browser fingerprint for everything so it looks like a legit browser over time and you might not get as much captcha or as hard to solve.
 
Back
Top