General discussion

Benutzerbild

If ya want my money, 'an' ya think I'm gullible, c'mon Saphie scam me now!

If ya want my money, 'an' ya think I'm gullible, c'mon Saphie scam me now!

"Okay, so I completely ruined what used to be a great Rod Stewart song - but it's been worth it. I was alerted by my friend Dee Hughes over at Freeware Home, of a rogue domain one of her visitors came across during a Google search for Outlook Express that led via the Sponsored results (surprise surprise) to expressdownloadz.com (see left).

She asked if I could dig up anything on this domain as she'd not found any contact information or anything that would help her take it down. Naturally I offered to help (I do love exposing these scheming wan**rs). Off I trotted to expressdownloadz.com, and low and behold, instantly identified the type of scam, and thus, how to track it.

expressdownloadz.com is identical to thousands of other itty bitty phishy sites out there, and it's stats are as follows;

IP: 72.10.171.202
IP PTR: Resolution failed
ASN: 36666 72.10.168.0/22 GTCOMM - GloboTech Communications
Created: October 19th 2009"

Read more
http://hphosts.blogspot.com/2009/11/if-ya-want-my-...

Benutzerbild

cardtransaction.com

whois shows the domain: cardtransaction.com as being created 02-Nov-04
go to hxxp://cardtransaction.com/ and you get a generic browser: "Under Construction" page. LOL, you'd think after 5 years they would at least have a homepage up...

This can become quit a dig...
I found several fake AV sites via 72.10.171.202 along with: openofficefree.org
Shame on them wanting to snag your PII for software they don't produce.

[edit]
I see you've done the leg work, nice digs.
Rated all referenced domains and I found a few more stragglers along with the IP's. Referenced your blog, this forum and the wiki page that was commented.
-------
WOT Services Ltd. - gives us safety through Web of Trust.
WOT Community - gives us security through unity.
Thank you all
- G7W