One Mill, Seventy-Two Costumes
Actionable intel article · TLP:CLEAR · Quantitative Security · @unccno · 2026-08-27 mail pull through 2026-08-28 HTTP/CAKE probes · 72 messages · 156 unique links
Do not visit r*.php?32= URLs, unsubscribe links, Policy Plug widgets, taobmaets.com, or keycanvascanvas.com. HEAD 403 does not mean the kit is down. LendingTree (NMLS #1136) is a footer-theft victim, not the sender.
What this is
On 27 August 2026 a single Gmail inbox took a burst of unsolicited auto-insurance and credit-card “offers.” Different From lines, different aged domains, different subject costumes. Not 72 companies. One snowshoe lead mill.
Every HTML body and every HTTP link carried e6jbv4z. Clicks were always the same machine-written shape: a two-letter label on an old-looking apex, a hex-named PHP script, a long 32= token. Policy Plug (51/72), Easy Insurance Match, Endurance, Indigo and Destiny Mastercard were wardrobe. A large subset stole LendingTree’s NMLS #1136 and 1415 Vantage Park Drive, Suite 700, Charlotte, NC.
Mail and clicks sat on NForce AS43350 in 185.47.200.0/24 and 185.47.203.0/24: nginx, PHP 7.4.33, no 443, filtered 25. Domains were aged Name.com inventory, many created in early May/June between 1998 and 2011, then burned after a short tour as ze., qm., fk., dx. and fifty other labels.
The PHP script is not the payload. It is a method-filtered 302 hop. HEAD gets a generic nginx 403. A browser-like GET returns 302 plus window.location.replace toward a CAKE lander (a=44&c=2701) on taobmaets.com (“steamboat” reversed) or an unsubscribe page on keycanvascanvas.com. Attachments named .docx / .pptx are plaintext. file(1) never saw ZIP/OOXML. ClamAV found nothing. The click wrap is the product.
Why the cluster holds
QS-SLIE’s subject clustering only produced three duplicate pairs. That is the mill working as designed. Subjects are padded with whitespace, circled letters, homoglyphs, and CJK/Hangul/Cyrillic/Thai junk so subject-only clustering fails. The invariant is the token.
Actionable intelligence
High-precision indicators
Use these if you already filter snowshoe lead spam. Do not spray every aged Name.com domain.
Still had A records on 28 Aug (20 of ~75 FQDNs):
lu.karupsdb.com .60, fk.frizzaway.com .61, ze.mediaignorance.com .65, dx.venduvent.com .66, sx.lubovniki.com 185.47.203.140, rf.gormeting.net .141, plus HostDime / DreamHost / Hetzner / IPXO outliers (sandhyashahmd, wophp, sinhalabuddhist, risaonline, dawncreations, casafaiola, and a handful of 184.171.240 / 198.136.51 hosts). The other 55 labels were already NXDOMAIN. Keep them as historical IOCs.
Detection notes that save false negatives
Do not key liveness on HEAD. 403 + charset=iso-8859-1 and no X-Powered-By means nginx refused HEAD.
GET + a mundane Mozilla UA is what produces 302 + PHP/7.4.33 (one host answered 7.2.24).
SPF, DKIM selector1, and DMARC p=REJECT can all pass. Auth-pass is not brand-pass.
Inner Received claiming Amazon SES (54.240.77.81, X-SES-Outgoing dated 2018-07-18) is costume. Gmail accepted NForce .65.
Score plaintext “.docx” that starts with a repeated sender domain, not OOXML.
Cluster on the token and path, not the subject.
Sensor IPs 192.168.1.73 and 172.20.10.3 in the case notes are inventory, not IOCs.
Report targets
Unredacted WHOIS on hassrods.com, 2kland.us, cigarweb.us, indiancremation.us: Robert Carpino, Granada Hills CA, +212.661625169, edcopm13g@gmail.com. Same name is tied (redacted or historically) to mediaignorance.com, sandhyashahmd.com, casafaiola.com, risaonline.com. That is a pivot, not a charging document.
Downstream landers — document, do not fetch
2025-02-24, AWS us-east-1. Direct GET of /+query was IIS 404 + sid/trk cookies (bot-gated).taobmaets.com— CAKE a=44&c=2701,Name.com.keycanvascanvas.com— unsubscribe, Name.com 2025-02-28, Cloudflare, CSP allows api.optoutsystem.com
URL tag mix on 156 links: no tag 84, _3bg4 34, _20y4 22, _20z4 12, _24x4 4. Stem 1o136a577c6a08aef without a click tag mapped to unsubscribe. Tail MHBnNTAyc2l2aTIx → 0pg502sivi21, split into CAKE s3/s5.
Do: sinkhole token + path + the two /24s if policy allows; file ASN/registrar abuse with 72/72 and the shared-vhost hash; warn that NMLS 1136 in a footer is not LendingTree mail; keep burned labels.
Do not: click the hop “to see if it still works”; publish this as a kill list; treat 71 From domains as 71 businesses.
Tools used to gather and parse
The point of the day is the pipeline, not a single scanner.
Collection
Gmail Show original — message.eml for the mediaignorance sample (~13:45 PDT 27 Aug), including the real outer hop and the fake SES block.
QS-SLIE in_spam — exploded 72 messages into messages.tsv, metadata.jsonl, campaigns.json, unique_urls.txt, extracted_links.csv, attachment index (202 rows).
Gmail had already labeled the stream SPAM.
Parse and cluster
QS-SLIE campaign keys — only 3 official pairs; forced the token as the cluster key.
summary.json — 72 / 202 / 156 / 71 hosts / 0 real Office.
file(1) — every fake Office part was ASCII or UTF-8.
SHA-256 — caught {msg_id}_unknown filename collisions (183 files on disk vs 202 indexed parts).
ClamAV — 0 infected. Negative result that stops a malware sidetrack.
Manual HTML counts — Policy Plug 51, stolen address 29, NMLS 25.
DNS / WHOIS / snowshoe
A / NS / MX → dns/hosts.tsv, dns/ips.tsv (20 live / 55 burned).
/ New Frontier) → unredacted Carpino on four apexes; May/June anniversary ages 1998–2011.WHOIS (Name.com) (recon siblings, not necessarily in the 72-mail set).subfinder + assetfinder → 447 unique names in subs/all_unique.txt; rest-list siblings such as onlyconveyancing.com and torahtorahtorah.com
Host and hop
HTTP:80 Host probes — Host: mediaignorance.com on all seven 185.47.200.60–66 IPs returned identical 200 / 52667 bytes, sha256 3be462b23bf540f098695092d977eec91883a1dcee031ef7979237dad1fa3f04.
Default vhost vs named Host — .63 (ffxivforums.com) default 404; named Host serves the lander.
nmap / masscan — :443 closed, :25 filtered, :80 open.
HEAD sweep of 156 URLs — 49×403, 107×NXDOMAIN, 0×302. The trap.
GET + User-Agent: Mozilla/5.0 — 302 + X-Powered-By: PHP/7.4.33 + JS replace. This is kit state.
CAKE parameters read from Location only. Stop before the offer form.
Local sensors that did not prove the mill
ChronoGuard, QuantumGuard, QuantC, QSlueth were running on the recon box. The readable ChronoGuard log shows process start and an NTP block of 0.0.0.0/0. It does not contain e6jbv4z, 185.47.200, or mediaignorance. Most other sensor files were root:root mode 600 and were not used as campaign evidence. Collection fabric ≠ cluster proof.
Reproduce the method, not the clicks
Export the spam set plus one full .eml.
Explode messages, links, attachments into tables.
Grep the invariant token before trusting subjects.
file(1) + hash every part.
Resolve A/NS/MX; keep NXDOMAIN labels.
WHOIS apexes for registrar NS + any unredacted registrant.
HTTP probe the mail /24 with default Host and the costume Host; hash bodies.
HEAD first, then one instrumented GET on the live set, stop at Location.
Shared vhost — the farm fingerprint
The cleanest infrastructure tell is not a domain. Sending Host:
mediaignorance.com to .60 through .66 returned the same body. Default vhosts differed by IP except .65, where default already was mediaignorance. Many names, one farm.
Costume PTRs on that seven-pack:
karupsdb.com, frizzaway.com, andrules-fries.com, ffxivforums.com, supercarssaturday.com, mediaignorance.com, venduvent.com.
What “still live” meant on 28 August
HEAD at ~03:22Z looked dead. GET with a browser UA was not. Liveness for this mill is GET-and-Location, not HEAD-and-status. NForce is the center of gravity; HostDime, DreamHost, Hetzner, and IPXO carried the rest of the still-resolving labels.
Limits
The pack does not identify who bought the leads or which advertiser sits behind CAKE offer 2701. Carpino on four WHOIS records is a pivot. taobmaets / keycanvascanvas are 2025 Name.com names in front of 1998–2011 snowshoe stock — two domain layers, not proof of one human. One TSV date (qd.oscom-guyane.com / 2026-12-03) is a parse artifact.
Stay inside the tables: one token, one hop pattern, one farm hash, stolen footer, fake attachments, CAKE Location from a single instrumented GET.
Bottom line
Policy Plug is a costume. The seventy-one From domains are snowshoe labels. What is real is a PHP 7.4 hop on NForce that lies to HEAD, greets a browser, and hands the session to CAKE.
Defender action is narrow: block token + path, sinkhole the two /24s if policy allows, tell LendingTree their NMLS line is being stolen, send the shared-vhost hash and the 72/72 token count to NForce and Name.com. Analyst action is to keep the pipeline so the next 72 messages do not look like 72 companies again.