Auto-Warranty Lead-Gen Fraud on Borrowed Infrastructure
Auto-Warranty Lead-Gen Fraud on Borrowed Infrastructure
Since January 2026, a lead-generation operator has impersonated CarShield, Endurance, and other US auto-warranty brands across thousands of compromised domains. The operation registers no infrastructure of its own. Instead, it uses aged small-business domains taken over for sending and redirect hosting, trusted cloud-storage buckets for lure images, and cheap virtual private servers for raw-IP click backends. The traffic is connected not by a blockable domain, but by a set of fingerprints: a shared PHP redirect kit, a self-issued authentication pattern, and a templated sender grammar that persists as the underlying hosts rotate. This is affiliate lead-gen rather than credential theft, and the entire build is designed to maintain a clean surface that a defender cannot flag.
Key Takeaways
- The operator sends from compromised aged small-business domains instead of registering burners, leaving newly-registered-domain heuristics and authentication checks with no signal.
- A shared
/r*.php?32=PHP redirect kit supports at least six lead-gen verticals simultaneously on the same compromised hosts and uses one affiliate-ID generator. - Click-through follows three parallel rails: the compromised-host kit, cloud-storage image lures on Azure Blob, S3, and Google Cloud Storage, and raw-IP backends reached through IPv4-mapped IPv6 literals.
- The sender local-part, not the domain, is the durable operator artifact: a decoration grammar built around a small set of stable vertical tokens.
- Content-level evasion combines homoglyph and punctuation-fragmented subjects, multilingual filler bodies, and URL-pool stuffing that hides a few operator links inside a block of legitimate high-reputation URLs.
Background
Auto-warranty and vehicle-service-contract marketing is among the most heavily abused lead-generation niches in unsolicited outreach. The product has high margins, sells through commissioned affiliates, and uses the "your coverage is about to expire" pretext to manufacture urgency among a large population of vehicle owners. Regulators treat the space as a standing priority. The FCC maintains a consumer advisory on auto-warranty scams and in 2022 proposed a roughly $300 million forfeiture, its largest robocall action to date, against an operation that placed more than five billion auto-warranty robocalls in about three months. The FTC has pursued the same vertical for over a decade, from a 2009 robocall ban to 2023 lifetime industry bans against operators of an extended-vehicle-warranty telemarketing scheme. Both agencies make the same point: these are vehicle service contracts deceptively marketed as manufacturer "warranties."
The infrastructure follows the economics. In an affiliate lead-gen model, the monetized asset is a qualified consumer lead rather than a stolen credential or payment card. The lure only has to send a recipient to an opt-in quote page that captures contact and vehicle details. The lead is then sold into a marketplace or directly to a contract seller, allowing the operator to profit per lead whether or not a sale closes. The build serves that purpose. It is tuned for deliverability and click-through at scale, not data exfiltration or malware, which explains its use of trusted cloud hosts, authenticated compromised domains, and reputation-diluted content.
Several platforms abused by this operation recur throughout the technical analysis and warrant a plain-English explanation:
- Azure Blob Storage (
*.blob.core.windows[.]net), AWS S3 (*.amazonaws[.]com), and Google Cloud Storage (storage.googleapis[.]com) are public cloud object stores. An attacker uploads a lure or redirect asset to a public container, giving the link a Fortune-100 cloud domain with valid TLS. Containers take seconds to create, cost almost nothing, and are disposable, so the operator can replace a killed bucket faster than a blocklist updates. - IPv4-mapped IPv6 URL literals express a dotted-decimal IPv4 address as an IPv6 literal in hexadecimal, for example
[::ffff:d83a:d2c7]. The literal resolves to the same server as the plain IPv4, but reputation lookups and IOC extractors that do not normalize it back to the real address cannot recognize the text. - ColoCrossing and OVH are commodity VPS providers that rent servers cheaply, in bulk, and with fast turn-up. The operator places raw-IP redirect backends on these ranges because the addresses are cheap, disposable, and rotate faster than reputation feeds.
Discovery and Infrastructure
The impersonated brand is the one signal the operator cannot rotate. Searching for a single brand keyword across the subject, display name, and body exposed the entire cluster, despite a sender pool split across thousands of unrelated domains. The resulting pattern was clear: hundreds of thousands of brand-themed messages over roughly 90 days, sent from 6,384 distinct sender addresses across 2,947 compromised from-domains, with tens of thousands of messages carrying branded attachments instead of a click link.
The domains reveal the infrastructure model. The sending and redirect hosts are aged legitimate small-business sites, not a same-week batch of newly registered burners. A WHOIS pull across a 25-domain sample of the pool found no domain younger than 2020, a creation span of 2004 to 2019, and a registrar mix (GoDaddy, Dynadot, Name.com, and several others including a Japanese registrar) consistent with opportunistic takeover of pre-owned domains rather than adversary registration. Every sampled domain used WHOIS privacy or full redaction, and none exposed a genuine business org. The operator takes over these domains, self-issues passing SPF, DKIM, and DMARC through the real domain's own DNS, and inherits the domain's clean history. Authentication-based heuristics therefore see aligned, authenticated mail from an established business.
Click-through is distributed across three rails, preventing a single takedown from collapsing the operation:
| Rail | Where it lives | Why it resists blocking |
|---|---|---|
| PHP redirect kit | /r*.php?32= on compromised aged hosts |
Both sender and CTA sit on a real business domain with clean reputation |
| Cloud-storage image lure | Azure Blob (88 containers), S3 (19 hosts across seven regions), GCS (1 host) | Link inherits a trusted cloud domain; ~80% of containers used once |
| Raw-IP backend | IPv4-mapped IPv6 literals on rented VPS IPs | No domain or hostname for reputation systems to key on |
How It Works
A representative message impersonates an auto-warranty brand in the display name, uses an obfuscated urgency subject, and places a short image or link call-to-action inside filler. The display name often appends the sending domain's own name in parentheses, a quirk of the sending tool that provides another useful fingerprint. After a recipient clicks, the compromised-host rail passes through a short PHP redirect script (/r*.php?32=<token>). Its 32-prefixed token encodes an affiliate tracking ID, and the script sends the victim to an opt-in quote page. The image-CTA rail links instead to a one-shot cloud-storage asset. The raw-IP rail directs the click to an IPv4-mapped IPv6 literal, bypassing domain reputation lookup entirely.
The sending process uses templates. Recognizable local-part prefixes recur verbatim across many unrelated compromised domains, indicating one centralized send pipeline rather than many independent senders. The operator then applies heavy obfuscation to the subject and display name so that exact-string and keyword matching fail while the brand remains readable to a person.
Sample Lures
All samples are defanged and redacted. Sending domains are compromised third-party small-business sites (victims) and appear as placeholders rather than by name. Recipient identifiers have been replaced with [recipient token].
Endurance pretext on the PHP redirect kit:
From: "✦ENDURANCE✦(<compromised-domain>)" <no_reply@<compromised-domain>[.]com>
Subject: ✔$300 Off Vehicle Coverage:Drive With Peace OfMind!
Body: 👉Hi [recipient token]🔵
hxxp://<compromised-domain>[.]com/re3c5[.]php?32=<encoded-token>
CarShield "you're eligible" quote lure on the image-CTA rail:
From: "Car|shield" <no_reply@<compromised-domain>[.]com>
Subject: CONGRATS YOU'RE ELIGIBLE FOR 2026 DISCOUNTS
Body: PRE-APPROVED ✔: [recipient token] Your Auto Coverage for 2026 is
available [image click-through to cloud-storage lure asset]
Obfuscated display name with URL-pool-stuffing body:
From: "(PoLiCyPlUg Savings)" <no_reply@<compromised-domain>[.]com>
Subject: *[recipient token]* RATES AS LOW AS $174 FOR 6 MONTHS OF COVERAGE
Body: Hi [recipient token], This is a Meeting for CarSHIELD.. ID: 2148...
[recycled legitimate meeting-invite thread with high-reputation
Google/Zoom/UN URLs surrounding one operator CTA]
Technical Analysis
Sending Infrastructure: Aged Compromised Domains
The operator does not use a domain-generation algorithm because it does not register the domains. Its sending and redirect hosts are compromised legitimate small-business sites, so the pool's WHOIS records show the sites' genuine, aged histories rather than an adversary registration batch.
| Cohort dimension | Sample result (25 domains) |
|---|---|
| Creation year | 100% pre-2020; span 2004 to 2019, densest around 2006, 2009, 2012, 2014 |
| Registrar | GoDaddy 14, Dynadot 5, Name.com 2, plus eNom, GMO Internet (JP), Tucows, Porkbun |
| WHOIS org | 9 explicit privacy shields, 16 NULL or redacted, zero genuine business org exposed |
The lack of a same-week registration cohort matters. Newly-registered-domain scoring, one of the cheapest and most reliable phishing signals, yields nothing here. These domains predate the campaign by years, have warmed sending histories, and pass alignment because the operator controls their DNS.
The Sender Local-Part Is the Operator's Generated Artifact
Because the operator borrows the domain, the local part of the address is the durable element it generates. The format follows a decoration grammar, with a small set of stable vertical tokens surrounded by padding characters and decorative Unicode.
| Family / pattern | Example | Pretext |
|---|---|---|
<token>-no_reply@ |
fresh per-send local part, return-path mirrors from-domain | CarShield (primary) |
5things@ |
one domain, one 5things@ mailbox, "Jason | CarShield" display |
CarShield |
barak.ravid@, realmadrid14*, mashreq*, 5coassa* |
fixed prefix reused across unrelated domains | CarShield / AutoPolicyDirect |
Underscore-padded _{3,} |
_carshield_protection_team_@, **auto__insurance**@ |
multi-vertical |
| IP-prefixed local part | 66.219.96[.]94rf-kkkk____________@ |
CarShield |
| Vertical-token decoration | cheap_auto_savings / ~cheap_auto_savings~ / cheap/auto/savings / cheap_auto_______savings |
auto insurance |
The subject and display name use a parallel obfuscation grammar: punctuation fragmentation (Last, Chance: Request, Your, Rate,), pseudo-spaces inside tokens (Y our (CAR) broke down ?), homoglyph substitution (runnıng with a dotless i, chαnces with a Greek alpha, a Greek mu in MyQµotes), leet in high-signal words (PR0TECTI00N, Y0urCar's), brand-token splitting (car//shield, EN: DU@TR:AN@N- CE), and decorative-glyph or zero-width padding in the display name (CarShield_USA˯˯˯˯˯˯˯˯•°˜"˜, a trailing U+200D on Jason | CarShield).
The /r*.php?32= Multi-Vertical Redirect Kit
One PHP redirect kit supports the entire operation. Each compromised host exposes a four-character script matching /r[a-z0-9]{3,4}\.php\?32=<token>, where the 32-prefixed token encodes an affiliate tracking ID generated by the same system. The same path supports at least six lead-gen verticals in parallel (a seventh, AHS Home Warranty, was grafted on later). Sibling verticals also appear on the same compromised hosts, confirming that they are rotations of one kit rather than separate operators.
| Sending vertical (local-part token) | Pretext brand | CTA rail |
|---|---|---|
cheap_auto_savings / cheapautosavings |
Auto insurance / CarShield | /r*.php?32= kit |
endurance_auto / ~endurance_auto~ |
Endurance | kit + image CTA |
fidelity_lifeinsurance / *fidelity___life* |
Fidelity Life | kit + attachment |
fastrates-update / fast-insurance-rates |
Generic rate lure | kit |
quote_pending / quotepending |
CarShield quote | kit |
debtreliefprogram |
Debt relief cross-sell | kit |
ahs_home_warranty |
AHS Home Warranty | kit |
Three CTA Rails and the Raw-IP Backend
The cloud-storage rail places an image-only click-through on Azure Blob, S3, and GCS. It uses keyboard-mash container names (mtc9py283o, ofzeizeigezfqsezigzqsgzze) and a burn-once lifecycle. The raw-IP rail is the most resistant to reputation checks. Click traffic goes to an IPv4-mapped IPv6 literal such as hxxps://[::ffff:9213:1894]/quote, which maps to a rented OVH address, while additional mapped-literal prefixes rotate across ColoCrossing and OVH backends. Because the URL contains no domain or hostname, a reputation lookup based on a name returns nothing.
Content-Level Evasion
Two body-level tactics weaken content signals. Multilingual filler surrounds the short brand CTA with long blocks of unrelated foreign-language newsletter text (German, Spanish, Japanese, Hebrew), disrupting bag-of-words and language-model classifiers based on English scam phrasing. URL-pool stuffing goes further by inserting a complete recycled legitimate email thread. In one observed case, a real meeting invite carried Google, Zoom, and UN URLs at roughly an 8-to-1 ratio of high-reputation to operator links. This pulls any classifier that averages or ratios link reputation toward clean, while burying the few operator URLs in noise.
The attachment rail is a separate delivery mode. Branded attachments replace the CTA link, using extensions that range from real office formats to scripts and fake or typo extensions (.words, .csv81072, .ipad, .instgram). The filenames include Hebrew (מגן רכב.pdf, "vehicle shield"), fullwidth digits, and HTML-fragmented tokens.
Detection Observations
The behavioral signals that distinguish this traffic from legitimate mail are structural rather than superficially content based:
- Aligned, authenticated mail from an aged business domain whose DMARC aggregate reports return to itself (
rua=mailto:report@<own-domain>), paired with a strict single-IP SPF record (ip4:<X> -all), is a strong operator fingerprint. A genuinely operated small business rarely combines self-routed DMARC reporting with a locked single-sending-IP posture across a large pool. - The
/r*.php?32=<token>path is a durable cross-vertical pivot: the same four-character-script signature appears regardless of the brand or vertical in rotation. - IPv4-mapped IPv6 URL literals in a message body are almost never legitimate and normalize cleanly to a rentable VPS IP for reputation scoring.
- Keyboard-mash cloud-storage container names that host an image-only CTA, then are used once and discarded, form a recognizable burn-once pattern.
- A link pool dominated by legitimate high-reputation URLs around one or two low-reputation redirectors indicates URL-pool stuffing; the ratio itself is the signal.
- Sender local-part templating, including fixed prefixes reused verbatim across unrelated domains and heavy padding-character decoration around a vertical token, becomes visible at the ecosystem level even when an individual message looks like mildly spammy brand mail.
MITRE F3 Mapping
This mapping follows the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3). F3 uses fraud-specific F1xxx identifiers alongside shared ATT&CK Txxxx techniques; it does not use an FT prefix.
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Phishing: Spearphishing Link (mass email initial contact) | T1566.002 |
| Initial Access | Impersonate Official (auto-warranty brand impersonation) | F1032 |
| Stealth | Social Engineering: Email Spoofing (aligned self-issued auth from compromised domains) | T1684.002 |
| Resource Development | Compromise Accounts: Email Accounts | T1586.002 |
| Resource Development | Compromise Infrastructure | T1584 |
| Resource Development | Acquire Infrastructure: Virtual Private Server (raw-IP CTA backends) | T1583.003 |
| Resource Development | Stage Capabilities (cloud-storage-hosted lure assets) | T1608 |
| Resource Development | Create Fake Materials: Fake Website (opt-in quote page) | F1020.002 |
F3 v1.1 does not yet include a technique for content-based classifier evasion. The homoglyph and punctuation-fragmented subjects, multilingual filler, and URL-pool stuffing described above fall under the Stealth tactic and map to enterprise ATT&CK Obfuscated Files or Information (T1027) and Masquerading (T1036) when a cross-reference is needed.
Indicators of Compromise
All indicators are defanged. The operator sends from compromised legitimate small-business domains, which are victim infrastructure and are intentionally excluded from this list; publishing them would flag the businesses rather than the operator. The operator-controlled indicators suitable for publication are the rented raw-IP CTA backends and the kit path signature.
Hosts / IPs
| Value | Role | Notes |
|---|---|---|
107.155.77[.]44 |
CTA backend | ColoCrossing, rented raw-IP redirector |
107.155.77[.]45 |
CTA backend | ColoCrossing |
192.227.96[.]101 |
CTA backend | ColoCrossing |
192.227.96[.]102 |
CTA backend | ColoCrossing |
15.235.106[.]247 |
CTA backend | OVH (BHS) |
15.235.149[.]112 |
CTA backend | OVH (BHS) |
51.161.50[.]129 |
CTA backend | OVH (CA) |
146.19.24[.]0/x |
CTA backend | OVH (CA); target of the mapped-IPv6 literal below |
158.51.120[.]36 |
CTA backend | rented VPS |
64.31.47[.]132 |
CTA backend | rented VPS |
67.23.233[.]235 |
CTA backend | bare-IP redirector variant |
URLs
| Value | Role | Notes |
|---|---|---|
hxxps://[::ffff:9213:1894]/quote |
CTA | IPv4-mapped IPv6 literal; resolves to the OVH-CA backend |
Kit / Path Signatures
| Value | Role | Notes |
|---|---|---|
/r[a-z0-9]{3,4}\.php\?32=<token> |
Redirect kit | PHP kit path on compromised hosts; 32-prefixed affiliate token |
Conclusion
The operation remains resilient because it owns almost none of its infrastructure. After a compromised host is taken down, the kit reappears on another aged domain. When a cloud bucket is blocked, another can be created in seconds. The raw-IP backends rotate faster than reputation feeds. Defenders therefore have more stable ground in the fingerprints than in the infrastructure: the pairing of self-routed DMARC with single-IP SPF, the /r*.php?32= path, the mapped-IPv6 literals, and the templated local-part grammar. New brand arms and vertical tokens are likely to appear on the same kit because the operator adds pretexts far more often than it changes how the system is built.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.