Wednesday, September 30, 2026
The Traceback
Tracing the connections behind cybercrime and digital threats.
By Ayansh Kumar
Investigations

Tracing the Infrastructure Behind a Reusable AI Investment Scam Ecosystem

How an AI-investment scam targeting Indians led to reusable code, shared video infrastructure, historical WHOIS links and a much wider domain network.

Tracing the Infrastructure Behind a Reusable AI Investment Scam Ecosystem

Key Points:

  • trckpb[.]com is an India-focused AI investment funnel promoted through Meta advertising, with leads followed up by telephone.
  • The campaign uses reusable infrastructure rather than a self-contained website. Its video content is hosted on wtcprojects[.]com, while related campaigns load lead-generation code from the public syimono1488/scripts ecosystem.
  • Historical evidence traces similar AI-investment infrastructure back to at least January 2024, with the same broader technical model appearing again in early 2026 and in the current September 2026 campaign.
  • The source-code contained Ukrainian and Russian developer comments, suggesting parts of the tooling were built or maintained in a Russian or Ukrainian-speaking environment. This does not prove the operators’ nationality.
  • Historical WHOIS records for zjcok[.]com and godatahawk[.]com show the same transition from shmek004 [at] gmail.com to syimono1488 [at] gmail.com. The syimono1488 GitHub repository also historically referenced zjcok.com, strengthening the relationship between the two identities.
  • Public-profile and WHOIS-derived records associate the shmek004 identity with the name Dmitry or Dmytro Shved and Zaporizhia, Ukraine. We do not consider this confirmed attribution.
  • The sales operation is heavily localized for India. In a recorded call, the caller discussed Aadhaar verification, a ₹15,200 senior-citizen offer, a supposed Noida office, an alleged Infosys connection and automated AI trading.
  • Our current assessment is that the evidence points to a reusable investment-lead ecosystem that might involve shared tooling, infrastructure providers, affiliates or multiple operators.

Our investigation began with trckpb.com, an AI-themed investment landing page promoted through Meta advertising and targeting users in India.

What initially looked like a single scam site led us to a reusable infrastructure ecosystem with historical activity dating back to at least January 2024.

The campaign

TRCKPB.COM landing page using prominent AI-brand imagery alongside the promotional video

The trckpb.com funnel relies heavily on externally hosted infrastructure. Its promotional video is delivered from wtcprojects.com through an HLS stream at:

  • wtcprojects[.]com/denivideo/ENtrckpb.com/3.m3u8

The page emphasizes telephone verification and states that it collects names, email addresses, telephone numbers, IP addresses, and browsing information.

Security and trust-brand imagery embedded in the landing-page template

The site’s legal content contains several signs of a reusable template. The company name is missing from parts of the terms, the contact email is simply “support@”, a UK address is provided, while the terms state that Japanese law applies.

E-Mail:support@
Adresse:51 Russell Rd, Shifford, UK, OX8 8HY
Telefon:479 8042 4547

Reusable lead-generation code

A major pivot led us to the public GitHub repository syimono1488/scripts.

Public syimono1488/scripts repository containing reusable lead-form logic used across the campaign ecosystem

Its adict.js file contains reusable functionality for collecting and validating first names, surnames, email addresses and international telephone numbers. It supports numerous languages, performs Facebook conversion tracking and submits the visitor’s current landing-page URL alongside the lead.

URLScan showed that this script appears far beyond trckpb.com.

We identified 1,286 scans containing syimono1488.github.io and adict.js. Of those, 287 also contacted wtcprojects.com, while 999 did not.

URLScan Results

URLScan identified 1,286 scans using adict.js, including a 287-scan subset also contacting wtcprojects.com

This indicates that wtcprojects.com is one backend within a much broader landing-page ecosystem rather than a mandatory component of the frontend kit.

A second media domain, wtcpremiumhub.com, appeared within another HLS-video subset, suggesting the video infrastructure can be swapped while the frontend acquisition logic remains reusable.

Developer-language clues

While reviewing the underlying code, we noticed another recurring clue. The captured trckpb.com source contained several developer comments written in Ukrainian, including comments describing interface sections, displaying page elements, right-click handling and keyboard shortcuts. Some of those comments appear directly beside code intended to interfere with right-click, F12, view-source and browser developer tools.

Ukrainian-language developer comments found in the trckpb.com source code

The related adict.js tooling in the public syimono1488/scripts repository also contained Russian-language developer comments and used “ru” as its fallback language when no language was supplied.

Developer's language indication

These language artifacts do not establish the nationality of the people operating the India-facing scam. The developer of the landing-page tooling, the infrastructure maintainer and the people speaking to prospective victims might represent different roles. They do, however, suggest that part of the technical ecosystem was developed or maintained in a Russian or Ukrainian-speaking environment.

Historical activity & infrastructure continuity

Our investigation indicates that the infrastructure behind the current trckpb.com campaign did not appear in 2026.

URLScan result indicating started at least in 2024

The earliest strong historical lead we identified was xelence.orderready.com, captured by URLScan on January 3, 2024. The site promoted an AI-powered automated trading product called “X AI” that claimed high trading success rates, collected telephone leads, and told prospective investors that a manager would contact them before a minimum deposit was made. The page described automated trading and promised users that profits would be generated without trading experience.

Older X AI Scam

Historical scan indicating retrieving promotional video content

The same historical scan was configured to retrieve promotional video content from:

  • wtcprojects[.]com/VT/video/XAIN/video/Xai.mp4

The video request returned 404 during the scan but the configuration establishes that wtcprojects.com was already being used as media infrastructure for an AI-themed investment funnel in January 2024.

By early 2026, the architecture had become closer to what we observed in the current campaign. Historical scans of blagabo.com showed the landing page simultaneously loading reusable frontend assets from syimono1488.github.io/scripts and HLS video content from wtcprojects.com/denivideo/hls/. This is significant because it demonstrates that the frontend and media components later associated with the broader ecosystem were already being deployed together before trckpb.com.

The current trckpb.com campaign continues the same general architecture but with a newer media-provisioning structure:

  • wtcprojects[.]com/denivideo/ENtrckpb.com/3.m3u8

Taken together, the observations show an evolution in the infrastructure rather than a single static setup:

  • January 2024: xelence.orderready[.]com used wtcprojects[.]com for an AI-investment campaign.
  • Early 2026: blagabo[.]com combined the syimono1488 frontend with wtcprojects[.]com HLS media.
  • September 2026: trckpb[.]com used the same broader acquisition model with domain-specific HLS provisioning and reusable lead-generation infrastructure.

This establishes persistent reuse of the technical ecosystem across multiple investment-oriented campaigns over more than two years, while common operator control remains unproven.

From infrastructure to identity clues

The infrastructure investigation also exposed two recurring email identities, shmek004 [at] gmail.com and syimono1488 [at] gmail.com.

A broader review of current and historical registration records found 975 unique domains where both identities appeared in the available registration history. In 857 of those domains, syimono1488 [at] gmail.com remained visible in the available WHOIS contact data, while shmek004 [at] gmail.com appeared in historical records.

This expands the relationship far beyond the two domains we initially identified, zjcok[.]com and godatahawk[.]com.

The relationship indicating identity clues

The overlap suggests a broader registration lineage between the two identities. It does not prove that every domain was transferred from one person to another, or that all 975 domains were controlled by the same operator.

We also found that 69 domains from our broader /denivideo hunting set overlapped with domains directly associated with syimono1488 [at] gmail.com in the registration data. This adds another connection between the registration identity and the infrastructure cluster we had already identified.

Following the older shmek004 identity produced another lead.

Identity-related OSINT lead

A public VK profile using the handle @shmek004 displayed the name Dmitry Shved and listed Zaporizhia as its location.

VK profile

Other public profile pages also associated Shmek004 with Dmitry Shved and Zaporizhia, Ukraine.

Separately, a WHOIS-derived record for godatahawk.com associated the administrator name Dmytro Shved with shmek004 [at] gmail.com.

Public profile page

Separately, a WHOIS-derived record for godatahawk.com associated the administrator name Dmytro Shved with shmek004 [at] gmail.com.

These records provide a suspected profile behind the shmek004 identity but they do not establish the real-world identity of the person operating the investment scam. Registration data is registrant-supplied, profiles might be copied or fabricated, and infrastructure might pass between different people.

From advertising to the sales call

The campaign is also visible at the advertising layer. We found Meta pages including “The Prestige Circle” and “Sovereign Heights” promoting TRCKPB.COM. One of these pages had been created only days before running multiple advertisements.

Meta Ad

Meta Ad

The Prestige Circle was created on September 11, 2026. By September 20, Meta’s Ad Library showed multiple active advertisements connected to the page.

Meta Ads

A recorded call supplied by the original source provides a view of what happens to at least some leads after they enter the funnel.

The caller described an AI trading platform, quoted a normal investment level of roughly ₹20,000 to ₹30,000, and then offered a supposed senior-citizen promotion of ₹15,200 after learning the prospective investor’s age.

The caller requested Aadhaar or similar identification, promised that a “senior account manager” would configure AI trading software, claimed profits would appear in a wallet and pushed the prospect toward an online deposit.

The caller also claimed an association with Infosys and an office in Noida Sector 63. We found no independent evidence supporting that affiliation.

When the prospect attempted to delay the decision, the caller introduced urgency by claiming that the opportunity had limited availability.

The person receiving the call said they had originally encountered the campaign through Instagram. This aligns with the Meta advertising activity observed independently.

The sales call creates an important contrast with the technical evidence. The victim-facing operation is heavily localized for India, using Aadhaar verification, rupee-denominated deposits, a claimed Noida office, an alleged Infosys association and social-media advertising aimed at Indian users. At the same time, parts of the underlying technical ecosystem contain Russian and Ukrainian developer-language artifacts, while the identity trail around shmek004 points toward public records associated with Zaporizhia, Ukraine.

This does not mean the developer and the caller are the same person. One working explanation is a layered operation in which infrastructure or fraud tooling is developed and maintained by one party while separate affiliates or sales teams localize campaigns for specific markets.

Our assessment

The evidence supports the existence of a reusable investment-lead acquisition ecosystem rather than a collection of unrelated standalone websites.

The recurring components include:

  • disposable landing domains,
  • shared lead-generation code,
  • external video infrastructure,
  • AI-themed investment narratives,
  • telephone-number collection,
  • paid social-media advertising,
  • and human follow-up designed to solicit deposits.

The strongest persistent infrastructure identified so far is the syimono1488 frontend ecosystem and the recurring use of wtcprojects.com across investment-oriented campaigns spanning at least January 2024 through September 2026.

We have not established that every domain using these components belongs to one operator. Several explanations remain plausible. The infrastructure might represent a private fraud kit, a developer-maintained platform, a shared lead-generation service, an affiliate model, or a smaller group repeatedly reusing the same tooling. The combination of Russian and Ukrainian developer-language artifacts with an India-focused sales operation makes the developer-plus-affiliate model particularly worth testing, but the current evidence does not establish it.

We also have not yet identified the final payment beneficiary, trading portal, bank account, UPI identifier or cryptocurrency wallet.

That financial layer remains the largest unresolved part of the operation.

the graph

Investment Scam in India (Tckpb.com) — Domain List

  1. Key domains examined during the investigation

blagabo.com
godatahawk.com
syimono1488.github.io
trckpb.com
wtcpremiumhub.com
wtcprojects.com
xelence.orderready.com
zikirim.com
zjcok.com

  1. Related identities and research pivots

Emails:
shmek004 [at] gmail.com
syimono1488 [at] gmail.com
Aliases:
shmek004
syimono1488
Public repository:
github.com/syimono1488/scripts
Suspected profile:
Dmitry / Dmytro Shved
Zaporizhia, Ukraine

CAVEAT: The name and location are derived from public-profile and WHOIS-derived records associated with the shmek004 identity. They do not represent confirmed attribution of the investment-scam operation to a real-world individual.

  1. Broader URLScan /denivideo hunting set

CAVEAT: The domains below were surfaced by a broad URLScan /denivideo search.
Their presence in this hunting set does not establish maliciousness, common control,
or attribution to the same operator. Treat them as leads requiring independent validation.

56484.space
7778.space
aachina-sz.com
abbademos.com
abcd-marly.com
acefleet.space
add-cart.com
adeelinco.space
advemi.com
afterours.space
agro-waste.com
ai-tapp.com
akuamarin.space
alaskabanksandlenders.com
alaskamortgagebankers.com
alevtaki.com
aliyazhou.com
alligatormedia.online
alqirmiz.com
anchoragebuilder.com
anchoragechamberonline.com
andeicto.com
arcanocine.com
artdebrazza.com
arutinvest.com
asclepius.space
asianextacy.com
athletetorchpottery.top
attwq.com
avantace-test.space
avn.news
baazooka.com
babesbot.com
baltiodp-p.netlify.app
bankofbc.com
basicotoyota.com
baushworc.com
bchxmc.com
bepawrepave.com
beteei.com
bicentennially.life
bongogas.com
bpplhubwworld.world
bradybrady.space
brightline.space
bunadistrict.com
buzmoney.com
calimete.com
casagoo.space
caschilling.com
cbtech.space
chatapp.space
checkspas.com
chubby-chix.com
citanel.com
citynetdsl.com
cleanorent.com
clickpublishingads1.space
cloufactory.com
cmalphaa.com
coachgato.com
cofelate.com
contactaonce.com
copipfx.com
counselw-pro.com
cpusand.com
crpinvs.site
cryptorooky.news
cspei.com
dazebank.com
dellybu.com
democritus.space
devshare.space
dinobalz.com
dkvms.com
doklerd.com
domainforbetterlife.info
domzasite.com
dotpets.space
dpcssrl.com
eaas-astro-bel.space
earthgroupie.space
eaststreaminghyperion.cloud
edgeplus1template.space
efimant.com
egyton.com
elenkia.com
ellamoria.com
emileniums.com
enemafan.com
enghed.com
ep20-test-filedcv-1426.space
euphrozorh.space
farronatkins.space
fdwzc.space
femtech.space
ffsbofva.com
finanse.new-site.pp.ua
findcovidtests.com
findurwayinthis.info
fine-world.com
flashstorage.space
fledge.space
flo-flg.cloud
flo-fli.cloud
fnbxcz.com
franskevine.com
fugux.com
funnel.aifreedom-news.com
funnel.gptai-innovation.com
funnel.gptai-learn.com
furryplay.space
gadating.com
galaxymoney.space
gasprom-bank.org
gasprombank.org
gasprominvest.ru
gazpramiinvestquiz.org
gazpraminvestquiz.com
gazpraminvestquiz.org
gazproinvestedquiz.org
gazproinvestquiz.org
gazquizprowork.org
gazworkformprom.info
gazworkformprom.org
gazworkpromquiz.org
gazworkquiz.org
gazworkquizprom.org
gciny.com
gczx2.space
giulia.space
gizmomoto.com
gmandcinc.com
gp-bank.org
gprombank.org
gtparkcity.com
gunblood.space
haecki.space
hannovair.com
hapinex.com
hartypress.com
healthslive.com
helloiambobbb.life
hermosodubai.com
hgtktkmin.info
hideyos.live
hlgchina.com
hoduu.com
holabuda.space
homeawayok.com
hubconfirm.com
humanesociety.space
idlerus.space
immersifyu.com
immobilising.info
inblx.com
infibu.com
info1.gptx-passive.com
injvotes.com
innaciti.com
insidewyeth.com
instanton.space
investgazprom.shop
investing-info.ru
investrade-info.ru
iproudest.com
isaacnewton.space
ivykane.com
jcshelpdesk.com
jen-bill.com
jlyqia.com
justrightideas.com
kanema-inc.com
katejohnson.space
katiepedia.com
kelepirsat.com
kolesoobozreniyezajopinsk.info
kqhit.com
kysassafras.com
kyzenadv.com
ladytkd.com
likha.space
lovewhatyoudo.space
lucrandoalto.space
maiibgotoppp.info
mauentp.com
mchciuk.com
mcnutkin.com
me-girl.com
midnightflaregenetic.cloud
minmax.news
mistflake.com
mitelefonica.com
mizunozapato.com
mohamicaba.com
moneyaws.com
monroedealz.com
msrpnot.com
multikarnes.com
mygaz-wilhelm.com
mymoney-info.ru
mymoney-online.ru
mymoney-rus.ru
myneckwear.com
mypatio.space
mystarvingartist.com
mywelhome.com
nation-park.top
netquzhou.com
neueton.com
newhomedoor.com
nihalm.com
nikoupdate.com
niltonsart.com
nitrophyte.com
nocturneburstgenetic.cloud
northblazinggenomic.cloud
notetoker.com
nsbfc.com
osiandrian.life
outas.space
parlainsaat.com
pericn.com
pfoetchen.space
philevsky.com
pidz.space
pingu.space
pokereyewear.com
posled.com
possibgwjw.space
postedanon.com
pottmaenn.space
pqmonitoring.com
premium-truefocus.info
primefactor.cloud
pyragravure.info
pyroimpex.com
qhnump.com
rashtcoffee.com
realhome.space
rheemassoc.com
rilcotech.com
roboterium.com
rockhill-mtl.com
ruicamacho.space
runennis.com
salarmall.com
selmarosen.com
semkroon.com
serious-gas.com
shbcard.com
shineconvincelike.top
shuku.space
sirenldn.com
skoceania.com
skpoland.com
skthailand.com
skypeportal.com
skyriock.com
slosbest.com
sma-geneva.com
snakelike.space
southfierygenetic.cloud
southventralhorizon.cloud
soyyainvest-h.cloud
soyyainvest-j.cloud
speedalam.com
stanleymaria.com
stuckonred.com
subaram.com
subjacencies.life
tahadekor.com
talentmineafrica.com
tbviolins.com
tcinyc.com
tea-and-health.com
techrobinland.world
tedwebs.com
telegram-platform.nfdvcompanf.com
telegram-platform.nfdvcompanof.com
telegram-platform.nfdvcompanyscnd.com
telegram-platform.pnchr-company.website
telegram-platform.telegaproject.ru
telekrediet.com
teslainvest.website
texmexmeterservice.com
theoneprize.space
tidebit.space
tijgernoot.com
tinafortuna.com
travelmars.space
trouvailleaussies.com
tscmlb.com
turbopunks.com
tvnova.news
tzjgxx.com
urmaindia.com
uxdaphne.com
vas.news
vestaxdjschool.com
vidasolteira.com
vijays.space
wabaoke.com
waywavetr.world
welchhotshotservice.com
wespp.com
westfrostbiogen.cloud
whatilearnedtoday.space
whenhow.space
while.news
willardlane.space
wisemode.space
witumki.life
wmgmkt.com
workgazquizpro.org
workquizgazpr.org
workquizgprom.org
workquizprom.org
worldforge.world
worldwheels.world
worldwz.com
x-money.space
xos.news
xoxo444.space
xplanetory.space
yaliceguan.com
yldmodular.com
yxasun.com
zanderguy.com
zyma2122.space

Acknowledgment: Thanks to Shashank Shekhar for sharing the initial lead that prompted this investigation.