Mapping Legitimate Infrastructure and Dissecting Emerging Phishing & Malvertising
Quantitative Security’s reconnaissance efforts identified a clear split between high-confidence legitimate infrastructure tied to Google’s global edge network and active malicious campaigns leveraging compromised hosting, sophisticated anti-bot cloaking, and cloned affiliate infrastructure for credential theft and lead harvesting.
Legitimate findings map directly to publicly documented infrastructure, primarily Google edge/anycast nodes. Malicious or high-risk clusters include compromised Japanese shared hosting (xs793906.xsrv.jp), Verizon-branded phishing sites exploiting the January 2026 outage, and cloned insurance lead-gen sites (pulsenodefwx.com mirroring easy-autoinsure.com). Supporting elements involve ad/tracking pixels and AI crawler evasion tactics.
These patterns align with commodity financially motivated cybercrime ecosystems—phishing-as-a-service, malvertising/affiliate fraud, and abused hosting—rather than named advanced persistent threat (APT) groups. The findings highlight the value of Quantitative Security’s custom tooling for early detection of credential-harvesting and data-theft campaigns targeting trusted brands and online ecosystems. Recommendations focus on refining detection logic and prioritizing protective intelligence for clients in finance, insurance, and high-visibility sectors.
Legitimate Infrastructure Identified
Google Edge & Core Infrastructure
Multiple scans resolved to Google properties and edge nodes (IPs in ranges such as 64.233.176.0/24, 142.251.15x.x, 74.125.21.x, 172.217.215.95). Consistent indicators included the gws server header, MarkMonitor registrar, NS1–4.GOOGLE.COM, and *.1e100.net domains. SSL hostname mismatches on direct edge node access (e.g., yo-in-f95.1e100.net) represent expected behavior for Google’s anycast architecture.
Google officially publishes crawler and infrastructure IP ranges (with documentation updates announced in March 2026). These nodes represent core, well-documented public internet infrastructure used by millions of services daily.
Cloudflare-Protected Legitimate Services
Several domains leverage Cloudflare infrastructure (published IP ranges and nameservers). Cloudflare remains a widely used legitimate CDN and security provider. Its presence alone does not indicate malice.
Suspicious & Malicious Findings with IOC Highlights
High-confidence Malicious/Campaign Infrastucture
Domain / Artifact:
Key IOCs: IP 162.43.117.134 (Japan); open ports 21/FTP, 25/SMTP, 80; SSL mismatch; xserver.jp NS
Risk Indicators: External phishing classification (IPQS); very low trust scores
Comparison: Compromised hosting abuse; classic for phishing C2/spam relay. Matches Xserver.jp official phishing advisory.
Domain / Artifact: verizon_hvnoe.icu
Key IOCs: Cloudflare IPs; anti-bot cloaking ("device type 'bot'"); new domain (~Jan 2026)
Risk Indicators: Verizon-themed content; cloaking TTP
Comparison: Brand impersonation + smishing exploiting Jan 2026 Verizon outage & $20 credit campaign.
Domain / Artifact:
(easy-autoinsure clone) + variants
Key IOCs: Full functional clone with Anura, Jornaya/Trusted Form, MediaAlpha, criteo scripts
Risk Indicators: Multiple timestamped variants; lead-theft functionality
Comparison: Malvertising / affiliate fraud cloning. Common in data-harvesting campaigns.
Domain / Artifact:
Key IOCs: Hong Kong IP; nginx + PHP sessions
Risk Indicators: Low trust scores across scam databases
Comparison: Likely offshore gambling/scam vertical.
Domain / Artifact:
Key IOCs: Cloudflare; aggressive AI-bot blocking in robots.txt; new domain (Jun 2025)
Risk Indicators: Large JS-heavy site
Comparison: Evasion tactic (increasingly common in content theft or detection-avoidance).
Supporting / Gray Infrastructure
Ad/tracking pixels (adscienceltd.com, 2yeskk6dtz7e.com) exhibit client-hint fingerprinting and appear in major ad-blocking filter lists. These fit broader adtech/malvertising supply chains.
Comparison to Known Groups and Tactics
The malicious clusters map to commodity cybercrime ecosystems rather than sophisticated nation-state actors:
Initial Access & Social Engineering: Brand impersonation (Verizon) and smishing tied to real-world events (January 2026 outage). This is a well-documented financially motivated tactic—attackers rapidly exploit news cycles for higher click rates. Verizon’s own reporting and public warnings highlight the shift toward mobile/social engineering vectors.
Defense Evasion: Anti-bot cloaking (verizon_hvnoe.icu) and aggressive robots.txt AI blocking (xxlbn.com). These are standard techniques in phishing kits and content-abuse operations.
Collection & Exfiltration: Cloned lead-gen sites with embedded lead-ID and anti-fraud bypass scripts enable credential or PII harvesting. Open ports on xs793906.xsrv.jp suggest potential C2 or data staging capability.
Infrastructure Abuse: xsrv.jp/xserver.jp
hosting is repeatedly flagged for phishing site hosting. This represents “bulletproof” or compromised shared hosting—a persistent low-sophistication vector.
No indicators pointed to specific named APT groups. The activity is consistent with phishing-as-a-service operators, malvertising affiliates, and opportunistic financially motivated actors who rapidly weaponize news events and clone popular web properties.
Attribution Insights from Headlines and Official Sources
Verizon-themed campaign: Directly contextualized by widespread 2026 reporting on scammers exploiting the January 14 outage and associated $20 credit offers via smishing. Official Verizon support channels warned customers against clicking links in unsolicited messages.
xs793906.xsrv.jp infrastructure: Aligns with Xserver.jp’s own public advisory on phishing sites mimicking their server panel and multiple external trust-score platforms classifying similar domains as malicious.
Insurance/lead-gen clones: The pattern of cloning affiliate/lead-gen sites for data theft is a recurring theme in malvertising and fraud reporting.
Overall ecosystem: Reflects the broader threat landscape where human-element attacks (phishing/social engineering) remain dominant, with attackers leveraging AI for faster operations and shifting toward mobile vectors.
These are not “advanced persistent threats” but persistent, adaptive cybercrime that scales through abused infrastructure and social engineering. The volume of easy-auto insurance variants and timestamp clustering suggests coordinated or opportunistic campaign activity.
Conclusion
Quantitative Security’s reconnaissance successfully mapped the intersecting well-known legitimate infrastructure (primarily Google edge nodes) and commodity cybercrime campaigns exploiting news events, compromised hosting, and cloned web properties. The malicious activity aligns with financially motivated tactics rather than sophisticated group operations.
These insights reinforce the necessity of custom, behaviorally aware tooling for protective intelligence—especially where trusted brands and online ecosystems intersect with opportunistic threat actors. Quantitative Security continues to refine its platform to deliver actionable intelligence and support federal positioning in protective intelligence, incident response, and deception technologies.