Policy Plug snowshoe mill-follow up
Classification: TLP:CLEAR. Defensive evidence from a Gmail SLIE pull plus DNS/WHOIS/HTTP follow-up.
Window: 2026-08-27 mail pull through 2026-08-28 GET/CAKE probes.
Hard constraints that stay in force: do not visit r*.php?32= links, unsubscribe links, or Policy Plug widgets. Do not treat LendingTree / NMLS #1136 as the sender. Do not treat HEAD 403 as “kit down.” Sensor IPs 192.168.1.73 and 172.20.10.3 are inventory, not IOCs. taobmaets.com is “steamboat” reversed — affiliate lander, not the mailer.
One-line assessment
Unsolicited auto-insurance and credit-card lead spam. One mill, not 72 companies. Shared tracker e6jbv4z in 72/72 messages and 156/156 HTTP links. SMTP and click sit on NForce AS43350 (185.47.200.0/24, 185.47.203.0/24), nginx + PHP 7.4.33, aged Name.com snowshoe labels, stolen LendingTree NMLS #1136 / 1415 Vantage Park Drive, Suite 700, Charlotte, NC 28203. Browser-like GET is method-filtered 302 → CAKE a=44&c=2701 on taobmaets.com (or unsubscribe on keycanvascanvas.com).
Display brands (Policy Plug 51/72, Easy Insurance Match, Endurance, Indigo/Destiny Mastercard) are costumes. SLIE only clustered 3 subject-duplicate pairs; the other ~66 campaign keys are the same kit because they share the token.
Click URL shape, every time:
http://{label}.{aged-apex}/r[0-9a-f]{4,5}.php?32={token containing e6jbv4z}
A few messages use the apex itself as the click host (fittax.com, seerobrun.com, couserans.org, owner-builder-consulting.com).
One TSV date outlier: qd.oscom-guyane.com is listed as 2026-12-03. Treat as a clock/parse artifact unless independently confirmed.
Why this is one mill
High-confidence cluster signals:
Token e6jbv4z in every HTML body and every link.
Path always /r + 4–5 hex + .php.
Sender domain almost always matches that message’s click host ({2-letter}.{apex}).
Same
NS set: ns1mtw ns2bkr ns3flt ns4bht.
Same NForce /24s for the core mail/click farm.
Same stolen LendingTree footer on a large subset.
Same fake “Office” attachment names that are actually plaintext.
Subjects are obfuscated with spacing, circled letters, homoglyphs, CJK/Hangul/Cyrillic/Thai padding, and the recipient handle UNCCNO.
SLIE official clusters (only 3 pairs):
“grap the lowest rates before they disappear” — 2 msgs, qm.sandhyashahmd.com
“grab the lowest rates before they disappear” — 2 msgs, mx.bardakalti.net / fc.cyrofilho.com
“pick from multiplecards designs at no extra charges” — 2 msgs, tn.purebasmatirice.com / hm.orpingtonsuk.com
Treat the other 66 keys as the same kit.
Mail authentication and costume
Sample message 1a044f84712ddc86, Gmail delivered 2026-08-27 13:45:17 PDT.
Treat the SES block as forged/stale costume unless independently verified. The hop Gmail actually accepted is NForce .65. TLS on that hop was old: TLS1 / ECDHE-ECDSA-AES128-SHA.
HTML of that sample also hid Vietnam Airlines / Agoda noscript filler (check-in deadline / itinerary language) — one of 72 messages.
Typical From-line tricks across the dump: Hangul “이 … 이창성”, Thai mai taikhu stacking, Cyrillic “СМИ/СИМ/Ответ/финансы”, Devanagari “बिक्री”, Chinese “内测版”, fake github_noreply@, docker_noreply@, vercel_noreply@, numeric local-parts.
Token anatomy
Query parameter is always 32=. Shared pieces:
Constant campaign fragment: e6jbv4z
Common unsub-looking stem: 1o136a577c6a08aef (no _3bg4 / _20y4 style tag) — recon mapped this class to keycanvascanvas.com
Click tags observed: _3bg4 (34), _20y4 (22), _20z4 (12), _24x4 (4); 84 URLs have no such tag
Mid-token looks like T019krff…… plus a short campaign/offer id (e72626, e74300, e72627, e72769)
Tail often base64-ish. Documented example: MHBnNTAyc2l2aTIx → 0pg502sivi21, then split into CAKE s3 / s5
GET Location (same udid across hosts from one client), as recorded:
Quote/click:
https://taobmaets.com/?a=44&c=2701&s1=
…&s3=…&udid=p4fepuxldrmugtzc7kenf4ysnsxlxkpdtynt&s4=…&s5=…
Unsubscribe:
https://www.keycanvascanvas.com/o-rzjq-p75-043322777a36bd893011e6fec0299b9d
Do not fetch those URLs from this session.
Scripts (r*.php)
47 distinct scripts. Top:
Probe matrix
Network
NForce AS43350 (core)
RIPE: 185.47.200.0/24 NFORCE_ENTERTAINMENT, abuse abuse@nforce.com. Sibling click net 185.47.203.0/24.
Shared vhost: Host: mediaignorance.com on all seven IPs returns identical 200 / 52667 bytes, sha256 3be462b23bf540f098695092d977eec91883a1dcee031ef7979237dad1fa3f04. Default-vhost bodies differ per IP except .65 default == named mediaignorance.
Resolved NForce click/mail hosts in this dump:
Other live nets in this dump
HTTP:80 headers on the NForce farm: Server: nginx, X-Powered-By: PHP/7.4.33, X-Frame-Options: SAMEORIGIN, X-XSS-Protection: 1; mode=block, X-Content-Type-Options: nosniff.
DNS live vs burned
Live A records (20 hosts from dns/hosts.tsv):
bg.casafaiola.com, bk.risaonline.com, bv.dmwhiteplumbing.com, dx.venduvent.com, fk.frizzaway.com, fy.guicorreia.com, jf.sinhalabuddhist.org, kr.premezcladostesia.com, lu.karupsdb.com, mx.bardakalti.net, qm.sandhyashahmd.com, rf.gormeting.net, ru.rausieusach.com, rv.wophp.com, ry.dawncreations.net, sx.lubovniki.com, tn.useroffers.com, wp.ngma-grants.org, ze.mediaignorance.com, zu.airpartner.net
Apexes that still have NS but no click-host A in this snapshot include
couserans.org, fittax.com, owner-builder-consulting.com, seerobrun.com.
The rest of the 71-ish FQDNs were NXDOMAIN / empty A — burned snowshoe labels, still historical IOCs.
Extra apexes in rest lists (recon siblings, not necessarily in the 72-mail set): onlyconveyancing.com, torahtorahtorah.com.
WHOIS / registrant
Registrar:
Name.com / New Frontier (IANA 625 / 1040). NS almost universal: ns1mtw.name.com, ns2bkr.name.com, ns3flt.name.com, ns4bht.name.com.
Unredacted registrant on several apexes:
Name: Robert Carpino
Address: 11024 Balboa Blvd unit A20, Granada Hills, CA 91344, US
Phone: +212.661625169
Email: edcopm13g@gmail.com
Seen unredacted on:
hassrods.com, 2kland.us, cigarweb.us, indiancremation.us. Same person also tied (redacted or prior) to mediaignorance.com, sandhyashahmd.com, casafaiola.com, risaonline.com.
Domain ages: bulk 1998–2011. Many created 2–11 May/June (anniversary drop of aged names). Examples: alboom.net 1998-06-06, ngma-grants.org 1999-06-10, unsoldbannerads.com 2000-06-04, risaonline.com 2001-06-02.hassrods.com example: created 2009-05-29, updated 2026-07-09, expiry 2027-05-29, registrar New Frontier / Name106, IANA 1040, abuse abuse@name.com +1.7203101849.
Content IOCs
Other footer decoys (1 each): 8282 South Memorial Drive, Tulsa OK; 1000 West Maude Avenue, Sunnyvale CA (LinkedIn-shaped poison).
Subject themes: auto-rate urgency, “lock before it jumps,” Endurance $300-off costume, Indigo/Destiny Mastercard “$700/$1000 credit limit,” cashback-on-gas, “no deposit,” “less than perfect credit,” personalized UNCCNO bait.
Attachments
202 parts, 0 real Office files. file(1) saw ASCII/UTF-8 text only. ClamAV: 0 infected. Payload is the HTML click wrap.
Fake names: Recommandation_Letter.docx, job_requirement.docx / .pptx, JOBS-Plug-JOBS.pptx, unknown. MIME claims image/png, image/jpeg, or OOXML — content is boundary garbage or repeated sender-domain text (“Check-i…”, “Dear…”).
Working copies: 183 files under quarantine_attachments/ because two {msg_id}_unknown parts per message collide on filename (different sha256, same path). Index is source of truth (202 rows).
Top file(1) buckets: ASCII+CRLF 126, UTF-8+CRLF 30, ASCII no terminators 30, then various “very long line” UTF-8 leftovers.
Sender / link-host inventory
Highest link volume:
ry.dawncreations.net, fk.frizzaway.com, dx.venduvent.com, mx.bardakalti.net, bg.casafaiola.com, wp.ngma-grants.org, lb.alboom.net (6 links each); qm.sandhyashahmd.com (4 links, 2 messages).
Sender list (71 domains, almost all 1 message):
qm.sandhyashahmd.com (2), then one each: ze.mediaignorance.com, bv.dmwhiteplumbing.com, ry.dawncreations.net, jf.sinhalabuddhist.org, fk.frizzaway.com, dx.venduvent.com, lu.karupsdb.com, mx.bardakalti.net, zu.airpartner.net, rv.wophp.com, fy.guicorreia.com, bg.casafaiola.com, rf.gormeting.net, sx.lubovniki.com, tn.useroffers.com, bk.risaonline.com, wp.ngma-grants.org, ru.rausieusach.com, xt.unsoldbannerads.com, dp.opensourcedeveloper.net, lb.alboom.net, kr.premezcladostesia.com, rf.chinalift.net, qx.jualkaospolos.com, hp.kyotoo.net, ng.icypeople.com, yt.loosebear.com, qv.bluelinemedicalservices.com, mu.surroundscore.net, fc.cyrofilho.com, zr.uvaentertainment.com, by.cooner.net, tk.ready2gocountry.com, md.hourlyincome.com, hx.oneearthnetwork.com, ed.imaginejustice.org, zr.windfallunited.com, df.indiancremation.us, jx.foodiehistory.com, qm.tacticutilization.com, bv.hassrods.com, d.ceotuan.com, ek.bestsms.in, hc.nakedgrape.net, nb.californiacustomcoach.com, qm.deboyland.com, qw.seerobrun.com, py.statetravelers.com, gl.cigarweb.us, cu.productiveprod.com, kn.doughavlin.com, vx.savelagoonvalley.net, cg.benforprez.com, ry.on-linepowerservice.com, ef.schoolgold.net, wp.salmanaward.com, qx.sg158.com, bk.enimra.com, zn.2kland.us, tn.purebasmatirice.com, pw.fittax.com, qy.inrss.com, couserans.org, ja.wiily.com, qm.commercialdriverscouncil.com, hm.orpingtonsuk.com, pv.ryanschaffer.com, vx.ctrltextile.com, owner-builder-consulting.com, qd.oscom-guyane.com.
Recipient in metadata: unccno@gmail.com throughout.
Defensive use / do-not
If you already filter this mill, local blocks that match the evidence:
Token e6jbv4z
Path /r[0-9a-f]{4,5}\.php
CIDRs 185.47.200.0/24, 185.47.203.0/24
NS set above, for these apexes only
Report:
NForce: abuse@nforce.com
Name.com: abuse@name.com
New Frontier: abuse@newfrontier.domains
Gmail: already labeled SPAM
Do not:
Open the php links, unsubscribe links, or Policy Plug widgets
Attribute the mail to LendingTree
Treat HEAD 403 as kit-down
Treat this file as a kill list