2.1 Generator attribution — cheap, and usually decisive
observed
Check the generator meta tag and the build-artifact naming before anything else. AI site generators emit a machine-readable signature, and their deployment slugs follow a fixed pattern. In this case every page in the operation carried <meta name="generator" content="v0.app"/>.
This single observation collapses a lot of speculation. Deployment suffixes that looked like deliberate naming — a sequence of Greek letters across multiple hosts — are the generator's default slug algorithm, not an evasion tactic. A hypothesis that was previously carried as "possible takedown evasion" became refuted: no operator intent is required to explain it.
GENERATOR SIGNATURES · BUILD METADATA · HYPOTHESIS REFUTATION
2.2 Deployment correlation by content, not by name
observed
Similar names are not evidence of common ownership. Correlation requires matching artifacts: identical form field sets, identical contact strings, identical component vocabulary, and — the strongest signal — distinct deployment identifiers per host, each with its own server-action hash.
Here, two live hosts shared a branding layer and an identical data-collection purpose while carrying independent deployment IDs and independent action IDs. That is a common author or a common template authored once and deployed repeatedly. The distinction matters: it is the difference between "someone copied this" and "someone is running this."
ARTIFACT COMPARISON · DEPLOYMENT IDS · SERVER ACTION HASHES
2.3 The architectural contradiction test
observed
The useful question is not "does a payment form look suspicious" — a legitimate merchant checkout also asks for a card. The question is whether the pipeline behind the form can do what the form's own text claims.
Procedure: retrieve every JavaScript bundle the application loads, extract every absolute URL literal, and enumerate every network destination. Then compare that list against the claims the page makes about itself.
In this case, all 14 bundles from both hosts (642 KB) were retrieved. The complete set of destinations was framework and library documentation URLs, an analytics script, and the host's own feedback widget — no application endpoint, no data store, no payment gateway of any kind. The page nonetheless told visitors they would pay "through a secure official gateway." That claim has no implementation behind it.
The finding is therefore architectural rather than inferential: the page's own reassurance is contradicted by its own code. This is the difference between a domain-logic argument ("tires don't need card details") and a measurement.
BUNDLE ANALYSIS · ENDPOINT ENUMERATION · CLAIM-IMPLEMENTATION MISMATCH
2.4 Duration from infrastructure state
inferred
Nobody publishes a deployment timestamp to anonymous callers — the platform API returns 403 and the deployment ID is not a decodable timestamp. Duration has to come from observable state instead.
Two derivable signals: the edge cache age reported by the host on each response, and the first nonzero response across all record types for any domain the operation claims. Both are inferences from observed headers, and both should be labelled as such.
A domain check is where over-claiming is easiest. A name appearing in the operation's own contact strings is a lead, not an indicator. In this case the domain did not exist at all — WHOIS returned no match and every DNS record type returned NXDOMAIN. The apex zone SOA that appears in those responses is present on every NXDOMAIN for the TLD and is not evidence of a child zone. An inferred registration, published as fact, is the defect a reviewer will find first.
EDGE CACHE AGE · DNS RECORD SWEEP · WHOIS · INFERENCE LABELLING
2.5 Independent timestamping before escalation
method
Everything above is worthless if the operation disappears first. Archival to a third-party service must precede any notification, and the artifact hashes must be captured at retrieval time.
Order matters: archive, hash, then notify. Notifying first gives the operator the one signal they respond to, and the evidence chain is gone. Where the collected data has no external destination — as established in 2.3 — the host's own records are the evidence chain, which raises the priority of a preservation request from "useful" to "the entire case."
THIRD-PARTY ARCHIVAL · ARTIFACT HASHING · PRESERVATION SEQUENCING