top of page
113 brands .png

Chapter 33: THE INTERNET LEAVES RECEIPTS

Updated: Jul 14

What a Casino Website, a Browser, and a Refusal to Back Down Taught Me About Documentation


I will not back down

There is a Tom Petty song whose title says the part I needed most:

I will not back down.

Not because I am fearless.Not because I am polished.Not because I always know what to do.

Because sometimes the only honest thing left is refusal.

Refusal to be managed.Refusal to let a half-truth become the record.Refusal to let silence do the work of a lie.

Last fall, I was not trying to become an internet infrastructure detective. I was trying to understand where my money had gone, who was actually involved, and why a polished casino website seemed to lead into a much messier machine underneath.

The front page said one thing.

The payment trail said another.

The people involved gave me fog.

The browser gave me receipts.

So I saved them.


The 200-processor mission

At the time, I was on what I now think of as the write-to-every-possible-payment-processor-until-someone-blinks mission.

Two hundred names.Two hundred possible doors.Two hundred chances that one company somewhere in the transaction chain would stop pretending the money had fallen from the sky with no parents.

It was humble work.

Which is different from small work.

Everyone is so obsessed with looking polished that they forget most meaningful work is held together by unglamorous labour: the follow-up email, the saved screenshot, the boring spreadsheet, the properly named file, the second request after the first one gets ignored.

Polish is what people see.

Documentation is what survives.

And if you stay with documentation long enough, sometimes it turns into momentum.

Real humility is not humiliation. It is not making yourself small. It is the ability to keep doing repetitive, unphotogenic work because the point is not how impressive it looks. The point is whether it is useful.

Sometimes the most important thing you do in a day is not cinematic at all.

Sometimes it is naming a file properly, saving the screenshot, checking the IP address, writing the email, and refusing to let a carefully polished lie become the official record.

But the machine was not talking to me.

That was the irony.

I was writing to processors, gateways, merchants, regulators, and support teams trying to make the system answer. The human side of the machine kept giving me silence, deflection, or carefully sanded-down non-answers.

So I went back to the part that still gave receipts.

The browser.


I am not a robot, but I learned to read the machine

The machine may not care.The machine may not comfort you.The machine may not apologize.

But the machine records.

That is where the old-school internet part of my brain comes in.

I learned computers when websites still had seams. HTML was not abstract to me. A webpage was something you could peel back. You could right-click. View source. Inspect. Follow the link. Break the table. Fix the tag.

The internet used to feel more physical.

Cables.Ports.Modems.Beige boxes.Computer labs.Screaming printers.Dead machines robbed for parts.Websites that looked like someone duct-taped them together with tables and optimism.

I did not grow up thinking websites were magic.

I grew up knowing they were built.

And built things have seams.

So when a modern casino website looked too smooth, I did what that older internet brain still knows how to do.

I looked underneath.

Not because I was hacking.

Because I was reading labels.


Momentum, opportunity, documentation

Three words kept showing up in this process:

Momentum. Opportunity. Documentation.

Momentum does not mean you know the ending.

It means you do not let silence become the ending.

You keep moving when the replies are useless. You keep asking when the answer is fog. You keep saving the receipts before anyone admits the receipts matter.

Opportunity is the moment where you know enough to know something is not okay, even if you do not yet have the perfect evidence package.

It is the moment where the polished version of the story stops working.

It is the instinct that says:

No.We are not pretending we did not see that.We are not waiting until the next crisis proves the last one was real.We are not letting silence become the official record.

And documentation is the discipline that keeps the work from becoming only emotion.

Document everything relevant.

Not everything.Not every panic thought.Not every scrap of noise your brain throws at you at 2:00 a.m.

But everything relevant.

Even if it is only a snip.Even if you do not know yet where it belongs.Even if all you can say is: this looks strange, and I do not trust myself enough to interpret it yet, but I trust myself enough to save it.

Because sometimes evidence changes grade.

The first time you see it, it is a C-minus.

A weird little detail.A screenshot you took because something in your gut went sideways.

Then months later, another fact arrives.

A name.A network.A report.A domain list.An IP block.A connection you did not have before.

Suddenly the same screenshot is not a C-minus anymore.

It is an A.

Not because the screenshot changed.

Because the context did.


The website was Neon54

The site was Neon54.

The public-facing path I was on was Canadian:

Not just a generic homepage. A Canada-facing environment with casino content, live casino content, sports, payment icons, account areas, and the usual polished offshore gambling wallpaper.

There was also:

A live casino section under the Canada path.

On the surface, it looked like a normal casino website.

That is what the surface is for.

But behind the surface, Chrome DevTools was showing the working parts.

One of the key screenshots from last fall showed a request to a Neon54 Canada account endpoint:

The response was successful.

The remote address shown in DevTools was:

185.207.196.198:443

That one number mattered later.

At the time, it was just a receipt. A technical breadcrumb. An address the machine gave me while the people were busy not answering.


Domains for people who thought DNS was a vitamin

Before we go further, let us make this painfully plain.

A website is not just a website.

A website is a sign on a building.

Sometimes the building is behind a curtain.

Sometimes the curtain is in front of a hallway.

And sometimes the hallway leads to an entire warehouse full of suspiciously similar casino signs.

A domain is the human-readable name.

Example:

A path is the part after the domain.

Example:

/ca

So neon54.com/ca is not a separate website. It is a Canada section inside the main Neon54 domain.

But 10neon54.com is different.

That is not a path.

That is a separate domain.

That distinction matters.

neon54.com/ca is the Canadian room inside the Neon54 house.

10neon54.com is another house with a very similar sign.

DNS is the phone book that tells the browser where a domain lives.

An A record is the part of DNS that says: this domain points to this IP address.

An IP address is the machine-ish address.

An IP range is a block of addresses.

An ASN is the network identity announcing that block.

BGP is how big networks tell each other where to send traffic.

BGP.he is one of the ugly public phonebooks for that routing world. IPinfo is another lookup tool that helps identify the network, ASN, country registration, hosted-domain counts, upstreams, and related metadata. Host.io tells you what else has been seen on or near the same hosting.

None of these tools are magic.

They do not prove legal ownership by themselves.

They read public plumbing.

And sometimes the plumbing is more honest than the front desk.


The IP address that changed grade

Months later, I circled back to FinTelegram.

That distinction matters.

I did not start with FinTelegram.

I started with my own DevTools screenshot.

I had already captured the Neon54 Canada account endpoint showing:

185.207.196.198:443

Then later, FinTelegram published reporting about NALMI / AS213846 and a casino-domain infrastructure cluster around:

185.207.196.0/22

That is when the old screenshot changed grade.

Because 185.207.196.198 sits inside 185.207.196.0/22.

Public IP/BGP data associates that block with AS213846 / NALMI LIMITED.

That means the screenshot I saved months earlier was not just a random DevTools curiosity.

It placed a Neon54 Canada account API request inside the same NALMI-linked IP block later discussed as part of a wider casino-domain hosting envelope.

Carefully:

That does not prove NALMI owns Neon54.

It does not prove NALMI processed my payment.

It does not prove every domain in the block is legally connected.

But it does prove something worth documenting:

A Canada-facing Neon54 account endpoint was observed using an IP inside a NALMI / AS213846 routed hosting block.

And once you know that, you look at the rest of the block.


Then the domain drawer opened

The BGP.he / Hurricane Electric output for the NALMI block was not a neat list of one or two things.

It was a drawer.

A very full drawer.

The output for 185.207.196.x listed domains mapped across IPs in that range. It included ordinary-looking infrastructure names, strange random strings, and a large number of casino-brand variants.

And not just one casino brand.

Many.

Neon54 variants appeared in the list, including:

These were not paths like /ca.

These were separate domains.

Some had numbers before the brand. Some had numbers and a hyphen. One looked typo-like. And they were sitting inside the same 185.207.196.x NALMI block.

That is when the story stopped being one IP address and became a better question:

Why are there multiple Neon54-looking domains in the same infrastructure range as the Canada account API IP?

Then came the rest of the drawer.

The same list contained brand roots and variants that looked like:

Wazamba, Robocat, Spinanga, Kingmaker, Mr Pacho, ZetCasino, PowBet, Buran Casino, Casinia, Rabona, MyEmpire, Cadoola, Nomini, LuckyHeroes, Lucky Elektra, GeniePlay, Boaboa, Malina, FezBet, SlotsPalace, Sportuna, AmunRa, and many others.

Some were clean brand names.

Some were numbered variants.

Some were typo-like.

Some looked like app routes.

Some looked like campaign domains.

Some looked like decoys invented by a slot machine during a power outage.

But the pattern was not subtle.

This was not one casino website sitting alone in a field.

This looked like a domain-farm environment.


Neon54-style domains observed in the NALMI 185.207.196.x list

The table below is pulled from the BGP.he / Hurricane Electric text export. It lists the Neon54-style domain names visible in that extract, with the IP row where each appeared.

Neon54-style domain

IP in NALMI block

Observed pattern

185.207.196.9

number + brand

185.207.196.9

brand + number / typo-like

185.207.196.18

number + brand

185.207.196.30

number + hyphen + brand

185.207.196.68

number + brand

185.207.196.68

number + brand

185.207.196.94

number + brand

185.207.196.100

number + brand

185.207.196.109

number + hyphen + brand

185.207.196.123

number + brand

185.207.196.127

number + brand

185.207.196.129

number + brand

What a domain farm means, and what it does not mean

A domain farm is a large collection of related-looking domains used around the same ecosystem.

It may include brand variants, typos, numbered mirrors, campaign domains, affiliate routes, backup domains, app domains, country routes, test deployments, and blocked-domain replacements.

Not every domain in a farm has the same legal owner.

Not every domain is active.

Not every domain is official.

Not every domain proves wrongdoing.

But the clustering matters.

If one domain says Neon54, and another says Neon54 with a number, and another says Neon54 with a different number, and they sit in the same IP block as many other casino-brand variants, that is not a final legal conclusion.

It is an investigative finding.

It tells you where to ask the next questions:

Do these domains redirect?Where do they redirect?Do they land on the same brand?Do they show the same operator footer?Do they use the same payment stack?Do they call the same APIs?Do they use the same Cloudflare setup?Do they expose the same merchant ID?Do they connect to the same app or Android route?

These are the questions that turn a domain list into evidence.


The redirects matter

When a suspicious-looking domain resolves, that is one level of significance.

It means the domain is configured in DNS.

It is not just dead text.

When it redirects, that becomes more interesting.

A redirect says:

You asked for this door, but I am sending you to that door.

In normal businesses, redirects can be boring. A company may redirect old domains, misspellings, campaign pages, or region-specific domains.

In offshore casino ecosystems, redirects can be more revealing.

They may show mirror infrastructure, affiliate funnels, blocked-domain workarounds, country targeting, backup access, brand migration, traffic attribution, app download routes, or campaign routing.

When the Neon54-like domains resolve and redirect, they are no longer merely names in a list.

They are active routing artifacts.

They are part of the machine.


The Swiper-Android oddity

One domain in the list stood out because it carried a word already relevant elsewhere:

It appeared in the same micro-cluster as:

That does not automatically prove it is connected to the Ontario-facing Swiper / Canadix entity.

It does not prove Canadix controlled it.

It does not prove the regulated Swiper product was involved.

But as an infrastructure lead, it is interesting.

It places a Swiper-labelled Android-style domain in the same NALMI IP neighbourhood as Neon54, Kingmaker, Mr Pacho, Robocat-style, and slot-brand variants.

If it was disabled when checked, that does not make it irrelevant.

Disabled domains can still be evidence of prior routing, app plans, campaign infrastructure, abandoned deployments, or domain-farm naming logic.

Sometimes a closed door is still useful because it tells you the hallway existed.

The app angle

The app trail is another drawer.

Modern gambling sites often blur the line between mobile website, progressive web app, home-screen shortcut, Android APK, affiliate app-review page, and actual native app.

An APK is an Android install file.

If a casino tells people to download an APK directly, that is more serious than a mobile website because it may bypass normal app-store review.

A PWA is a website behaving like an app, with icons, cached files, and sometimes service workers.

An affiliate app page may not be official at all.

It may just be search-engine bait.

But when a domain farm contains Android or app-labelled domains, and the casino brand has app-style pages floating around the web, the question becomes reasonable:

Is there app-routing infrastructure connected to the same ecosystem?

If yes:

What domains does the app call?What payment endpoints are embedded?What package name is used?Who signed the APK?What permissions does it request?Does it use the same Neon54 account/payment environment?Does it route through the same NALMI block?

Again:

Questions, not conclusions.

But good questions.


The payment layer

The payment side was the original reason I was there.

The front end said casino.

The transaction trail said:

Find the processor.

The evidence I captured included PaymentIQ/payment-gateway style material and a merchant ID that appeared in the Neon54 payment context:

merchantId=100206305

A payment gateway is not necessarily the merchant of record.

A payment gateway is not necessarily the acquirer.

A payment gateway is not necessarily the company that held the customer relationship.

But it is part of the transaction machinery.

If the same merchant ID appears in payment configuration resources and in a successful transaction response, that matters.

It supports a payment-chain map.

Not the final answer.

A map.

And when the front-facing site is localized for Canada, while the payment evidence shows layered gateways, offshore operator disclosures, and infrastructure in a wider casino-domain environment, the compliance questions become obvious.

Who was the merchant of record?Who controlled the PaymentIQ merchant account?Who was the acquirer?Who processed the card transaction?Who received the funds?Who configured Canada-facing payment methods?Who decided what currency was displayed?Who decided how the backend represented the transaction?Who retained logs?Who can produce the authorization, 3DS, routing, and settlement records?

When everyone tells the customer to go ask someone else, those are the questions they are avoiding.

The operator layer

Neon54 has been publicly associated with Stellar Ltd and an Anjouan licence.

That matters because a website’s public operator disclosure is one layer of the story.

The infrastructure is another layer.

The payment stack is another.

The domain farm is another.

The customer-facing country path is another.

None of these layers alone is the whole truth.

But when layers overlap, the questions get sharper.

A Canada-facing path.A live-casino product.Payment icons.Payment gateway calls.A merchant ID.A DevTools remote IP inside 185.207.196.0/22.NALMI / AS213846 public IP/BGP records.A domain list containing multiple Neon54 variants and many other casino-brand variants.Later public reporting describing the same NALMI range as a casino-domain hosting envelope.

That is not a conclusion written in stone.

It is convergence.

And convergence is where due diligence should begin.


Why FinTelegram mattered later

The FinTelegram piece did not create the trail for me.

It named a piece of the trail I had already touched.

That distinction matters.

I had the fall screenshots first.

I had the Neon54 Canada account endpoint.

I had the IP.

I had the payment fragments.

I had the feeling that the machine was telling a different story than the humans.

Then later, FinTelegram’s reporting on NALMI / AS213846 and the 185.207.196.0/22 casino-domain ecosystem gave external context to the same infrastructure neighbourhood.

Their view was the aerial map.

Mine was the street-level receipt.

That is how investigations often work.

You collect a thing before you understand it.

Someone else publishes a wider frame.

You go back.

The old thing changes grade.

And suddenly the drawer has a label.


What this proves

This is the careful part.

The evidence supports that a Neon54 Canada account API request was observed in DevTools with remote address:

185.207.196.198:443

That IP sits inside:

185.207.196.0/22

Public IP/BGP sources associate that block with:

AS213846 / NALMI LIMITED

The same NALMI 185.207.196.x dataset contains multiple Neon54-style domains.

The same dataset contains many other casino-brand and casino-variant domains.

Several domains appear to resolve and/or redirect, making them active infrastructure leads rather than dead names.

The structure is consistent with a domain-rotation, mirror, app-routing, campaign, or casino-brand infrastructure environment.

PaymentIQ/payment-gateway evidence and merchant-ID material suggest a separate but related payment-chain inquiry.


What this does not prove

It does not prove NALMI owns Neon54.

It does not prove NALMI operates Neon54.

It does not prove NALMI processed the payment.

It does not prove every domain in the NALMI block has the same legal owner.

It does not prove every domain is official.

It does not prove Cloudflare operates the casino.

It does not prove a disabled app-looking domain was used for customers.

It does not replace transaction-level evidence from the merchant, gateway, acquirer, processor, or card network.

This distinction matters.

If the goal is truth, not just heat, you have to know where the evidence stops.

But where it stops is not nowhere.

It stops at a very strong question.


The question

Why did a Canada-facing Neon54 account environment show an IP inside a NALMI / AS213846 hosting block that also contains multiple Neon54-style domains and a large casino-brand domain cluster?

That is the question.

Not the only question.

But the one that turns the drawer upside down.


The broader problem

The bigger issue is not one casino domain.

It is the architecture of plausible deniability.

The customer sees a brand.

The website discloses one operator.

The payment page may involve another gateway.

The card descriptor may show another merchant.

The processor may point to the bank.

The bank may point to the merchant.

The merchant may point to support.

Support may point to terms.

The terms may point offshore.

The infrastructure may point somewhere else entirely.

The customer is expected to give up somewhere in the maze.

That is the business model of exhaustion.

And that is why documentation matters.

Because when every human channel says “not us,” the machine may still show who was in the room.


The human part

This is where I keep coming back to the words:

Momentum. Opportunity. Documentation.

Momentum kept me writing when the replies were useless.

Opportunity told me when the facts were incomplete but the situation was not okay.

Documentation let me save the fragments before I knew what they were worth.

And somewhere in there is the Tom Petty lesson I needed:

Not a tidy strategy for winning the table.

Just the plain refusal to fold because the room expects exhaustion to do its work.

Sometimes you stay standing because the evidence matters.

Sometimes you keep the receipts because the story is not finished.

Sometimes not backing down is not aggression.

It is record-keeping with a pulse.

I did not need to be certain to preserve the evidence.

I did not need to have the whole map to know the front page was not the whole story.

That is the part I think people miss when they talk about investigations like they are clean, linear, professional things.

They are not.

Sometimes they are a person in a messy room with too many tabs open, trying to keep enough momentum to not drown in the silence.

Sometimes they are a screenshot taken months before anyone else gives you the vocabulary for what you saw.

Sometimes they are a strange little IP address that waits in a folder until the day it becomes important.


Final word

The internet leaves receipts.

Not always clean ones.

Not always complete ones.

Not always the ones you wanted.

But it leaves them.

A domain points somewhere.An IP sits in a block.A block belongs to an ASN.An ASN has peers and upstreams.A payment page calls a gateway.A redirect sends one door to another.A supposedly separate domain lands in the same drawer as twelve cousins wearing the same fake moustache.

The job is not to pretend every receipt is a conviction.

The job is to keep the receipts long enough to know what they are.

Last fall, I saved the screenshots.

Months later, I circled back.

The machine still had not talked to me in words.

But it had been talking the whole time.



 
 
 

Recent Posts

See All
Oh Shit, Guys… I’m Alive. Well…

I’m alive. It’s Tuesday night. About 8:50 p.m. Roughly thirty-six hours ago I was being wheeled into surgery. Now I’m home. I’ve had a real shower. I’m wearing my own pajamas. And yes… I’m currently h

 
 
 

Comments


bottom of page