Spam Campaign – Persistent Redirection Network

Building on the initial findings, deeper analysis of the latest QS-SLIE extraction reveals a maturing spam operation using professional HTML templates, hidden obfuscation layers, and a network of short-lived redirect domains. The campaign continues to push fake "Indigo" and "Destiny" Mastercard offers while mixing in job-application lures to boost open rates.

The program has now processed multiple runs, revealing consistent infrastructure patterns and evolving social engineering tactics.

QS-SLIE Program Overview

The QuantSec SpamLink Intelligence Extractor (QS-SLIE) continues to deliver high-value data. In these runs it:

  • Extracted full HTML bodies with smart naming

  • Parsed links, domains, and tracking parameters

  • Generated structured CSVs for graph analysis and blocklist creation

  • Produced actionable intel (blocklist.txt) for immediate defensive use

This internal tool is proving its worth in turning raw spam into structured threat intelligence for protective operations and client deliverables.

Deeper HTML & Link Analysis

The latest samples show advanced email crafting:

Obfuscation Techniques

  • Multiple hidden sections using extreme CSS (max-height:calc(1vw - 1vw), clip-path: inset(100%), tiny fonts, opacity 0.1) — designed to hide text from filters while remaining in the DOM.

  • Heavy use of tables for layout control and visual card mockups with gradients and Mastercard branding.

  • Fake job application emails as openers (e.g., "Supplement your application" for Machine Operator role at RailTech Solutions) to increase engagement.

Link & Redirect Patterns

Visual & Messaging Tactics

  • Professional card visuals with "Indigo Mastercard" branding, "$1,000 Credit Limit", "No Security Deposit", and urgency language.

  • Fake legal footers with company details, addresses, and disclaimers to appear legitimate.

Infrastructure Insights

The campaign relies on a rotating set of short-lived domains, many with random-looking subdomains. Top recurring hosts from both runs (after exclusions) include: bn.tarabuh.com, yh.isafund.com, tg.hilldew.com, op.ss2526.com, tk.trudiannetemple.com (4 hits each). Several 3-hit domains focused on loan spam and unsubscribe collection.

The operation shows signs of testing and refinement — mixing credit offers with job lures and using obfuscation to bypass filters.

Previous
Previous

Suspicious USFHP Disenrollment Email: Legitimate Infrastructure Abuse and Secondary Clusters

Next
Next

Spam Campaign Analysis: Infrastructure Overlapping Security Scanning Platforms