Fraud: Investments Corporation | Faith Isabella - The Bulk Mailer's Demo Project, Sent by Mistake
Warning: do not use this project as a template for your mailing campaign! A fraudster sent us the built-in demo file of a commercial mass-mail program instead of the scam, exposing the machinery behind the campaign.
Complete Emailβ
from: Faith Isabella faithisabelL@faithsella.com
to: info@secure-techie.com
date: 07/22/2026 6:12 AM
subject: Investments Corporation
Attachment: Horoscope.txt (0.4 KB) - blocked by the receiving server.
Email Bodyβ
Warning: do not use this project as a template for your mailing campaign!
This project demonstrates some of Gammadyne Mailer's capabilities, especially the GβMerge scripting language. We won't mind if you send us this message, although it would be more useful to send it to yourself. Your first project should be created from scratch: choose "New Project" from the File menu.
Before sending this message, you will need to specify the relaying SMTP Server on the Servers/SMTP branch.
Basic Tags:
Recipient: info@secure-techie.com
Email: info@secure-techie.com
Full Name:
First Name:
Last Name:
Date formatting:
Now: 7/22/2026 7:42:15
Years: 26,2026,Twenty Six,Twenty Twenty Six
Months: 7,07,Jul,July
Days: 22,22,22nd,Twenty Second
WeekDays: 4,04,Wed,Wednesday
Hours: 7,07,7,07
Minutes: 42,42
Seconds: 15,15
AM/PM: a,a.m.
Date formatted to system settings:
7/22/2026
7:42:15 a.m.
7/22/2026 7:42:15 a.m.
Data switching:
Bool true=true=true
Int six=six
String 6=6
Default Default=Default
Thirty days from today: 21 Aug 2026
Test of formatted expressions: string6:=string6:
Test of default: abc=abc
What follows is roughly a thousand further lines of the same thing - the demo project's automated self-test, printing a numbered result for every scripting feature it exercises. It is reproduced in full below because its sheer length is the evidence.
Show the complete test output (approximately 1,000 lines)
IF-Statements (all of these should display "ok", not "FAIL")
11 ok
13 ok
15 ok
31 ok
32 ok
34 ok
51 ok
52 ok
53 ok
71 ok
72 ok
73 ok
74 ok
75 ok
76 ok
77 ok
81 ok
82 ok
83 ok
84 ok
85 ok
86 ok
87 ok
91 ok
92 ok
93 ok
94 ok
101 ok
102 ok
103 ok
104 ok
110 ok
111 ok
112 ok
113 ok
114 ok
115 ok
116 ok
117 ok
120 ok
121 ok
122 ok
123 ok
130 ok
131 ok
132 ok
140 ok
141 ok
142 ok
143 ok
144 ok
145 ok
146 ok
147 ok
148 ok
149 ok
150 ok
151 ok
152 ok
153 ok
154 ok
160 ok
161 ok
162 ok
163 ok
While Loops:
xxxxx=xxxxx
xxxxxx=xxxxxx
Variable Testing
1 ok
2 ok
3 ok
4 ok
5 ok
Nested IF:
1 ok
2 ok
3 ok
Functions
100 ok
101 ok
102 ok
103 ok
104 ok
105 ok
110 ok
111 ok
112 ok
120 ok
121 ok
122 ok
130 ok
131 ok
132 ok
133 ok
140 ok
141 ok
142 ok
143 ok
150 ok
151 ok
152 ok
153 ok
160 ok
161 ok
162 ok
163 ok
170 FAIL
171 ok
180 ok
181 ok
182 ok
183 ok
184 ok
185 ok
186 ok
187 ok
190 ok
191 ok
192 ok
200 ok
201 ok
202 ok
210 ok
211 ok
212 ok
213 ok
220 ok
221 ok
222 ok
223 ok
224 ok
225 ok
226 ok
227 ok
228 ok
229 ok
230 ok
231 ok
232 ok
232 ok
234 ok
235 ok
240 ok
261 ok
270 ok
271 ok
272 ok
273 ok
280 ok4
281 ok3
282 ok3
283 ok4
290 ok
291 ok
292 FAIL
293 ok
294 ok
295 ok
300 ok
301 ok
302 ok
303 ok
304 ok
305 ok
306 ok
307 ok
308 ok
310 ok
311 ok
312 ok
313 ok
314 ok
315 ok
316 ok
317 ok
322 ok
330 ok
331 ok
332 ok
335 ok
336 ok
337 ok
338 ok
343 ok
345 ok
346 ok
347 ok
349 ok
350 ok
351 ok
352 ok
353 ok
354 ok
355 ok
356 ok
357 ok
358 ok
359 ok
360 ok
361 ok
365 ok
366 ok
370 ok
371 ok
380 ok
381 ok
382 ok
383 ok
390 ok
391 ok
392 ok
393 ok
400 ok
401 ok
402 ok
403 ok
410 ok
420 ok
421 ok
422 ok
423 ok
430 ok
431 ok
440 ok
450 ok
451 ok
452 ok
453 ok
460 ok
461 ok
480 ok
481 ok
490 ok
491 ok
500 ok
501 ok
502 ok
503 ok
510 ok
511 ok
512 ok
513 ok
514 ok
520 ok
521 ok
522 ok
523 ok
524 ok
530 ok
531 ok
532 ok
533 ok
534 ok
540 ok
541 ok
542 ok
543 ok
544 ok
550 ok
551 ok
552 ok
553 ok
554 ok
555 ok
560 ok
561 ok
562 ok
563 ok
564 ok
565 ok
570 ok
571 ok
572 ok
573 ok
574 ok
575 ok
580 ok
581 ok
582 ok
583 ok
584 ok
585 ok
590 ok
591 ok
592 ok
593 ok
594 ok
595 ok
600 ok
601 ok
602 ok
630 ok
631 ok
632 ok
633 ok
640 ok
660 ok
661 ok
662 ok
670 ok
671 ok
672 ok
680 ok
690 ok
691 ok
692 ok
693 ok
700 ok
701 ok
702 ok
703 ok
704 ok
705 ok
706 ok
710 ok
711 ok
720 ok
721 ok
730 ok
731 ok
740 ok
741 ok
742 ok
750 ok
760 ok
770 ok
780 ok
790 ok
800 ok
810 ok
820 ok
830 ok
850 ok
860 ok
870 ok
880 ok
890 ok
900 ok
910 ok
920 ok
930 ok
935 ok
940 ok
950 ok
960 ok
970 ok
980 ok
990 ok
1000 ok
1010 ok
1020 ok
1030 ok
1040 ok
1050 ok
1060 ok
1070 ok
1080 ok
1090 ok
1100 ok
1110 ok
1120 ok
1130 ok
1140 ok
1150 ok
1160 ok
1170 ok
1180 ok
1190 ok
1200 ok
1205 ok
1210 ok
1220 ok
1230 ok
1280 ok
1290 ok
1300 ok
1310 ok
1320 ok
1330 ok
1340 ok
1350 ok
1360 ok
1370 ok
1380 ok
1390 ok
1400 ok
1410 ok
1420 ok
1430 ok
1440 ok
1450 ok
1460 ok
1470 ok
1480 ok
1490 ok
1500 ok
1510 ok
1520 ok
1550 ok
1560 ok
1570 ok
1580 ok
1590 ok
1600 ok
1610 ok
1630 ok
1640 ok
1650 ok
1660 ok
1670 ok
1680 ok
1690 ok
1700 ok
1710 ok
1720 ok
1730 ok
1860 ok
1870 ok
1880 ok
1890 ok
1900 ok
1910 ok
1920 ok
1930 ok
1940 ok
1950 ok
1960 ok
1970 ok
1980 ok
1990 ok
2000 ok
2010 ok
2020 ok
2030 ok
2040 ok
2060 ok
2070 ok
2080 ok
2090 ok
2100 ok
2110 ok
2120 ok
2130 ok
2140 ok
2150 ok
2160 ok
2170 ok
2180 ok
2190 ok
2200 ok
2210 ok
2220 ok
2230 ok
2240 ok
2250 ok
2260 ok
2270 ok
2280 ok
2290 ok
2300 ok
2310 ok
2320 ok
2330 ok
2340 ok
2350 ok
2360 ok
2370 ok
2380 ok
2390 ok
2400 ok
2410 ok
2420 ok
2430 ok
2431 ok
2432 ok
2433 ok
2440 ok
2445 ok
2446 ok
2447 ok
2448 ok
2450 ok
2451 ok
2452 ok
2453 ok
2460 ok
2470 ok
2471 ok
2472 ok
2480 ok
2481 ok
2482 ok
2490 ok
2491 ok
2500 ok
2501 ok
2510 ok
2511 ok
2512 ok
2513 ok
2514 ok
2515 ok
2516 ok
2520 ok
2521 ok
2522 ok
2523 ok
2524 ok
2525 ok
2526 ok
2527 ok
2528 ok
2529 ok
2530 ok
2531 ok
2532 ok
2533 ok
2534 ok
2535 ok
2536 ok
2537 ok
2538 ok
2539 ok
2540 ok
2541 ok
2542 ok
2543 ok
2544 ok
2550 ok
2551 ok
2552 ok
2560 ok
2561 ok
2562 ok
2563 ok
2570 ok
2571 ok
2572 ok
2573 ok
2574 ok
2575 ok
2576 ok
2577 ok
External Email
![]()
Red Flagsβ
Most scam emails have to be taken apart to reveal how they were made. This one arrived already disassembled. The subject line says Investments Corporation - the same subject, from the same persona, that reached this inbox a week earlier carrying a textbook advance-fee investment approach. What follows the subject line this time is not a scam at all. It is the sample file that ships inside a commercial mass-mailing program, sent out unedited because whoever pressed Send never opened the message.
The result is unusual and worth studying: instead of the story the fraudster wanted you to read, we get the tooling, the list quality, the merge fields, and the sending machine's clock.
1. This Is Not an Email. It Is a Bulk-Mail Program's Demo Fileβ
- Line one: "This project demonstrates some of Gammadyne Mailer's capabilities, especially the GβMerge scripting language."
Gammadyne Mailer is real, legitimate, commercially sold Windows software for sending mass email. It ships with a demonstration project that shows off its scripting engine, and this message is that demonstration project, transmitted verbatim.
That single fact answers a question you can normally only guess at. This was not typed into a webmail window by a person writing to you. It was assembled and fired by desktop campaign software, at whatever volume the operator's relay would carry - and if the demo went to this address, it went to every other address on the same list at the same time.
The second sentence gives away the mechanism: G-Merge is a scripting language. It exists so that each outgoing copy can be different - names substituted, sentences conditionally swapped, dates and figures generated on the fly. That is a personalisation feature for marketers and an evasion feature for fraudsters, because a message that is textually different in every copy is harder for filters to fingerprint. The thousand lines of test output are the operator's tool proving that its IF statements, loops, and string functions all work.
2. It Ignored an Instruction Printed at the Top of Its Own Messageβ
- "Warning: do not use this project as a template for your mailing campaign!"
- "Your first project should be created from scratch: choose 'New Project' from the File menu."
- "Before sending this message, you will need to specify the relaying SMTP Server on the Servers/SMTP branch."
The very first line of the email you received is the software's own warning not to send it, in bold, with an exclamation mark. The vendor put it there precisely to stop this from happening.
The third line is more revealing. It is a setup instruction telling the user to configure a relaying SMTP server before sending - and that setup was evidently completed, because the message arrived. A relay had been configured; nothing else had. Someone got the delivery infrastructure working, then hit Send on the file that was already open in front of them.
3. The Blank Merge Fields Prove the List Is Scraped and Namelessβ
Recipient: info@secure-techie.com
Email: info@secure-techie.com
Full Name:
First Name:
Last Name:
This is the single most valuable thing in the message. Those five lines are the demo asking the mail engine to print what it knows about you, personally, from the campaign's own database. Here is the entire answer:
The address is populated twice, because the address is all there is. Full Name, First Name and Last Name are empty. Not wrong, not misspelled - empty.
A list built from real business relationships, a purchased marketing list, or genuine research would carry names. This one carries nothing but strings harvested from web pages, WHOIS records, and directory scrapes. It also explains a detail from the earlier email in this campaign, which opened with a bare "Hello," and never once used a name or a company: the sender was not being coy. There was nothing in the field to merge.
Note too that Recipient and Email returned the same value. In a properly built campaign those are distinct fields - a display name and an address. Collapsed into one, they confirm a single-column import.
4. The Subject Line and the Body Are From Different Universesβ
The subject reads Investments Corporation. The body contains no investment, no corporation, no proposal, no greeting, no signature, and no request. It does not mention money, property, partnership, or the recipient's business.
The subject line survived because it lives in a different field of the campaign - the operator had already set it for this run. Only the message body reverted to the demo. What that tells you is that this send was part of a live campaign, mid-flight, not an idle experiment: the subject was configured, the recipient list was loaded, the relay was live. Only the payload was wrong.
5. The Sender Address Is a Throwaway Built From an Invented Nameβ
- Address:
faithisabelL@faithsella.com
Two things stand out. The local part ends in a capital L - faithisabel followed by L, not the doubled lowercase ll of "Isabella". In many sans-serif fonts a capital L is not what the eye expects there, and the name as typed is not the name in the signature of the earlier email. It is close enough to pass a glance and wrong under inspection.
The domain is worse. faithsella.com is a blend of the sender's own invented first name and the tail of her invented surname - faith plus sella, from Isabella. It has no relationship to "Investments Corporation" or to any business. A corporation moving investor capital does not send mail from a domain named after one employee's forename, because that is not what a corporate domain is.
6. Same Persona, Same Subject, New Domain, Seven Days Laterβ
Line the two messages up:
| 15 July 2026 | 22 July 2026 | |
|---|---|---|
| Display name | Mrs. Faith Isabella | Faith Isabella |
| Subject | Investments Corporation | Investments Corporation |
| Address | faithisbella01@faithi.com | faithisabelL@faithsella.com |
| Domain | faithi.com | faithsella.com |
Identical persona, identical subject line, two entirely different domains one week apart - and each domain is a different scramble of the same fake name, each misspelling it differently.
This is disposable infrastructure, and the rotation is deliberate. A domain used for bulk fraud gets reported, blocklisted, and suspended within days, so the operator registers cheap replacements and moves the campaign across. Blocking the sender therefore buys you almost nothing; a new address is a few rupees and a few minutes away. The persona is the constant. The infrastructure is consumable.
7. The Clock Inside the Message Contradicts the Clock on the Deliveryβ
- Delivered: Wednesday, 22 July 2026 at 6:12 AM (recipient's local time, IST)
- Generated inside the message: "Now: 7/22/2026 7:42:15"
That Now: value is not decoration. G-Merge evaluated it against the sending machine's system clock at the moment the message was assembled, which must be at or before the moment it was delivered.
Instead it reads one hour and thirty minutes later. A message cannot be composed after it arrives, so the two clocks are not in the same timezone - and IST plus 1:30 is UTC+07:00. That band runs through mainland Southeast Asia and western Indonesia. The demo helpfully confirmed the same instant three more ways, including "Thirty days from today: 21 Aug 2026" and "WeekDays: 4,04,Wed,Wednesday", so the date itself is not in doubt - only the offset.
Treat this as an indication rather than a certainty: a misconfigured clock or a VPS rented in one region and operated from another would produce the same reading. But it is a genuine artefact of the sender's environment, leaked by the sender's own tool, and it is the sort of thing no scam email is ever supposed to contain.
8. Horoscope.txt - The Demo's Sample Attachment, Not the Scam'sβ
A message about an investment corporation arrived carrying a 0.4 KB text file called Horoscope.txt. It is the demo project's own sample attachment, included to show that the software can attach files, and it came along for the ride exactly as the body did.
Two lessons sit in that tiny file. The first is corroboration: the attachment configuration was inherited from the demo too, which means the send was wholly unreviewed rather than partly. The second is capability. The operator's tooling attaches files to bulk sends as a matter of course, and this time the payload was harmless only by accident. The receiving server blocked it regardless - "Some of the attachments are blocked to be downloaded by the server" - which is the correct handling for any unexpected attachment from an unverified sender.
9. Nobody Read It - The Message Reports Its Own Failuresβ
Buried in the output, among hundreds of lines reading ok, are two that do not:
170 FAIL
292 FAIL
The email the fraudster sent to a cybersecurity company contains the word FAIL, twice, in its own self-test - under a heading that explicitly states "all of these should display 'ok', not 'FAIL'".
The point is not that the software has two failing checks. It is that not one human being looked at this message between composition and delivery. No proof, no test send, no glance at the preview pane. This is what an automated fraud pipeline looks like when it is run carelessly, and it is a fair indication of the attention paid to every other message the same operator sends.
10. Three Verdicts Before the First Line of Textβ
The mail client had already ruled on this message in three separate banners, stacked above the body:
Unverified, beside the sender's name - the message failed sender-authentication checks. A domain registered days earlier for a single campaign rarely carries validSPF,DKIM, andDMARCrecords.- "This message appears to be Junk. Links and other functionality will not work." - the provider's filter, with link handling disabled as a precaution.
- "Some of the attachments are blocked to be downloaded by the server." -
Horoscope.txtquarantined on arrival.
And at the very end of the body, one more:
External Email
That line is not the sender's sign-off. It is the banner injected by the receiving mail gateway, marking the message as originating outside the organisation, and it has been absorbed into the message text. Four independent safety signals fired before a single word was read. The only way this email causes harm is if a person overrules all four.
How This Scam Worksβ
This message asks for nothing, because it was never meant to be sent. It is a misfire in the middle of a running advance-fee campaign - the same campaign whose properly-composed version reached this inbox seven days earlier. Its value is that it shows the assembly line rather than the product.
- Harvest: Addresses are scraped in bulk from websites,
WHOISrecords, and business directories.info@,sales@, andcontact@addresses are the richest seam, because they are published deliberately and answered by someone whose job is to be helpful. The blank name fields in this message are the receipt for that method. - Tool Up: A desktop mass-mailer is configured with a relaying
SMTPserver and a throwaway sending domain - here, a domain named after the fake persona rather than the fake company. - Script the Personalisation: The scripting engine composes each copy differently, substituting whatever fields the list carries and varying the wording so that no two messages are textually identical. This is what defeats signature-based filtering, and it is the feature the demo file exists to advertise.
- Blast and Qualify: The campaign goes out to the entire list at once. Nothing is asked for in the first message except a reply, because the reply is the product - it separates attended, business-owning inboxes from dead addresses on the same scraped list.
- Escalate the Repliers: Only those who answer are worked by hand. A more senior character is introduced, a specific mandate appears, and paperwork begins to circulate - non-disclosure agreements, "investor profile" forms, company registration documents, financials, banking details.
- Charge the Fee: The deal is approved and waiting, held up by one final obstacle only the victim can clear: a transfer levy, an anti-money-laundering certificate, a lawyer's retainer, a notary fee. The sums are always smaller than the prize, which is the entire arithmetic of advance-fee fraud, and each payment reveals the next obstacle.
- Rotate and Repeat: The sending domain is reported and burned within days, so it is discarded and replaced. The persona, the subject line, and the list survive.
faithi.combecamefaithsella.comin a week;faithsella.comwill have become something else by now.
The misfire changes nothing about that pipeline. It only means that on 22 July, at step four, the wrong file was in the window.
Conclusion and Recommendationsβ
An advance-fee fraud operation accidentally mailed out the sample file that ships with its bulk-mailing software, and in doing so published its own case notes: the name of the tool, the fact that it scripts each copy to defeat filters, proof that its recipient list contains addresses and nothing else, a sending machine roughly two zones east of India, and confirmation that no human reviews the outbound mail. The subject line still said "Investments Corporation" because the campaign was live at the time.
Nothing here is dangerous. Everything here is instructive, and the same operator is still sending - from a different domain by now, with the correct body attached.
Immediate Actions:β
- Do Not Reply: Not even to point out the mistake, and not out of curiosity about what the message was supposed to be. A reply to a bulk-mailed address does one thing: it confirms an attended mailbox at a real company and promotes you from a scraped string to a qualified target on a hand-worked list.
- Do Not Open the Attachment:
Horoscope.txtis inert, but that is luck rather than judgement - the same pipeline attaches whatever the operator configures. The server blocking it was correct handling; leave it blocked and delete the message. - Treat the Earlier Message as the Real One: If anyone in your organisation replied to the 15 July "Investments Corporation" email, that thread is the live risk, not this one. Stop the correspondence and send nothing further, particularly company documents.
- Report It as Fraud: Flag it in your mail client so the pattern is learned across the tenant. In India, report to the National Cyber Crime Reporting Portal at
cybercrime.gov.inor the helpline 1930. - Block the Domain, But Do Not Rely on It: Add
faithsella.comandfaithi.comto your blocklist. It costs nothing and buys little - the next domain is already registered.
Verification Steps:β
- Read the Header Block Before the Body: The sender's address, the authentication badge, and the delivery time sat above this message and told the whole story.
faithisabelL@faithsella.comnames no company;Unverifiedmeans the domain could not prove it sent the mail. - Search the Distinctive Sentences: Paste an exact line - "This project demonstrates some of Gammadyne Mailer's capabilities" - into a search engine, and the message identifies itself as vendor sample text in seconds. The technique generalises: any unusual phrase from an unexpected email, searched verbatim, will either place it in a known campaign or return nothing at all, and both answers are useful.
- Check the Domain, Not the Display Name: Run a
WHOISlookup on the sending domain. A registration created days or weeks ago, behind privacy protection, is decisive for an entity claiming an established investment practice. - Look the Company Up: A firm handling investor capital appears in a companies register - MCA in India, Companies House in the UK, the equivalent elsewhere - and usually in a financial regulator's register too. Nothing in this campaign can be looked up, which is why it is named the way it is.
- Compare Against Earlier Mail From the Same Persona: Keep reported scam mail rather than deleting it. Placing these two messages side by side is what exposed the domain rotation, and it is the sort of link no single message reveals on its own.
Additional Protection Tipsβ
- Understand What a Reply Is Worth: On a scraped list of a hundred thousand addresses, almost nothing comes back. The handful that do are worked individually, for months. Silence is not rudeness - it is the only response that keeps you off that shorter list.
- Do Not Read a Bungled Email as a Harmless One: Incompetence and intent are unrelated. The pipeline that misfired here is the same one that delivers the polished version, and the operator gets unlimited attempts.
- Treat Unsolicited Offers of Capital With More Suspicion Than Sales Pitches: An inbound offer of money lowers defences in a way a sales pitch never does, because it flatters the recipient into believing they were selected. Nobody was selected. The list was.
- Reduce What Can Be Scraped: Every address published in plain text on a website, in a
WHOISrecord, or in a directory listing ends up on lists like this one. Use forms, role addresses, andWHOISprivacy where you can, and accept that a publishedinfo@address will receive this traffic permanently. - Route Investment and Partnership Approaches Through One Person: Decide who evaluates inbound funding offers, and require that anything reaching a shared inbox goes to them unanswered. This removes the well-meant individual reply that starts the entire sequence.
- Enforce SPF, DKIM, and DMARC on Your Own Domain: It will not stop mail from
faithsella.com, but it stops the next operator from running a campaign like this one against your staff and customers using your company's name. - Never Pay a Fee to Receive Money: Adopt it as a standing rule, decided in advance, so that nobody has to make the judgement while excited about a deal. No legitimate investor charges you for the privilege of accepting their capital.
Remember: Fraud at this scale is not written, it is manufactured - and the machine that manufactures it leaves fingerprints. This one printed its tooling, its list quality, and its clock straight into the message. When an email arrives that clearly nobody read before sending, you are not looking at a person who wants to do business with you. You are looking at one address out of a hundred thousand, and the only question the sender has is whether you will answer.
