Mapping Legitimate Infrastructure and Dissecting Emerging Phishing & Malvertising

Quantitative Security’s reconnaissance efforts identified a clear split between high-confidence legitimate infrastructure tied to Google’s global edge network and active malicious campaigns leveraging compromised hosting, sophisticated anti-bot cloaking, and cloned affiliate infrastructure for credential theft and lead harvesting.

Legitimate findings map directly to publicly documented infrastructure, primarily Google edge/anycast nodes. Malicious or high-risk clusters include compromised Japanese shared hosting (xs793906.xsrv.jp), Verizon-branded phishing sites exploiting the January 2026 outage, and cloned insurance lead-gen sites (pulsenodefwx.com mirroring easy-autoinsure.com). Supporting elements involve ad/tracking pixels and AI crawler evasion tactics.

These patterns align with commodity financially motivated cybercrime ecosystems—phishing-as-a-service, malvertising/affiliate fraud, and abused hosting—rather than named advanced persistent threat (APT) groups. The findings highlight the value of Quantitative Security’s custom tooling for early detection of credential-harvesting and data-theft campaigns targeting trusted brands and online ecosystems. Recommendations focus on refining detection logic and prioritizing protective intelligence for clients in finance, insurance, and high-visibility sectors.

Legitimate Infrastructure Identified

Google Edge & Core Infrastructure

Multiple scans resolved to Google properties and edge nodes (IPs in ranges such as 64.233.176.0/24, 142.251.15x.x, 74.125.21.x, 172.217.215.95). Consistent indicators included the gws server header, MarkMonitor registrar, NS1–4.GOOGLE.COM, and *.1e100.net domains. SSL hostname mismatches on direct edge node access (e.g., yo-in-f95.1e100.net) represent expected behavior for Google’s anycast architecture.

Google officially publishes crawler and infrastructure IP ranges (with documentation updates announced in March 2026). These nodes represent core, well-documented public internet infrastructure used by millions of services daily.

Cloudflare-Protected Legitimate Services

Several domains leverage Cloudflare infrastructure (published IP ranges and nameservers). Cloudflare remains a widely used legitimate CDN and security provider. Its presence alone does not indicate malice.

Suspicious & Malicious Findings with IOC Highlights

High-confidence Malicious/Campaign Infrastucture

Domain / Artifact:

xs793906.xsrv.jp

Key IOCs: IP 162.43.117.134 (Japan); open ports 21/FTP, 25/SMTP, 80; SSL mismatch; xserver.jp NS

Risk Indicators: External phishing classification (IPQS); very low trust scores

Comparison: Compromised hosting abuse; classic for phishing C2/spam relay. Matches Xserver.jp official phishing advisory.

Domain / Artifact: verizon_hvnoe.icu

Key IOCs: Cloudflare IPs; anti-bot cloaking ("device type 'bot'"); new domain (~Jan 2026)

Risk Indicators: Verizon-themed content; cloaking TTP

Comparison: Brand impersonation + smishing exploiting Jan 2026 Verizon outage & $20 credit campaign.

Domain / Artifact:

pulsenodefwx.com

(easy-autoinsure clone) + variants

Key IOCs: Full functional clone with Anura, Jornaya/Trusted Form, MediaAlpha, criteo scripts

Risk Indicators: Multiple timestamped variants; lead-theft functionality

Comparison: Malvertising / affiliate fraud cloning. Common in data-harvesting campaigns.

Domain / Artifact:

bh538.com

Key IOCs: Hong Kong IP; nginx + PHP sessions

Risk Indicators: Low trust scores across scam databases

Comparison: Likely offshore gambling/scam vertical.

Domain / Artifact:

xxlbn.com

Key IOCs: Cloudflare; aggressive AI-bot blocking in robots.txt; new domain (Jun 2025)

Risk Indicators: Large JS-heavy site

Comparison: Evasion tactic (increasingly common in content theft or detection-avoidance).

Supporting / Gray Infrastructure

Ad/tracking pixels (adscienceltd.com, 2yeskk6dtz7e.com) exhibit client-hint fingerprinting and appear in major ad-blocking filter lists. These fit broader adtech/malvertising supply chains.

Comparison to Known Groups and Tactics

The malicious clusters map to commodity cybercrime ecosystems rather than sophisticated nation-state actors:

  • Initial Access & Social Engineering: Brand impersonation (Verizon) and smishing tied to real-world events (January 2026 outage). This is a well-documented financially motivated tactic—attackers rapidly exploit news cycles for higher click rates. Verizon’s own reporting and public warnings highlight the shift toward mobile/social engineering vectors.

  • Defense Evasion: Anti-bot cloaking (verizon_hvnoe.icu) and aggressive robots.txt AI blocking (xxlbn.com). These are standard techniques in phishing kits and content-abuse operations.

  • Collection & Exfiltration: Cloned lead-gen sites with embedded lead-ID and anti-fraud bypass scripts enable credential or PII harvesting. Open ports on xs793906.xsrv.jp suggest potential C2 or data staging capability.

  • Infrastructure Abuse: xsrv.jp/xserver.jp

    hosting is repeatedly flagged for phishing site hosting. This represents “bulletproof” or compromised shared hosting—a persistent low-sophistication vector.

No indicators pointed to specific named APT groups. The activity is consistent with phishing-as-a-service operators, malvertising affiliates, and opportunistic financially motivated actors who rapidly weaponize news events and clone popular web properties.

Attribution Insights from Headlines and Official Sources

  • Verizon-themed campaign: Directly contextualized by widespread 2026 reporting on scammers exploiting the January 14 outage and associated $20 credit offers via smishing. Official Verizon support channels warned customers against clicking links in unsolicited messages.

  • xs793906.xsrv.jp infrastructure: Aligns with Xserver.jp’s own public advisory on phishing sites mimicking their server panel and multiple external trust-score platforms classifying similar domains as malicious.

  • Insurance/lead-gen clones: The pattern of cloning affiliate/lead-gen sites for data theft is a recurring theme in malvertising and fraud reporting.

  • Overall ecosystem: Reflects the broader threat landscape where human-element attacks (phishing/social engineering) remain dominant, with attackers leveraging AI for faster operations and shifting toward mobile vectors.

These are not “advanced persistent threats” but persistent, adaptive cybercrime that scales through abused infrastructure and social engineering. The volume of easy-auto insurance variants and timestamp clustering suggests coordinated or opportunistic campaign activity.

Conclusion

Quantitative Security’s reconnaissance successfully mapped the intersecting well-known legitimate infrastructure (primarily Google edge nodes) and commodity cybercrime campaigns exploiting news events, compromised hosting, and cloned web properties. The malicious activity aligns with financially motivated tactics rather than sophisticated group operations.

These insights reinforce the necessity of custom, behaviorally aware tooling for protective intelligence—especially where trusted brands and online ecosystems intersect with opportunistic threat actors. Quantitative Security continues to refine its platform to deliver actionable intelligence and support federal positioning in protective intelligence, incident response, and deception technologies.

Previous
Previous

Spam Campaign Analysis: Infrastructure Overlapping Security Scanning Platforms

Next
Next

Mapping the Attack Ladder: High- and Medium-Risk Infrastructure in Observed Traffic