Spam Campaign – Persistent Redirection Network
Building on the initial findings, deeper analysis of the latest QS-SLIE extraction reveals a maturing spam operation using professional HTML templates, hidden obfuscation layers, and a network of short-lived redirect domains. The campaign continues to push fake "Indigo" and "Destiny" Mastercard offers while mixing in job-application lures to boost open rates.
The program has now processed multiple runs, revealing consistent infrastructure patterns and evolving social engineering tactics.
QS-SLIE Program Overview
The QuantSec SpamLink Intelligence Extractor (QS-SLIE) continues to deliver high-value data. In these runs it:
Extracted full HTML bodies with smart naming
Parsed links, domains, and tracking parameters
Generated structured CSVs for graph analysis and blocklist creation
Produced actionable intel (blocklist.txt) for immediate defensive use
This internal tool is proving its worth in turning raw spam into structured threat intelligence for protective operations and client deliverables.
Deeper HTML & Link Analysis
The latest samples show advanced email crafting:
Obfuscation Techniques
Multiple hidden sections using extreme CSS (max-height:calc(1vw - 1vw), clip-path: inset(100%), tiny fonts, opacity 0.1) — designed to hide text from filters while remaining in the DOM.
Heavy use of tables for layout control and visual card mockups with gradients and Mastercard branding.
Fake job application emails as openers (e.g., "Supplement your application" for Machine Operator role at RailTech Solutions) to increase engagement.
Link & Redirect Patterns
Consistent use of alphanumeric redirectors: /r[0-9a-f]+\.php?32=... with long encoded parameters for tracking.
Unsubscribe links frequently lead back to the same infrastructure, enabling double-click harvesting.
Examples from the latest data: http://h.louisvillepropellerclub.com/r62af.php?... Multiple variants on domains like dk.corporatekits.in, tg.hilldew.com, op.ss2526.com
Visual & Messaging Tactics
Professional card visuals with "Indigo Mastercard" branding, "$1,000 Credit Limit", "No Security Deposit", and urgency language.
Fake legal footers with company details, addresses, and disclaimers to appear legitimate.
Infrastructure Insights
The campaign relies on a rotating set of short-lived domains, many with random-looking subdomains. Top recurring hosts from both runs (after exclusions) include: bn.tarabuh.com, yh.isafund.com, tg.hilldew.com, op.ss2526.com, tk.trudiannetemple.com (4 hits each). Several 3-hit domains focused on loan spam and unsubscribe collection.
The operation shows signs of testing and refinement — mixing credit offers with job lures and using obfuscation to bypass filters.