> the following stages were too sophisticated for some person to just serve me an ad.
You may not believe me, but this is much less sophisticated than some of the things I have seen; My opinion is that the people who participate in ad fraud are a lot more sophisticated than any of the ad-fraud detection/protection "vendors" working to try and stop it.
To give you an idea of what I mean, "these guys" might not have been trying to show you an ad at all, but to sell your traffic (or normal looking cookies) to someone else who has already sold an ad, but just want something to juice the click-rate or the conversion-rate of some other traffic, and so if you weren't in that market, they won't even serve you the content that performs these steps.
> I'm very confident that they tore down their C2 after seeing either a (in their eyes) successful callback, or me badger their server with follow on requests.
No doubt. Unusual traffic tends to spook them. They will shut everything down, then use google search to look for their domain name in blogs and stuff, and if that doesn't happen, and their "customer" doesn't complain about anything, they will resume the juicing.