The Frozen Build Timestamp: Fingerprinting a Multi-Vertical Lead-Gen Kit
The Frozen Build Timestamp: Fingerprinting a Multi-Vertical Lead-Gen Kit
Since January 2026, one operator has run auto-insurance lead-gen from hundreds of aged, drop-caught domains, each stamped with one frozen build timestamp. The kit rotates senders, click-through domains, and lure verticals constantly, and it splits delivery across two parallel rails to keep any single sending address below the volume a reputation system needs to score it. Two things never change: a hard-coded template build timestamp and a Goldman Sachs unsubscribe URL that leads nowhere. Together those two artifacts collapse a deliberately fragmented sending operation into a single attributable operator.
Key Takeaways
- A frozen template build timestamp,
2025.09.23-15.41.30, unchanged across five months and more than 186 sender apexes, is the operator's single strongest cross-rail correlator. - The operator embeds a real Goldman Sachs tracking URL in the
List-Unsubscribeheader as a legitimacy prop. The URL is a decoy that never resolves as a click destination, and Goldman is a spoofed brand here, not a participant. - Delivery runs on two owned rails that differ only by sender-address shape: a persistent per-apex rail on ESP-style subdomains, and a burner rail that discards each address after a single send.
- Nearly every sending domain is an aged drop-catch registration from 2001 to 2019, with clean history and no brand token, chosen to defeat domain-age reputation heuristics.
- A self-hosted
/r<hex>.php?32=redirect script on the sender apex keeps the click path off third-party shortener reputation lists. - Lure verticals rotate on shared infrastructure across at least nine themes, from auto insurance to life insurance, debt relief, and retail-rewards bait.
Background
Auto-warranty and vehicle-service-contract lead generation is one of the longest-running high-volume spam ecosystems targeting US consumers, driven by lucrative per-lead payouts for "extended coverage" sign-ups. It has drawn sustained federal enforcement: the FTC permanently banned the Transcontinental Warranty / Voice Touch robocall operation and returned roughly $3.2M to victims, and the FCC later proposed a fine of nearly $300M against the robocall ring behind billions of auto-warranty calls, eventually ordering carriers to block the traffic. The operator profiled here is the inbox analogue of that robocall economy. The same "your auto coverage" pitch, monetized as leads, has migrated to self-hosted email on aged domains.
Two techniques recur throughout this campaign, and their combination at this scale is unusual enough to define before going deeper.
Aged drop-catch domains are expired registrations that fall back to the open market and get re-bought, often through auction or drop-catch services. Operators want them because mail filters treat domain age as a trust signal. Reputation attaches to the name rather than the owner, so a new operator inherits years of clean history without earning it, sidestepping the "newly registered domain is suspicious" heuristic entirely.
The List-Unsubscribe header (RFC 2369 and RFC 8058) tells a mail client where to send an opt-out request. Here the operator points it at a real, well-reputed Goldman Sachs tracking URL that never unsubscribes anything. The legitimate brand host is borrowed purely to make the message headers look trustworthy to a filter that might weight a recognizable corporate domain in the header pane.
Discovery and Infrastructure
The operator's most useful mistake is a build artifact. Every message from the primary rails carries the literal string 2025.09.23-15.41.30 inside the body template, a fixed build timestamp the operator has never rotated even as it churns everything else. Pivoting on that string surfaces the full cluster in a single pass: more than 300 distinct sender local-parts spread across at least 186 sender apex domains, running continuously from mid-January 2026 to late June. In aggregate the campaign accounts for tens of thousands of messages.
The sending footprint is engineered for fragmentation. The operator uses roughly one mailbox per apex, then rotates, so no single sending address accumulates the repeat volume a per-sender reputation system needs to build a bad score. Self-hosted SPF, DKIM, and DMARC records sit on each apex and align on the same domain, which tells us the operator controls the mail server rather than relaying through a shared ESP.
Within that footprint we mapped a smaller, currently active cohort of 27 operator-controlled sender-and-redirector apexes pushing an auto-insurance "$39/Month" pitch. Every apex in this cohort is confirmed malicious infrastructure, and every one is an aged drop-catch shell.
How It Works
A recipient receives a message whose subject embeds their own email handle as personalization theatre, for example a quote pitch that opens with the handle followed by an "as low as $38/month" hook. The visible body sometimes carries the real lure and sometimes carries unrelated decoy text (fake academic-consultation copy, trade-show filler) while the actual pitch lives only in the subject and preview line. The List-Unsubscribe header shows a Goldman Sachs URL, lending the headers a corporate sheen. When the recipient clicks through, the link resolves to a /r<hex>.php?32= redirect script hosted on the sending apex itself, which bounces them onward to whatever landing page the operator is currently monetizing. Because the redirector is self-hosted, the operator can swap destinations without re-sending and keeps the click path off shortener blocklists.
Sample Lures (Email)
Attacker-side content only. Every recipient identifier has been replaced with a placeholder, and all domains are defanged. The Goldman URL shown is a spoofed decoy that points at genuine Goldman Sachs infrastructure and should not be blocked.
Burner sub-rail, one-shot rotating sender, with the decoy unsubscribe header and a decoy visible body:
From: cheaprates@akdxu.can.tirexresources[.]com
Subject: [ VEHICLE [Q U O T E S] ... ] Save up to 50% [recipient-handle]?
List-Unsubscribe: <http[:]//tracking.gs[.]com/mail/un-subscribe/m/eo?id=221B928D-C14A-4084-9E21-BEF767CE19FA&sid=100001>
[visible body: decoy "CodeBook University" academic-consultation HTML]
[click target, embedded rather than linked: http[:]//can.tirexresources[.]com/rc50c.php?32=1o776a3121...]
Persistent rail, "$39/Month" pitch with a Unicode-padded display name:
From: "AUTOㅤINSURANCEㅤ" <recalculaatedrates.fi@instantgod[.]com>
Subject: AutoInsurance Coverage Starting At $39/Month
The display name is padded with U+3164 Hangul-filler characters, a byte sequence shared verbatim across several connect.<apex> senders on the persistent rail.
Cross-vertical rotation, retail-discount bait borrowing a well-known auto-warranty brand name as the display name:
From: "CarShield!" <[random-token]@localcontractorsnews[.]com>
Subject: Congrats! You're Eligible for 2026 Discounts!
Technical Analysis
The value in this campaign is not any single message. It is the way a deliberately noisy, high-churn operation reduces to a compact set of durable signatures once the infrastructure is laid out. This section is the operator's build sheet.
Two-Rail Sender Grammar
The kit delivers on two owned rails that carry an identical payload and differ only in the shape of the sending address. A third sending family, on compromised third-party servers, was later merged into the same operator and is covered under Cross-Cluster Pivots.
The persistent rail places one durable mailbox on a named ESP-style prefix of the apex. Observed prefixes include connect., mailer., software., tall., c., us5., and the tell-tale fdffsdf., alongside bare-apex senders. These addresses stay put and build a little sending history.
The burner sub-rail prepends a random five-letter label to a mail. or can. node, for example insured@abujk.mail.klikkauai[.]com, and discards each label after a single send. Twelve distinct burner apexes appear in the confirmed set: eleven under .mail. and one under .can.. The heaviest-churn apexes each spin up around eleven one-shot senders in a burst. The burner sub-rail is the operator's lowest-cost lane: each address carries no sending history and its self-hosted redirect target never surfaces as an extractable click URL.
| Rail | Sender shape (defanged) | Sending behavior |
|---|---|---|
| Persistent | <localpart>@connect.newavenow[.]com, <localpart>@software.sapporosystem[.]com, <localpart>@fdffsdf.1688house[.]com |
Stable per-apex, builds thin history |
| Burner sub-rail | insured@<5char>.mail.klikkauai[.]com, cheaprates@<5char>.can.tirexresources[.]com |
One-shot, discarded after a single send |
The Aged Drop-Catch Domain Portfolio
Of the 27 operator-controlled cohort apexes, 26 are aged drop-catch registrations and exactly one is a fresh throwaway. The aged names cluster heavily in 2001 to 2010, with a smaller 2014 to 2019 tail, and the lone outlier, mayorrational[.]my, was registered only days before use on the .my ccTLD. GoDaddy and its resellers register the majority of the pool, with a thin spread across Name.com, Dynadot, eNom, and others. WHOIS organization is almost universally null or privacy-shielded.
| Apex (defanged) | Registrar | Created | Rail |
|---|---|---|---|
| klikkauai[.]com | GoDaddy | 2001 | burner (.mail.) |
| scoutstewart[.]com | GoDaddy | 2002 | burner (.mail.) |
| sapporosystem[.]com | GMO Internet | 2005 | persistent (software.) |
| tattooljubo[.]com | eNom | 2005 | persistent (tall.) |
| bidlawn[.]com | GoDaddy | 2006 | burner (.mail.) |
| rockclimbingbot[.]com | Name.com | 2007 | persistent (bare apex) |
| 22hughesnet[.]com | GoDaddy | 2008 | persistent (bare apex) |
| instantgod[.]com | Name.com | 2009 | persistent / redirect host |
| elisezeppelin[.]com | GoDaddy | 2009 | burner (.mail.) |
| calcoasthydro[.]com | GoDaddy | 2010 | burner (.mail.) |
| newavenow[.]com | Dynadot | 2014 | persistent (connect.) |
| stateofnews[.]com | Name.com | 2018 | persistent (connect.) |
| tirexresources[.]com | Dynadot | 2019 | burner (.can.) |
| mayorrational[.]my | Spaceship | 2026 | burner (fresh throwaway) |
The apex names read as generic small-business or personal-site strings, which is exactly what they were before drop-catch. Several are brand-suggestive but are not the brand they evoke: 22hughesnet[.]com is not a HughesNet property, sapporosystem[.]com is not the Sapporo beverage brand, and wakeupnowinc[.]com is not the defunct MLM of a similar name. All are aged shells, not domain-level brand impersonation.
The Frozen Build Timestamp and the Decoy Unsubscribe Header
Two artifacts anchor attribution. The first is the build timestamp 2025.09.23-15.41.30, baked into the message template and never changed. Because the operator rotates senders, domains, click targets, and verticals but treats this string as a non-indicator, it survives across the entire campaign and behaves as a near-perfect, low-false-positive operator marker.
The second is the fake Goldman Sachs List-Unsubscribe header. The operator embeds a genuine Goldman tracking URL on tracking.gs[.]com, real corporate infrastructure that is verified legitimate and never resolves as a click destination in this campaign. The unsubscribe token rotates per cohort but is reused verbatim across otherwise unrelated apexes inside a cohort. The June cohort, for instance, shares the token 221B928D-C14A-4084-9E21-BEF767CE19FA across elisezeppelin[.]com, hemsleaders[.]com, and tirexresources[.]com, which makes it a strong intra-cohort correlator on top of the timestamp.
Local-Part Families and Vertical Rotation
Local-part construction follows a small set of stylized templates, and the templates map loosely onto lure verticals. The same shared infrastructure carries at least nine themes.
| Local-part family (example, defanged) | Lure vertical |
|---|---|
_*cheap_auto_savings_**_@, auto_insurance~!@, autoinsurance~*@ |
Auto insurance |
insured@, insuredauto@, quotes@, quotecenter@, cheaprates@ (burner rail) |
Auto-insurance quotes |
*quote~wizard!!@, quotesauto*@ |
Auto-insurance quotes |
recalculaatedrates.<2c>@ |
Auto-rate "recalculation" |
fast_rates, fastrates, **fastrates-update**@ |
Auto-rate lead-gen (merged family) |
enduranceauto~!@ |
Vehicle-service-contract |
*fidelity-life#_<2c>@ |
Life insurance |
*liberty~mutual!!@ |
Insurance-brand impersonation |
debtrelief~services@ |
Debt relief |
Sam's Club rewards, casino rewards, contractor "2026 Discounts" bait, and clinical-trial recruitment round out the vertical rotation. The sender theme does not predict the vertical, which is expected when a single kit drives every lure.
Cross-Cluster Pivots
The load-bearing correlators tie the two owned rails, several registrar cohorts, and a large secondary local-part family into one operator. The frozen build timestamp is primary. The self-hosted /r<hex>.php?32= redirect kit on the sender apex is second. The per-cohort Goldman unsubscribe token is third. A sprawling fast_rates / fastrates local-part family, spread across many compromised third-party small-business mail servers, initially looked like a separate actor. It merged into this operator once the same frozen timestamp and the same June Goldman token turned up on its sends. The distinction matters: the operator's compromised-server sending is separate from its owned drop-catch domains, but the payload fingerprints cross both.
Detection Observations
The campaign separates cleanly from legitimate mail on structural grounds rather than content grounds, which is where a defender should key.
The strongest behavioral signal is the frozen build-timestamp string in the body template. It is operator-unique and survives every rotation the operator performs, so it functions as a durable content fingerprint independent of sender or domain.
The burner sub-rail is recognizable by sender-address structure alone: a random five-character label on a mail. or can. node under an aged apex, paired with heavily obfuscated auto-insurance subject text such as spaced-out Q U O T E S tokens and Unicode-padded display names. Individually, each of these one-shot addresses looks like unremarkable low-volume mail. The pattern is visible at the apex and rail level, not the single-message level.
A trusted-brand URL in the List-Unsubscribe header that never appears as an actual click target is itself a signal worth treating as suspicious rather than reassuring, because header-only brand borrowing is the whole point of the technique. Aged drop-catch apexes carrying self-hosted, self-aligned SPF, DKIM, and DMARC, running a /r<hex>.php?32= redirect script on the sending domain, complete the structural profile.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The Goldman tracking.gs[.]com URL is a spoofed decoy pointing at legitimate Goldman Sachs infrastructure and must not be blocked.
Sender Addresses (representative)
| Value | Rail | Notes |
|---|---|---|
recalculaatedrates.fi@instantgod[.]com |
Persistent | "$39/Month" pitch |
newavenow@connect.newavenow[.]com |
Persistent | ESP-style prefix |
cheapservices@software.sapporosystem[.]com |
Persistent | ESP-style prefix |
rec.alculatedr.ates@fdffsdf.1688house[.]com |
Persistent | fdffsdf. prefix |
car.sh.ieldusa@rockclimbingbot[.]com |
Persistent | Brand-borrow local-part |
insuredauto@ilurq.mail.bidlawn[.]com |
Burner | One-shot |
quotes@fpibk.mail.elisezeppelin[.]com |
Burner | One-shot |
quotecenter@eeser.hemsleaders[.]com |
Burner | One-shot |
cheaprates@akdxu.can.tirexresources[.]com |
Burner | .can. one-shot |
insured@abujk.mail.klikkauai[.]com |
Burner | One-shot |
kevinbrooks@assentingly.mayorrational[.]my |
Burner | Fresh throwaway apex |
fastrates@ont6.staging.cachepages[.]com |
Merged family | Compromised-server sending |
Representative subset; hundreds of verified-malicious sender addresses tracked across the campaign.
Operator Domains (sender and redirector apexes)
| Value | Role | Notes |
|---|---|---|
instantgod[.]com |
Sender / redirect host | Persistent rail |
newavenow[.]com |
Sender apex | Persistent rail (connect.) |
stateofnews[.]com |
Sender apex | Persistent rail (connect.) |
jollybabyclub[.]com |
Sender apex | Persistent rail (connect.) |
sapporosystem[.]com |
Sender apex | Not the Sapporo beverage brand |
22hughesnet[.]com |
Sender apex | Not a HughesNet property |
tattooljubo[.]com |
Sender apex | Persistent rail (tall.) |
1688house[.]com |
Sender apex | Persistent rail (fdffsdf.) |
elisezeppelin[.]com |
Sender apex | Burner sub-rail; shares June token |
hemsleaders[.]com |
Sender apex | Burner sub-rail; shares June token |
tirexresources[.]com |
Sender / redirect host | Burner sub-rail (.can.); shares June token |
bidlawn[.]com |
Sender apex | Burner sub-rail |
calcoasthydro[.]com |
Sender apex | Burner sub-rail |
klikkauai[.]com |
Sender apex | Burner sub-rail |
mayorrational[.]my |
Sender apex | Fresh throwaway (2026) |
Active-cohort subset; 27 operator-controlled apexes confirmed, part of a broader pool of more than 186 sender apexes across the full campaign.
Message Fingerprints
| Value | Type | Notes |
|---|---|---|
2025.09.23-15.41.30 |
Body-template build timestamp | Frozen operator marker; primary correlator |
221B928D-C14A-4084-9E21-BEF767CE19FA |
Fake-unsubscribe token (June cohort) | Reused verbatim across cohort apexes |
http[:]//tracking.gs[.]com/mail/un-subscribe/... |
Decoy List-Unsubscribe URL |
Goldman-owned, spoofed, do not block |
http[:]//<sender-apex>/r<hex>.php?32=<token> |
Self-hosted redirect kit | Runs on the sending apex |
AUTOㅤINSURANCEㅤ |
Unicode-padded display name | U+3164 filler; shared across persistent rail |
Conclusion
The operator's discipline is real everywhere except its build pipeline. It rotates domains, sender shapes, click targets, and lure verticals with care, and it fragments delivery specifically to starve reputation systems. Yet it ships every message with the same hard-coded build timestamp and the same recycled decoy unsubscribe token, treating both as invisible. For defenders, the takeaway is that durable content and header artifacts, not sender reputation, are what unify an operation built to look like noise. Watch the build strings the operator forgets to rotate.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.