One IP, One Landing Page: Anatomy of an SES Parcel-Phishing Ring
One IP, One Landing Page: Anatomy of an SES Parcel-Phishing Ring
Since mid-January 2026, one operator has run hundreds of thousands of parcel-phishing emails through Amazon SES from over a thousand burner domains. The lure never changes: a curt notice that "your parcel's status has updated," addressed to you by name, with a single button that routes through an Amazon-owned tracking link and lands on one destination the operator has reused for the entire run. What makes the operation worth dissecting is not the pretext, which is old, but the plumbing behind it. Behind the churn of throwaway sender domains sit a handful of durable correlators: one landing page, four dedicated SES accounts, and a single cloud IP that authorizes almost the entire fleet.
Key Takeaways
- A single operator has sustained a brandless parcel/shipping-pretext email operation for roughly six months and counting, fronted by more than 720 algorithmically-coined burner sender domains that rotate one-and-done.
- Every burner domain is a real registration authenticated through Amazon SES, so the mail passes SPF and DKIM and reads as a legitimately signed sender. The churn defeats per-sender blocklists; the authentication defeats alignment-based filtering.
- The visible sender domains are disposable, but the backbone is not. Four operator-dedicated SES accounts (
vpktzgwp,d1gpgtp5,821rttmg,qtbeczhj) surface as non-rotatableawstrack[.]metracking hosts, and all clicks funnel to a single landing page,tracking-hub[.]com. - Public WHOIS corrects a common assumption about this fleet: it is not registered through a Western budget registrar. Roughly 158 of 169 resolved burner domains sit at Alibaba Cloud / HiChina, split across an aged 2022 to 2024 stash and purpose-built 2025 to 2026 batches.
- The strongest clustering signal is a shared SPF record: 166 of 169 resolved domains authorize sending from one Alibaba Cloud address. One line of DNS ties a fleet that was designed to look unrelated.
Background
Generic parcel lures work because they need no brand. A message that impersonates a specific carrier has to reproduce a logo, a sender identity, and a tone that a brand-impersonation detector or a trademark-takedown team can key on. A message that just says "your parcel" borrows none of that and still lands, because at any given moment a large share of recipients is plausibly waiting on a delivery. Postal inspectors and the FCC have warned about the smishing version of this lure for years; the email version shares the same economics, thinned out across a wide field of disposable domains.
The delivery rail here is Amazon Simple Email Service. SES verifies each sender domain on its own: the operator publishes SES-issued DKIM CNAMEs and an SPF include for every domain it onboards, and from then on that domain sends fully authenticated mail. For a defender this removes two of the usual levers at once. The sending IPs belong to shared AWS ranges, so blocking them is not an option, and the mail passes SPF, DKIM, and DMARC alignment, so authentication posture says nothing useful. A dedicated SES account, rather than a shared sending pool, buys the operator its own reputation lane and its own tracking subdomain, so a single burned domain does not drag down the rest.
When SES click and open tracking is enabled, SES rewrites every link in the body to route through https[:]//<account_id>.r.<region>.awstrack[.]me/.... That indirection is the point. The click inherits the reputation of an Amazon-owned host, the true destination stays hidden from the recipient and from many URL scanners until after the redirect, and the <account_id> label is derived from the SES account itself. It cannot be changed without standing up a whole new account, which is exactly why it becomes the most reliable way to cluster the campaign even as the From: domains rotate underneath it.
The spread across many low-volume domains is a textbook snowshoe pattern, named for how a snowshoe distributes weight so no single point sinks. Legitimate bulk senders concentrate volume on a few long-lived, reputation-built domains; a snowshoe operator does the opposite, keeping per-domain volume under the thresholds that reputation and volume filters watch. What is less common is fusing that churn with an authenticated cloud rail and a trusted redirector, which is what this operator does.
Discovery and Infrastructure
The campaign surfaces first as noise: dozens of never-before-seen sender domains a week, each sending a small number of near-identical messages, all carrying the exact subject [Important] Your parcel's status has updated. Pivoting on that subject and on the decoded body opener pulls the fleet together. The awstrack[.]me tracking hosts then split it cleanly by SES account, and the single landing page confirms the whole thing belongs to one operator.
| Indicator | Role | Notes |
|---|---|---|
tracking-hub[.]com |
Landing / CTA | Sole destination for the entire fleet; reused across 1,000+ sender domains; registered 2021 at NameSilo; ScamAdviser score 86 |
vpktzgwp.r.us-east-2.awstrack[.]me |
SES tracking host | Primary account, bulk of volume; DMARC-fail leg |
d1gpgtp5.r.us-west-2.awstrack[.]me |
SES tracking host | Second-highest volume; DMARC-pass leg |
821rttmg.r.us-east-1.awstrack[.]me |
SES tracking host | Later account; also carries the fake-storefront templates |
qtbeczhj.r.us-west-1.awstrack[.]me |
SES tracking host | Later account |
mc.sendgrid[.]com/assets/social/white/*.png |
Abused CDN asset | Footer social icons hotlinked for visual polish; no SendGrid account involved |
Two of those rows deserve a note. The mc.sendgrid[.]com reference is not SendGrid involvement of any kind. The operator hotlinks a set of footer social-media icons that SendGrid serves publicly, purely so the message footer looks like it came off a real marketing platform. And tracking-hub[.]com is the operator's own property, not an abused shared service. It has been held since 2021, carries a poor third-party trust score, and every scanned message in the fleet funnels to it.
How It Works
A recipient gets a short message from a sender they have never heard of, on a domain that reads like a mangled English word. The subject and body claim a package has an update. The greeting uses the recipient's real first and last name, run together, which comes from a mail-merge list. The body supplies a fake order number in a fixed NNNNN plus M plus NNNNNN format, a fabricated 20-digit tracking number, a plausible product name pulled from a catalog, and a randomized shipping sub-status. A single button, "Track your Parcel," routes through the SES tracking host and on to tracking-hub[.]com, with the fake tracking number echoed in the query string.
Nothing in the message is personalized beyond the name and the rotating filler fields, which is what gives the fleet away once you have two samples side by side. The template is locked. Only the mail-merge fields move.
Sample Lures
Two representative messages, victim names removed and destinations defanged. The first comes off the primary account (the DMARC-fail leg); the second off the .vip outlier domain on the secondary account (the DMARC-pass leg). They differ only in the mail-merged fields.
From: support@enhanceas[.]com
Subject: [Important] Your parcel's status has updated
Return-Path: <...@us-east-2.amazonses[.]com> (SPF pass, DKIM pass, DMARC fail)
Your parcel's status has updated
Dear [recipient name]:
Your order number is 46800M119063 and the product name is
Portable Binder Clip Stapler - Includes 50 reusable clips.
The tracking number is: 6352237681976457097.
We checked that your package logistics status has been updated.
Now the package logistics status is: transit.
Detail status of the logistics: The shipment arrived at the
customs of United States.
[ Track your Parcel ] -> hxxps://vpktzgwp.r.us-east-2.awstrack[.]me/.../tracking-hub[.]com/?nums=...
If you have any questions, please contact us at support@enhanceas[.]com
any time. We will assist you in tracking your parcel.
From: shipping@24hservice[.]vip
Subject: [Important] Your parcel's status has updated
Return-Path: <...@us-west-2.amazonses[.]com> (SPF pass, DKIM pass, DMARC pass)
Your parcel's status has updated
Dear [recipient name]:
Your order number is 55156M113420 and the product name is
Line Smoother Fine Line Blurring Primer.
The tracking number is: 10839630091289090968.
We checked that your package logistics status has been updated.
Now the package logistics status is: transit.
Detail status of the logistics: The shipment has left the
sorting center.
[ Track your Parcel ] -> hxxps://d1gpgtp5.r.us-west-2.awstrack[.]me/.../tracking-hub[.]com/?nums=...
Technical Analysis
The visible layer of this operation is designed to look disposable and disconnected. The durable layer, once you pull public WHOIS and DNS, is anything but.
Domain-Generation Grammar
The sender domains are not random strings. They follow three grammars, and all three produce output grammatical enough to slip past naive high-entropy or random-string heuristics.
| Shape | Template | Examples |
|---|---|---|
| Word plus trailing letter | <word><a-z>.com |
journalw[.]com, petitionm[.]com, orientaln[.]com, quantifyn[.]com |
| Two-word compound | <word><word>.com |
allowgive[.]com, beforehatched[.]com, outunusual[.]com, bridgebalk[.]com |
| Typo sibling | misspelled base | consecutivte[.]com, sculptiure[.]com, appearancte[.]com, effiective[.]com |
The fleet is almost entirely .com, with a thin scatter of .net (auralotic[.]net, matchequal[.]net, specificcum[.]net) and a single .vip (24hservice[.]vip, later joined by its plural sibling 24hservices[.]vip). Typo siblings cluster around shared bases, so the same root reappears mutated: humorouis/humorousy, probablei/probabledy/probabilityi, cherishty/cherishous. Local parts are support@ on roughly 99 percent of the fleet; the only consistent exception is shipping@ on the .vip domains.
A later cohort drifts toward a patriotic and US-250th-anniversary lexicon: usafaithfreedom[.]com, weareallfrog[.]com, nokingsjustpeople[.]com, votethemoutmovement[.]com, america250style[.]com, freedom250wear[.]com. Earlier internal reads treated this "political" batch as a separate purchasing persona. Public registration data does not support that reading. It is simply the operator's 2025 to 2026 registration cohort wearing themed names, likely an attempt to dodge fingerprinting that keys on algorithmic-nonsense strings.
Registration Cohorts and the Aged Stash
Pulling WHOIS across the confirmed sender fleet produces the single most useful correction to the folklore about this operator. The fleet is not registered at a Western budget registrar. It is overwhelmingly Chinese-registrar infrastructure, dominated by the Alibaba group.
| Registrar | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 | Total |
|---|---|---|---|---|---|---|---|
| Alibaba Cloud / HiChina + aliyun (wanwang) | 0 | 21 | 52 | 23 | 57 | 5 | 158 |
| Xin Net Technology | 0 | 0 | 0 | 0 | 8 | 0 | 8 |
| NameSilo (landing page only) | 1 | 0 | 0 | 0 | 0 | 0 | 1 |
| Communigal (Galcomm) | 0 | 0 | 0 | 0 | 1 | 0 | 1 |
| Other / year unresolved | 0 | 0 | 0 | 0 | 0 | 0 | 1 |
The NameSilo row is the one that reframes the operator. NameSilo appears exactly once in the resolved set, and it is the landing page tracking-hub[.]com (registered 2021), not a sender domain. The sending fleet is Alibaba Cloud / HiChina (www.net.cn) and aliyun (wanwang.aliyun.com), with Xin Net a distant second. The cohort shape matters as much as the registrar: nearly 100 domains were registered across 2022 to 2024 and held dormant, an aged stash that buys the operator domains old enough to sidestep "young domain" reputation penalties, alongside fresh 2025 to 2026 batches burned as the campaign runs. Both cost-friendly, API-driven registrars appear repeatedly in DNS-abuse reporting for cheap bulk registration, which is the economics that makes a 700-plus-domain disposable fleet viable.
One IP Authorizes the Fleet
The domains are meant to look unrelated. One line of DNS says otherwise. Of 169 resolved domains in the verified set, 166 publish the identical SPF record authorizing a single Alibaba Cloud address:
v=spf1 ip4:47.254.92[.]90 ~all
That address is shared Alibaba Cloud hosting, not a dedicated operator asset, so it is a clustering fingerprint rather than something a defender should block outright. As a pivot it is powerful: it binds 98 percent of a fleet that was otherwise built to resist correlation. DMARC posture is just as uniform. Where a policy is published at all, it is p=none, so there is no enforcement anywhere in the fleet. A defender who has one confirmed domain from this operator can reach most of the rest through that shared SPF record without ever touching the sender-domain rotation.
The SES-Account Correlator
Above the DNS layer, the four SES accounts provide the second durable pivot. Because the <account_id>.r.<region>.awstrack[.]me label is fixed to the SES account, it survives every sender-domain rotation. The operator grew from two accounts in two regions to four accounts in four US regions over the campaign, which reads as resilience and quota-scaling rather than any geographic targeting. Most volume rides the two original accounts, which split roughly 85 to 15 between them; the two later accounts run lighter and carry the secondary storefront templates.
| SES account (tracking host) | Region | Role |
|---|---|---|
vpktzgwp.r.us-east-2.awstrack[.]me |
us-east-2 | Primary sender, bulk of volume; DMARC-fail leg |
d1gpgtp5.r.us-west-2.awstrack[.]me |
us-west-2 | Second-highest volume; DMARC-pass leg |
821rttmg.r.us-east-1.awstrack[.]me |
us-east-1 | Later account; fake-storefront and "FINAL CALL" templates |
qtbeczhj.r.us-west-1.awstrack[.]me |
us-west-1 | Later account |
Template Lock and the Storefront Pivot
The content is as rigid as the infrastructure is fluid. Across a sender inventory now past 1,000 distinct domains, the display name is blank on every message: one homogeneous sender profile behind the whole fleet. The subject is byte-for-byte constant, the body opener is constant, the order-number format holds to NNNNN plus M plus NNNNNN, and the tracking number is a uniform 20 digits echoed into the landing URL's nums parameter. The footer pulls the same five SendGrid-hosted social icons every time.
The same sender apexes have also been observed running a second template family: fake storefronts with the subjects Order Confirm and You left an order in your cart, plus a FINAL CALL promotional variant, where the sender domain is reused verbatim as an all-caps store brand and the CTA points at www.<sender-apex>/collections/all. That is a monetization pivot layered onto the same infrastructure, not a separate operation.
Detection Observations
The parcel fleet is hard to catch on sender features alone. Each domain is a real, SES-authenticated registration sending low volume, so authentication posture, domain age (for the aged-stash cohort), and per-sender reputation all read clean or neutral in isolation. The signal is not in any single message; it is in the shape of the fleet.
- The exact subject string combined with the body opener and the
NNNNN-M-NNNNNNorder-number format with a 20-digit tracking number is a tight content fingerprint that survives every infrastructure rotation. - The blank display name across the entire fleet, paired with the parcel template, separates this traffic from legitimate carrier and retailer mail, which carries branded display names.
- The shared SPF record authorizing one Alibaba Cloud address is the single strongest cross-domain pivot; one confirmed domain reaches most of the fleet.
- The
<account_id>.r.<region>.awstrack[.]metracking host is a durable per-account correlator that outlives sender-domain churn and clusters messages by SES account. - The single reused landing page collapses the entire ring to one destination, which is the cheapest cross-fleet pivot of all.
MITRE Fight Fraud Framework Mapping
Mapped to the MITRE Center for Threat-Informed Defense Fraud matrix (https://ctid.mitre.org/fraud). Technique labels follow the matrix vocabulary.
| Tactic | Observed behavior | Notes |
|---|---|---|
| Resource Development | Acquire bulk sender domains | 700-plus burner domains across an aged stash and fresh batches at Chinese registrars |
| Resource Development | Acquire cloud sending accounts | Four dedicated Amazon SES accounts across four US regions |
| Initial Access | Mass phishing message | Authenticated SES email at snowshoe volume |
| Execution | Impersonate a delivery notice, manufacture urgency | Brandless parcel-status pretext with mail-merged victim name |
| Monetization | Data and credential collection at landing | Single reused landing page reached through a trusted redirector |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The lists below are a representative subset of the verified-malicious set held for this operator; large aggregate totals are stated as floors, since observed inventory understates what the operator holds.
Senders
| Value | Role | Notes |
|---|---|---|
shipping@24hservice[.]vip |
Sender | Longest-running burner; .vip outlier |
support@indicatek[.]com |
Sender | High-volume, both regions |
support@consecutivte[.]com |
Sender | Typo-sibling shape |
support@journalw[.]com |
Sender | Word plus trailing letter |
support@outunusual[.]com |
Sender | Two-word compound |
support@zenromall[.]com |
Sender | Both regions |
support@sculptiure[.]com |
Sender | Typo-sibling shape |
support@preliminaryt[.]com |
Sender | Both regions |
support@appearancte[.]com |
Sender | Typo-sibling shape |
support@auralotic[.]net |
Sender | .net outlier |
support@usafaithfreedom[.]com |
Sender | Patriotic-lexicon cohort |
support@votethemoutmovement[.]com |
Sender | Patriotic-lexicon cohort |
| … (representative subset; 100+ verified-malicious senders) |
Domains
| Value | Role | Notes |
|---|---|---|
tracking-hub[.]com |
Landing / CTA | Sole destination for the entire fleet; NameSilo 2021 |
consecutivte[.]com |
Sender domain | Typo sibling |
journalw[.]com |
Sender domain | Word plus trailing letter |
outunusual[.]com |
Sender domain | Two-word compound |
allowgive[.]com |
Sender domain | Two-word compound |
beforehatched[.]com |
Sender domain | Two-word compound |
auralotic[.]net |
Sender domain | .net outlier |
matchequal[.]net |
Sender domain | .net outlier |
24hservice[.]vip |
Sender domain | .vip outlier |
usafaithfreedom[.]com |
Sender domain | Patriotic-lexicon cohort |
votethemoutmovement[.]com |
Sender domain | Patriotic-lexicon cohort |
america250style[.]com |
Sender domain | US-250th lexicon |
| … (representative subset; 250+ verified-malicious domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
vpktzgwp.r.us-east-2.awstrack[.]me |
SES tracking host | Primary account correlator |
d1gpgtp5.r.us-west-2.awstrack[.]me |
SES tracking host | Secondary account correlator |
821rttmg.r.us-east-1.awstrack[.]me |
SES tracking host | Later account; storefront templates |
qtbeczhj.r.us-west-1.awstrack[.]me |
SES tracking host | Later account |
tracking-hub[.]com |
Landing host | Sole landing page reached by the entire fleet |
Conclusion
The disposable layer of this operation is exactly that, and chasing individual burner domains is a losing game against an operator who burns a fresh batch every few days. The parts that do not move are where defenders have leverage: one landing page, four fixed SES-account tracking hosts, and a single SPF record that quietly authorizes almost the entire fleet. An operator that has held its landing domain since 2021 and stockpiled sender domains years ahead of use is provisioned for a long run, so the useful question is not when the current domains burn out but whether the landing page and the shared authentication record ever change. As long as they do not, one confirmed domain still unlocks the rest.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.