P2 High · Deceptive Lead Generation · GDPR Violation · Spam Infrastructure · voyager-ship.com Platform

Case 008 — vorortliefernsender.de
Fake Delivery Domain · White-Label Scam Site · Lead 365 Ltd Data Broker

A domain name meaning "local delivery sender" — designed for spam campaigns impersonating parcel delivery companies — serves a generic fitness template built by voyager-ship.com, operated by Buncha Media UG, Hamburg. A single HTTP response cookie leaked the complete platform config, operator identity, and the hidden UK data broker: Lead 365 Ltd, Gloucester. Email infrastructure spans 11 /24 subnets (2,816 IPs) across two German bulk email providers.

P2 High Deceptive Domain Name GDPR Art.5 / Art.13 Cookie Config Leak voyager-ship.com Platform Next.js / Cloudflare 2,816 Spam IPs Buncha Media UG · Hamburg Lead 365 Ltd · UK Data Broker Passive OSINT Only
Target Domainvorortliefernsender.de
StatusLIVE — Active Lead Harvest
Platformvoyager-ship.com
OperatorBuncha Media UG · Hamburg
Data BrokerLead 365 Ltd · UK
Spam IPs2,816 (11 × /24)
StackNext.js · Express · Cloudflare
Finding 1 — Cookie Config Leak: Complete Platform Config in Plain HTTP Response

The very first HTTP response from vorortliefernsender.de set a cookie named templateData containing URL-encoded JSON. No authentication or special tools required — every visitor receives this data on page load. Decoded, it reveals the complete platform configuration, operator identity, and the backend SaaS provider:

# Set-Cookie: templateData=[...] — decoded from URL encoding: [ { "id": "16164e139ff5d6df449ed81c886414a3", ← template UUID "template_name": "Default", ← template not customised "template_language":"de", ← German "logo_url": "voyager-ship.com", ← platform backend revealed "company": { "id": "6ca33756311081b6c15f2e6e92e33c9e", ← company UUID "name": "Buncha Media UG", "address": "Buncha Media UG (Haftungsbeschränkt)\nMittelweg 144, 20148 Hamburg\nLegal Representative: Thomas Tirling\nE-Mail: kontakt@buncha.org", "created_at": "2025-11-28T04:21:09.000Z", "updated_at": "2025-12-23T07:06:00.000Z" } } ]
Operational security failure: The platform (voyager-ship.com) exposes its own backend name, the operator's legal company data, and internal UUIDs in a browser-readable cookie on every page load. Any visitor — or any abuse team — can extract the full operator chain from a single curl request. This is the primary intelligence pivot for the entire investigation.
Platform
voyager-ship.com
Operator
Buncha Media UG
Legal Rep
Thomas Tirling
Address
Mittelweg 144, 20148 Hamburg
Contact
kontakt@buncha.org
Template
"Default" (not customised)
Finding 2 — Domain Deception: "Local Delivery Sender" ≠ Fitness Platform

vorortliefernsender.de translates to "local delivery sender" (Vorort = local/suburban, Liefer = delivery, Sender = sender). The domain is designed to appear as a parcel delivery company — the exact profile used in German-language smishing and spam campaigns: "Ihr Paket konnte nicht zugestellt werden" (Your package could not be delivered).

The actual landing page serves the platform's uncustomised "Default" fitness template:

  • "DEFINIERE DEIN TRAINING NEU" (Redefine your training) — sports and workout content
  • Images of cyclists, surfers, skiers, tennis players
  • Features: "Ernährung & Mahlzeitenpläne", "Leistungsanalysen", "Zugriff über mehrere Geräte"
  • The page header even uses the domain name verbatim as the brand: "⚡ Vorortliefernsender"

The template was never configured. The operator registered a delivery-sounding domain for spam campaigns and never updated the landing page content — the actual payload is the newsletter email collection form in the page footer, not the visible content.

UWG §5 violation: The domain name constitutes a misleading commercial communication under German Unfair Commercial Practices law (UWG §5 — irreführende geschäftliche Handlungen). Consumers clicking a link from a spam email referencing package delivery would reasonably believe they're visiting a logistics company's website. The reality — a fitness template collecting email subscriptions for a UK data broker — is materially different from the implied identity.
Finding 3 — Hidden Data Broker: Lead 365 Ltd (UK) Disclosed Only in Privacy Policy Fine Print

The privacy policy, reachable at /privacy-policy, reveals the actual purpose of email collection and the undisclosed data recipient:

"We may use your personal data to inform you and offer you claims management services and related campaigns that we believe may be of interest to you."

The domain implies a delivery company. The visible site shows a fitness platform. The privacy policy discloses the actual use: claims management services — a third entirely different industry. Buried in the "Marketing Services Providers / Sponsors" section:

# From /privacy-policy — Marketing Services Providers / Sponsors section: Lead 365 Ltd 6th Floor, Alexandra Warehouse, West Quay, Gloucester, GL1 2LG, UK Sector: Marketing Services, Data Processing http://www.lead365.co.uk/privacy-policy # Also disclosed in privacy policy: UK GDPR compliance mentioned → but the site serves EU/German users Post-Brexit UK is a third country for GDPR purposes EU → UK data transfer legal basis: not specified in policy # Terms and Conditions page (/terms-and-conditions): "Services to be provided by , ('') to the customer" ← company name field is BLANK Template never configured — operator's legal name missing from own ToS
GDPR Article 13 violation: At the point of data collection (the newsletter form), there is no disclosure that data will be shared with Lead 365 Ltd or transferred to the UK. The only mention is buried in the privacy policy under "Marketing Services Providers." Under GDPR Art.13(1)(e), recipients of personal data must be disclosed before collection, not hidden in linked documents. The Terms and Conditions page has a blank company name — confirming the template was copy-pasted without legal review.
Finding 4 — Industrial Spam Infrastructure: 11 × /24 Subnets · 2,816 Authorized Send IPs

The domain's SPF (Sender Policy Framework) DNS record authorizes 11 separate /24 subnets to send email as @vorortliefernsender.de. This is not a configuration mistake — it reflects the actual bulk email infrastructure behind the operation:

IP RangeOwner (ASN)CountryType
193.107.76.0/24Audience Serv GmbH (AS212886)DE · EssenBulk email platform
193.107.77.0/24Audience Serv GmbH (AS212886)DE · EssenBulk email platform
193.107.78.0/24Audience Serv GmbH (AS212886)DE · EssenBulk email platform
193.107.79.0/24Audience Serv GmbH (AS212886)DE · EssenBulk email platform
185.236.128.0/24Audience Serv GmbH (AS212886)DE · EssenBulk email platform
45.81.228.0/24mailcommerce GmbH (AS212745)DE · EssenBulk email platform
45.81.229.0/24mailcommerce GmbH (AS212745)DE · EssenBulk email platform
45.81.230.0/24mailcommerce GmbH (AS212745)DE · EssenBulk email platform
45.81.231.0/24mailcommerce GmbH (AS212745)DE · EssenBulk email platform
77.247.193.0/24mailcommerce GmbH (AS212745)DE · DüsseldorfBulk email platform
176.57.53.0/24iLevant FZE (AS60849)JO · AmmanInternational routing
Scale context: 11 × /24 = 2,816 IP addresses authorized to send email as @vorortliefernsender.de. Legitimate small businesses use 1-3 IP addresses for email. 2,816 IPs is the infrastructure of an industrial email marketing operation. Both Audience Serv GmbH and mailcommerce GmbH are established German bulk-email ESP (Email Service Provider) platforms — being used here to send campaigns impersonating a delivery company. The Jordan-based iLevant FZE range suggests international campaign routing to bypass German spam filters.
Finding 5 — Platform Analysis: voyager-ship.com White-Label Site Generator

voyager-ship.com is the backend SaaS platform generating these white-label sites. It is built on Express.js + Next.js (same tech stack as the front-end sites), hosted behind Cloudflare. Its public root returns 404 {"message":"Not Found - /"} — no public-facing marketing site, no signup page, no documentation visible.

What is known from the leaked templateData cookie structure:

  • It maintains a template library (UUIDs per template) with language-specific variants
  • It maintains a company registry (UUIDs per operator) with address, legal rep, privacy/ToC content
  • Operators register companies on the platform, select templates, point domains at the generated Next.js app
  • The platform injects company data client-side via the cookie and React context (CompanyProvider, TemplateProvider visible in page source)
  • The "Default" fitness template appears to be a placeholder — sites are meant to be customised but many aren't

The platform design enables the creation of large numbers of disposable lead-gen sites across different domains, all sharing the same backend. Each domain gets a different company identity but the same infrastructure.

# voyager-ship.com infrastructure: IP 188.114.96.3 / 188.114.97.3 ← Cloudflare-proxied Stack Express.js + Next.js (React SSR) NS tani.ns.cloudflare.com / vin.ns.cloudflare.com Root 404 {"message":"Not Found - /"} ← no public frontend # Site generation architecture (inferred from page source): React providers CompanyProvider ← injects company data from cookie TemplateProvider ← selects template layout Cookie templateData ← carries full config client-side (data leak) Google verify 7ajit9FpxBhvE67c1QQdQZH4qNUQMAtInXvGGyzJrWQ ← GSC ownership confirmed
Reporting Actions Taken

Regulatory compliance case: deceptive domain + GDPR data harvesting + industrial spam infrastructure. Reporting targets cover German data protection, German anti-spam enforcement, UK data protection (for Lead 365), and Cloudflare for hosting deceptive content.

BfDI — German Federal Data Protection Commissioner

Reported to poststelle@bfdi.bund.de. Domain impersonates a delivery company to lure German users into submitting email addresses. Data is shared with UK-based Lead 365 Ltd without adequate disclosure at point of collection (GDPR Art.13 violation). Post-Brexit UK transfer lacks stated legal basis. Privacy policy mentions "claims management services" — unrelated to delivery or fitness — confirming the deceptive collection purpose.

Bundesnetzagentur — German Anti-Spam Authority

Reported via spam@bundesnetzagentur.de. SPF record for vorortliefernsender.de authorizes 2,816 IP addresses across Audience Serv GmbH (AS212886) and mailcommerce GmbH (AS212745) for bulk email. Sending commercial email impersonating a delivery company without prior consent of recipients violates UWG §7 (unverlangte Werbung — unsolicited commercial communication).

ICO — UK Information Commissioner's Office

Reported via https://ico.org.uk/make-a-complaint/. Lead 365 Ltd (Gloucester, UK) receives personal data of EU citizens from this operation. The privacy policy discloses Lead 365 as a data recipient but provides no legal basis for the EU→UK cross-border transfer. UK is a third country under GDPR; an adequacy decision exists but transfer conditions must still be met. Lead 365's own website must also disclose receiving EU data under UK GDPR.

Cloudflare — Hosting Abuse

Reported to abuse@cloudflare.com. vorortliefernsender.de and voyager-ship.com are both Cloudflare-proxied. The platform facilitates deceptive lead generation using misleading domain names to collect personal data for undisclosed third-party brokers. Cloudflare ToS Section 2.8 prohibits using services to facilitate deceptive or fraudulent activity.

Method — Intelligence Chain from a Single HTTP Request

Phase 1 — Initial HTTP probe: A standard curl -sI request returned HTTP headers including a Set-Cookie header with URL-encoded JSON. This single response provided: platform identity (voyager-ship.com), operator name, address, legal representative, email, and internal UUIDs.

Phase 2 — DNS analysis: SPF TXT record contained 11 IP ranges. Each IP looked up against ASN data revealed two German bulk-email ESP providers (Audience Serv GmbH, mailcommerce GmbH) and a Jordan-based routing provider, confirming industrial-scale outbound email operation.

Phase 3 — Page source analysis: Full HTML fetch revealed the Next.js platform architecture, React context providers (CompanyProvider, TemplateProvider), and the mismatch between domain name (delivery) and page content (fitness). The blank company name in Terms and Conditions confirmed the template was deployed without customisation.

Phase 4 — Privacy policy extraction: The /privacy-policy route disclosed Lead 365 Ltd as the downstream data recipient, the actual stated purpose (claims management services), and the missing EU→UK transfer legal basis — the three core GDPR violations documented in this case.

Key OSINT technique: Misconfigured or over-verbose HTTP cookies are a consistently underrated intelligence source. In this case, a single Set-Cookie header from the first page load disclosed what would otherwise require hours of investigation: the SaaS platform, operator identity, company registration details, and all internal IDs needed to pivot to related infrastructure. Passive HTTP response header analysis is always step one.
IOC Table
Domain vorortliefernsender.de Lead-gen site (delivery domain name) IPs 172.67.158.117 / 104.21.50.69 Cloudflare proxy NS tani/vin .ns.cloudflare.com Platform voyager-ship.com White-label site SaaS (Express+Next.js) Platform IPs 188.114.96.3 / 188.114.97.3 Cloudflare proxy Operator Buncha Media UG Address Mittelweg 144, 20148 Hamburg, DE Legal Rep Thomas Tirling Contact kontakt@buncha.org Data Broker Lead 365 Ltd Alexandra Warehouse, Gloucester, UK SPF providers Audience Serv GmbH (AS212886) Essen DE · 5× /24 mailcommerce GmbH (AS212745) Essen/Düsseldorf DE · 5× /24 iLevant FZE (AS60849) Amman JO · 1× /24 Total send IPs 2,816 (11 × /24 subnets) Template ID 16164e139ff5d6df449ed81c886414a3 voyager-ship.com internal Company ID 6ca33756311081b6c15f2e6e92e33c9e voyager-ship.com internal
Live Evidence — Screenshot Captured 2026-08-16

Screenshot confirms the domain-content mismatch in action: the header reads "⚡ Vorortliefernsender" (the delivery domain name, used verbatim as the brand) while the page shows fitness content — cycling, surfing, tennis. The template was never configured to match the domain's implied identity. The newsletter signup form collecting data for Lead 365 Ltd appears in the footer below this fold.

vorortliefernsender.de — DELIVERY DOMAIN · FITNESS CONTENT · BUNCHA MEDIA UG ⚠ DECEPTIVE LEAD-GEN
Screenshot: vorortliefernsender.de fitness template on fake delivery domain

Domain implies parcel delivery company. Page serves uncustomised fitness template. Newsletter form in footer collects emails for Lead 365 Ltd UK data broker. Complete operator chain identified from first HTTP response cookie.

Live Infrastructure Status
Loading status…
Previous: Case 007 — Netflix PhaaS Next: Case 009 — bpost-secure.com
SevinOS BLE Radar