Illustration generated for this article. Every prop is a finding: the sack of blank name badges is the Faker persona namespace, the rubber stamp ...
For further actions, you may consider blocking this person and/or reporting abuse
Great investigation from a spam comment that we all see at some point! Good work Don :)
Awesome post, I liked this investigation!
Two comments of this exact template landed under unrelated DEV posts today, and both shorteners put me back on your host:
tinyurl.com/ykka56aptozenviapro.store/massapply?along=zowie,tinyurl.com/42jatv3wtozenviapro.store/ainotetaker?dress=hovel. The parameter name is randomized, not only its value —whose,along,dress, andmadlyacross four samples, the last one being the linkmarianhuels45529dropped in this very thread. That extends your inert-prop finding rather than just confirming it: your sweep held the key fixed and varied the value, and nothing moved because the key is generated per comment too, so it is uniqueness noise rather than segmentation and no value of it could ever have routed anything. The other thing four samples show is a second route./ainotetakeranswers today and 302s tobluedothq.com/?via=us, a different product with a different Rewardful token, so this is not one domain and one route but a small rack with at least two products on it, and the three-signups-a-year break-even becomes a per-product figure.Really solid investigation, especially the fact that you documented the false attribution lead instead of quietly dropping it.
One small evidentiary distinction I’d make: showing that Jaylon, Stiedemann, and Terry all exist in Faker datasets demonstrates that the username is consistent with automated generation, but it doesn’t quite prove Faker provenance from a single account.
That argument would get much stronger if you found multiple accounts using the same {firstName}_{lastName}-{lastName}{NN} structure with tokens mapping back to the same locale or generator family.
That aside, the preservation, redirect tracing, IOC work, and disconfirmation section are unusually well done for a spam investigation.
The cost model is the sharp part: low conversion economics explain why weak attribution does not make the operation irrational. A useful defensive extension would be to record the redirect chain and account signals as structured evidence, so moderation has a reusable pattern instead of a one-off anecdote.
The break-even math is the part that actually matters — three signups a year to cover domain + shortener costs means the economics are basically unkillable. I ran similar attribution on spam hitting my own API docs last year and hit the same wall: the redirect chain resolves, the affiliate code resolves, but the human behind the faker.js persona never does. The wombat engraving is a nice touch but the real finding is that "who" is a dead question when the cost of being nobody is $2.
The game is afoot! Well played.
great inestigation and great title lol