Tuesday, March 22, 2022

BEC Still #1, but Investment Fraud passes Romance Scams


https://www.ic3.gov/Media/PDF/AnnualReport/2021_IC3Report.pdf


The FBI's Internet Crime Complaint Center (ic3.gov) has released their 2021 Internet Crime Report.

The number of complaints increased by 7% to 847,376 from 2020 to 2021, however the reported losses increased by 64% year over year to $6.9 Billion!


For several years, the #1 Cybercrime type has been Business Email Compromise followed by the #2 of Romance Scam. But this year, we had a change!  The criminals have discovered how many people don't understand investing in cryptocurrency and have turned Investment Scams into a new money factory. 

#1 is still Business Email Compromise, but with only a 3% increase in victims, there was a 28% increase in reported financial losses.  That's an average loss of $120,000 per victim, compared to last year's $96,700 per victim. 

#2 dislodges Romance Scams by Investment Scams for the first time ever with a dramatic increase!  Investment Scams went from 8,788 complaints to 20,561 complaints, while losses increased 333% from $33.6 Million dollars to $1.45 Billion dollars!  THat's an average loss of $70,810 per victim, up from $38,287 per victim last year!

#3 Romance Scams was quite similar to 2020 in the number of complaints, however the amount of losses still increased by 59%.  In 2020, the average victim lost $25,272, but in 2021, the average victim lost $39,344.  And these victims tend to be senior citizens! 

Crime Type 2021 Losses2020 LossesChange in Loss2021 Victims2020 VictimsChange in Victims
BEC/EAC $2,395,953,296$1,866,642,10728%19954193693%
Investment $1,455,943,193$336,469,000333%205618788134%
Confidence Fraud/Romance $956,039,739$600,249,82159%24299237512%
Personal Data Breach $517,021,289$194,473,055165%518294533014%
Real Estate/Rental $350,328,166$213,196,08264%1157813638-15%
Tech Support $347,657,432$146,477,709137%239031542155%
Non-Payment/Non-Delivery $337,493,071$265,011,24927%82478108869-24%
Identity Theft $278,267,918$219,484,69927%516294333019%
Credit Card Fraud $172,998,385$129,820,79233%1675017614-5%
Corporate Data Breach $151,568,225$128,916,64818%12872794-54%
Government Impersonation $142,643,253$109,938,03030%1133512827-12%
Advanced Fee $98,694,137$83,215,40519%1103413020-15%
Civil Matter $85,049,939$24,915,958241%111896815%
Spoofing $82,169,806$216,513,728-62%1852228218-34%
Other $75,837,524$101,523,082-25%123461037219%
Lottery/Sweepstakes/Inheritance $71,289,089$61,111,31917%59918501-30%
Extortion $60,577,741$70,935,939-15%3936076741-49%
Ransomware $49,207,908$29,157,40569%3729247451%
Employment $47,231,023$62,314,015-24%1525316879-10%
Phishing/Vishing/Smishing/Pharming $44,213,707$54,241,075-18%32397224134234%
Overpayment $33,407,671$51,039,922-35%610810988-44%
IPR/Copyright and Counterfeit $16,365,011$5,910,617177%427042131%
Health Care Related $7,042,942$2,904,2515-76%5781383-58%
Malware/Scareware/Virus $5,596,889$6,904,054-19%8101423-43%
Terrorism/Threats of Violence $4,390,720$654,7449-33%1234620669-40%
Gambling $1,940,237$3,961,508-51%3953911%
Re-Shipping $631,466$3,095,265-80%516883-42%
Denial of Service/TDoS $217,981$512,127-57%11042018-45%
Crimes Against Children $198,950$660,044-70%21673202-32%

Investment Scam Examples

What does an Investment Scam look like?  The most common ones these days are promising a guaranteed rate of investment. Thousands of such Investment Scam sites have been created and most of them are being pushed on social media.  People who claim to be successful on the sites are often only trying to earn a commission by referring others to the site.

It only took a couple hours to find more than 500 live Investment Scam sites last month.  Many of these sites are still live today.


Many of the sites are unlikely to attract real investors because of how ridiculous their rates are.  No one believes that they can earn 50% per hour ... however this site promises that if you can trick your associates into investing, you'll get 5% of whatever they deposit.  This is quite common. 

Crypto-Trades[.]uk 

A more believable site promises a much lower rate, such as 3% per day for investments up to $4,999 dollars.  If the site owners believe they have a big fish, they may actually PAY the 3% for a small investment, using that as proof that the system works in order to lure a larger investment.  This site, and many like it, then offer 6% daily profits for investments of at least $5,000, or 9% daily profits for investments of at least $30,000. 


The site pictured above claims to be "Crypto-Trades[.]uk" and offers proof of their legitimacy by providing a link to their "Certificate of Registration."

Crypto-Trades dot UK
claiming to be the British Corporation, "Crypto Ltd" which is a real company, just not them. 


They are regularly abused in that way.  CryptSparkFX[.]com, Crypto-binary[.]com, CryptoTrust[.]ltd, CryptoAlphas[.]uk, CryptoHive[.]uk, Webull-Investments[.]com, ExploreFX[.]uk, Crypto-Gain[.]ltd, Slushpool-investment[.]com, Intrex-invest[.]com, and FedelityFunds-Crypto[.]com are some of the other Investment Scam sites that use their address, hoping to gain credibility from it. 

Intrex-Invest[.]com

FedelityFunds-Crypto[.]com

Slushpool-investment[.]com

CryptoHive[.]uk

A True Victim Story

A successful businessman in my area came to me to ask for help.  He had originally joined a group such as those above called CryptoHood[.]io which later became CryptoHood[.]co.  He invested a small five figure number on their site, and got scammed, losing it all.  When he was complaining about being scammed, someone in a Facebook investment group let him know they too had been scammed by those people.  But good news!  He had found a legitimate company that really paid out!  EasonFXPro[.]com! Because he had been burned already, he put in a smaller investment this time.  $2,500.  An amount that this CEO "could afford to lose."

The scammers let him know that because he was a VIP investor, they were going to let him use their "special" app, so that he could watch his trades in real time.  The theory was that their advanced Artificial Intelligence was doing Bitcoin trading to make amazing profits.  The app they used was in the Google Play store ... but the VIP version was only available via their special URL.  They convinced him to download the app from "blockchain.en.uptodown[.]com/android/download/2264221." That was his "personalized" version.  He was truly amazed by the bot, and could enter "his" bitcoin address into any blockchain explorer to see his earnings.  (We checked the address, and it was doing HUGE volumes of small transactions ... it just wasn't his wallet.   He was led to believe that the transactions were "the AI doing trades" for him.  Within a couple months, his bitcoin address had funds worth nearly $250,000!  So he decided to cash out.

In order to cash out, he just had to pay them a "Sigma Fee" of 10%.  He refused ($25,000!?!?!?!) 
They then offered to let him withdraw just $50,000, for a Sigma Fee of only $5,000.
He was harassed on the phone for a while by "Elizabeth Frances" and "Evelyn" and "Mark Gerrard" and "Steven Williams" but chose to file an IC3.gov report about his experiences and walk away from Crypto Investments for a while.

The Appeal of Easy Money

With 1100 "likes" it must be real, right?

And they provide screenshots as proof that they are really getting paid!  So, it's guaranteed, right?



Monday, March 21, 2022

Chinese Call Center "Runner" Pleads Guilty in Georgia

This week the Department of Justice received a guilty plea from Jianjie Liu, a Chinese citizen living in Texas. 

https://www.justice.gov/usao-ndga/pr/chinese-national-pleads-guilty-money-laundering-scheme

In Call Center Frauds, there are many roles to be played.  One of these roles is often referred to as "Runner." When people in other countries are the ones running the phones and Facebook accounts used in fraud, they often need someone in the United States to pick up packages and open bank accounts.  From that perspective, Liu was a Runner.

The case began when Liu was arrested at a Walmart in Duluth, Georgia after attempting to purchase "a suspicious number of gift cards."  During that arrest, her 2016 black Nissan Altima was searched, and was found to have 718 gift cards, mostly WalMart, Vanilla Mastercard, and American Express gift cards. he also had a deposit slip showing that she controlled a JP Morgan Chase Bank account ending in #5887. The bank account was tied to her business license in Gwinnett County, Georgia fro "A&J Commercial Services" which used an address at 16634 Roseglade Drive, Cypress, TX 77429. 

The 16,000 images on her phone were reviewed, and found to contain many images of gift cards along with their accompanying purchase receipts. 

From May 30, 2019 until September 30, 2019, Liu deposited at least $70,400 into her Chase account from elderly fraud victims.  Those funds were all seized by the U.S. Secret Service, however there were many other victims and victim types described in the court records:


In a "Government Grant Scam" an elderly "J.B." received a message from a Facebook friend, who told him about a $150,000 government grant he could receive.  He sent $2,500 cash to an address in Heath, Ohio; 4,000 to an address in Atlanta, Georgia; $4,500 to an address in Newark, New Jersey, and was later instructed to purchase gift cards at a Walmart in Washington and message them to "Agent Walter" (which were then forwarded to Liu, who used those cards to purchase OTHER gift cards!)

In an "Inheritance Scam" a woman using a Facebook account in the name "Fola V. Williams Fly" asked a 64-year old man from Cheyenne, Wyoming to help her receive a multi-million dollar inheritance by paying various fees.  He sent two cashier's checks for $10,000 each payable to Jianjie Liu at the address 3182 Steve Reynolds Blvd, #105, Duluth, GA 30096. 

In a "Computer Support Scam" someone claiming to be "Allen Johnson" from Microsoft took control of a victim's computer, claiming he needed remote access to her bank account to process a $300 refund.  Instead he pretended to deposit $3,000, claiming it was in error.  He then asked the victim to refund $2,600 of the erroneous funds, by sending three money orders to Liu in Duluth, Georgia. 

An identical process was used by someone claiming to refund $555, but "accidentally" depositing $20,555 instead.  The victim, an 89-year old priest in St. Paul, Minnesota, sent the "accidental" $20,000 via cashier's check to Joy Liu, A&J Commercial Services, 3182 Steve Reynolds Blvd, Duluth, GA.

In a "Grandparent Scam" "Sergeant Jonathan Parker" called one of the elderly victims claiming their teenaged grandson had been arrested for assaulting a police officer and was required to post $9,000 bail.  He sent a box with $9,000 cash in it to an address in Las Vegas, Nevada.  Days later, Sergeant Parker demanded an additional $15,000 to settle the matter out of court.  He again sent a box of cash to Las Vegas.  Then he was asked to send $5,000 to pay the medical bills of "Officer Joyce Phillips" and this time sent a personal check to "Joyce Phillips" of A&J Commercial Services, 3182 Steve Reynolds Boulevard, Duluth, GA 30096. 

In a "Compromised SSN Scam" another elderly victim was told he was being investigated by the IRS, and that during the investigation, to protect his funds, he needed to convert all of his cash to Gift Cards, which would be held in escrow pending the results of the investigation.  These gift cards were used by Liu to purchase the gift cards in the Walmart in Duluth, Georgia. 

Liu posted $10,000 bail, and shockingly, failed to appear in court again.  

She was re-arrested in Pearland, Texas on 06JAN2021 for theft, where it was discovered that she had an outstanding warrant.

Saturday, December 04, 2021

Online Shopping Reminder: If It Looks Too Good To Be True ...

As we look towards the Christmas holiday, 'tis the season for freaking out and making poor decisions with regards to online shopping. Tonight a friend reached out to get my help in convincing his family that an incredible laptop sale they saw on laptop was not real.
That's the ad they saw on Facebook.  "Due to special reasons" the company has decided to "sell the last batch of laptops." If you click the Shop Now button, it takes you to the website "maxwellplaceonhudson[.]com"



Now, I'm not saying that everyone who re-uses an image is a scammer, but John J. Rogers and MaxwellPlaceHudson are using a photo from a 2019 Mainichi News article in Japan about the fact that computers were piling up in warehouses in China.  Doesn't that look familiar?  

https://mainichi.jp/english/articles/20191223/p2g/00m/0bu/050000c

John J. Rogers is being an extremely helpful and interactive salesperson as people are asking him how long it takes to ship the laptops.  He's giving recommendations on which model to order, and estimates on shipping time.




But How Do We Know It's Real?  ... Testimonials!

Just look at all the happy customers! "Sdhuy Fhabn" says "This is a quality built and spec'd laptop! Very satisfied!"
Strange that all of the comments on Sdhuy's page are in Filipino.  Even stranger? Someone named Tonie Pomintel thanked the computer seller "Memasabe" for a laptop using exactly the same words!

Mandy also loves his new laptop.  "Mine has arrived, this is an unexpected laptop, it even has a touch screen, I like it very much!" he gushes.

Mandy lives in Quezon City, Philippines, which does make it seem odd that he would be mail-ordering a laptop from New Jersey.  Even stranger?  "Ams Minang" shared exactly the same image to thank "Memasabe" for her new laptop!



MD tells us "So far so good, works great, looks great!" 
But then, for MD, people who look like John J. Rogers are kind of "his type."
I'm sure that Mandy and Sdhuy are fine people.  But let me tell you friends, MD, he's a Scammer!
MD Sajjad is a fake account that is giving a fake testimonial.

Take a look at his Facebook "Likes" -- 

He likes John J. Rogers, Noah Robert, Oliver Noah, Sean M Hemming, Debra Carter, Gerry R Frederickson, George S Krebs, and RiodiJanero ... who surprisingly all have the same two profile pictures!

Romance Scam and Online Fraud expert "FireFly" at www.scamsurvivors.com let us know that one of these men is the model "Michael Justin."  The profile picture is swiped from a 16MAY2019 post by Instagram user @themichaeljustin: 
https://www.instagram.com/p/Bxizn4iFWXy/ (@themichaeljustin)

The other primary profile picture is from a photo sales site and is entitled "businessman with laptop thinking at night office." 
https://photodune.net/item/businessman-with-laptop-thinking-at-night-office/20174205



Let's look at what else they have in common!


Noah Robert is a "Computer Company" ... oh gee! On November 25th "due to special reasons" he starting selling computers from his website "ajakubowski[.]com"

You may be surprised to know that ajakubowski's website is IDENTICAL to  MaxwellPlaceHudson's website!

His telephone number is in Afghanistan. (+93 is international dialing code for Afghanistan.)

Email ioiw7nkrvs@claimab.com

https://www.facebook.com/Noah-Robert-103879551585935/

Oliver Noah is a Computer Company. You'll never guess! Due to Special Reasons, he's selling the last batch of his laptops! 

His website, "utoal[.]com" strangely looks EXACTLY like John's website!

Sort of odd that he has an Afghanistan telephone number (+93)

Email n7x1z325fk@thrubay.com

https://www.facebook.com/Oliver-Noah-100751858389405/

Sean M Hemming is a Computer Company . Guess what! Due to Special Reasons, he's selling the last batch of his laptops! 

He has an Afghanistan telephone number and his website is MarbleTownGreen[.]com. (But it's closed down now.)

https://www.facebook.com/Sean-M-Hemming-769171696455694/

Facebook tells us the Page Manager location is Bangladesh


Debra G. Carter is a Computer Company. Guess what! Due to Special Reasons, he's selling the last batch of his laptops. He has a +93 Afghani telephone number and his website is "teamlse[.]com"

https://www.facebook.com/Debra-G-Carter-746064202423878/

Facebook tells us the Page Managers are in Indonesia, Liberia, Saint Vincent, and the Grenadines.


You might already be able to guess on this next one.

Gerry R Fredericksen is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops. 

He has a +93 Afghani telephone number and 

His website is "legeb[.]com" is currently disabled.

https://www.facebook.com/Gerry-R-Fredericksen-104079251980543/


George S Krebs is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops. 

His email is "esi01uo8d15@claimab.com" 

His website is "highlyacceleratedstresstest[.]com" is offline.

https://www.facebook.com/wo.kya.hoti/


RiodiJanero is a Computer Company. 

Due to Special Reasons, he's selling the last batch of his laptops.

His email is xdwdseiwb6@linshiyouxiang.net

His website is PineappleHillDesigns[.]com is offline.

He has a +93 Afghani telephone number.




So, getting back to the original question:  

Actually, I'm thinking that you may not really be able to buy a $2,600 laptop for $79 and have it delivered anywhere in the world in time for Christmas.  But then, my friends all tell me that I'm paranoid.

And there's so many more ... 

 
another Fake testimonial account: https://www.facebook.com/ams.minang.5/likes 

https://www.facebook.com/antonia.pomintel.5/likes_all

  • Helen Z Picket
    • https://www.facebook.com/Helen-Z-Pickett-111752013985708/
    • http://andaluciapropertyservices.com/
    • (216) 755-9391
  • Jackie K Freund
    • https://www.facebook.com/Jackie-K-Freund-448774108917513/
    • http://affordablegreensystems.com/
  • Andrew H Doyle
    • https://www.facebook.com/Andrew-H-Doyle-105266824762892/
    • http://affordablegreensystems.com/
    • +93212-307-8110
  • Memasabe
    • https://www.facebook.com/Memasabe-103806308164677/
    • http://snvpL.com/
    • +93803-520-1898
  • Fernando
    • https://www.facebook.com/Fernando-1894457434202054/
    • http://caughtfromabove.com/
    • 6trmfvuo2sh@thrubay.com
    • +93704-927-4239
  • Anne P Dudley
    • https://www.facebook.com/Anne-P-Dudley-141541912968147/
    • http://fricade.com/
    • y38msxh8zps@claimab.com
  • Dean B Vigil
    • https://www.facebook.com/Dean-B-Vigil-116775383783140/
    • http://fmpcms.com/ (live) 
    • +93816-539-3967
    • shhk60jhpng@claimab.com
  • A Addawd
    • https://www.facebook.com/A-addawd-100571795787651/
    • http://schoolbackpackstore.com/ (live) 
  • Criative
    • https://www.facebook.com/criativcalcad/
    • http://fourteenkaratomaha.com/
    • 5c992xqncjc@thrubay.com
  • My House 
    • https://www.facebook.com/My-House-100743925704289/
    • https://konamitech.com/ nbsp;(live) 
    • +213717-630-6321
    • gv2q360p9q@claimab.com
  • Helen T Lewis
    • https://www.facebook.com/Hector-T-Lewis-106551108311154
    • http://stevestoyboxny.com/
    • +93304-763-9483
    • ftxwy0rlela@linshiyouxiang.net
  • Leonia D Hill
    • https://www.facebook.com/Leonia-D-Hill-107212691802456/
    • https://chealyjean.com/
    • +93361-299-6243
    • ioiw7rnkrvs@claimab.com
  • Kermit
    • https://www.facebook.com/Kermit-119766538090600/
    • http://certificadoscolombia.com/
And the network is even bigger, because they also have female fake store owners selling Mobile Phones: 


Thursday, November 18, 2021

To the Black Axe: #GardaWillGetYou

 You may recall from July that I am very impressed with the Garda National Economic Crime Bureau (GNECB) in Ireland.  (See: "Operation Skein: The Irish Garda Target BEC Criminals")  While the biggest Black Axe arrest in recent days was the amazing work of the US Secret Service and their partners in South Africa (See: "Eight Nigerians Charged with Conspiring to Engage in Internet Scams and Money Laundering") the Garda are also taking things to a new level of working every lead and following every string and most importantly, sharing important facts with the public that allows us to be more wary!

In this last Garda action, two criminals were charged with Pandemic Unemployment Payment fraud, which in Ireland is called PUP.  In the US, we also have West African gangs heavily involved in unemployment fraud, as was demonstrated in Washington State in the case that Agari called "Scattered Canary." 

In Ireland, Oluwagbewikeke Lewis and Bashiru Aderibigbe stole €183,000 but were working on a scheme to steal €1,000,000 and communicating via WhatsApp on how to launder that amount of stolen funds.  Detective Superintendent Michael Cryan believes their activities were consistent with the behavior of The Black Axe. The pair were in communication with someone who they referred to as "the Chairman" where they discussed laundering funds, partly via bank accounts located in Germany.  The story is expertly conveyed by Liam Heylin of the Irish Examiner, which I summarize below:

This case would not have even begun were it not for the alert behavior of Detective Garda Kieran Crowley.  After stopping a suspicious Mercedes, Crowley discovered false passports, fraudulent bank documents, and extra SIM cards for mobile phones. The messages recovered from the phone linked to an active investigation into PUP fraud being conducted by another Detective Garda in Wexford.  A key behavior was unlocked during the investigation.  The individuals who were having their identities stolen to conduct the Unemployment fraud had all been victims of a phishing email! 

The Phishing Email: Jury Duty

Many of the victims reported that they had received a suspicious email informing them that they were being summoned for Jury Duty.  The email led the victims to a website where they were required (believing themselves to be on a government ordered website) to enter their personal details.  Those personal details were then used by the scammers to file for Pandemic Unemployment Payments, which were then harvested by the criminals after the payments went to bank accounts controlled by the pair.

Bashiru Aderibigbe was found on camera on 22 occasions making withdrawals from 13 bank accounts.

Knowing that the prosecutors had 70 witnesses lined up to testify against them, and giving the overwhelming weight of the digital evidence, the pair pled guilty to the charges. Oluwagbewikeke, aged 36, was sentenced to four years in prison. Bashiru Aderibigbe, 45, was sentenced to 3.5 years.  (Both will have the final year suspended, a common practice in Ireland if one behaves well in prison.)

Lewis has lived in Ireland since 2002 and claims he had worked as a taxi driver prior to Covid and became involved in this scam out of desperation.  


Saturday, September 18, 2021

AT&T Free Msg: You know you shouldn't click ... so we did it for you!

 If you live in the United States and have an AT&T phone, you are almost certainly receiving SMS messages that look something like this:

AT&T Free Msg: August bill is paid. Thanks, MARY! Here's a little gift for you: n9cxr[.]info/dhmxmcmBTQ (from +1 (718) 710-0863) 

or 

AT&T Free Msg: August bill processed. Thanks, Mary! Here's a little something for you: l4bsn[.]info/C2Lx3oggFi (from +1 (332) 220-7291) 

or 

AT&T Free Msg: Latest bill is paid. Thanks, Fedencia!  Here's a little freebie for you: k5amw[.]info/VloTBdytEl  (from +1 (870) 663-5472) 

AT&T has sort of trained us that it's cool to get messages from them with links in them.  Every time your bill is available, or paid, or has a new charge, you get a text message from them that starts with "AT&T Free Msg:" and ends with a link such as "att.com/myattapp" or "att.com/myViewBill."

This is where some independent amateur researchers make a mistake.  If you visit the URL in the first message from your Windows computer, you are automagically forwarded to Google.


That's what's happening in the background. My web browser (in red) tells the server, hey look! I want this page dhmxmcmBTQ and btw, here's my user agent.  n9cxr[.]info replies,
"Never heard of it - why don't you go to Google instead." by sending a "302 redirect."

If you had clicked on that same message from your phone, you would NOT be sent to Google.  That's because the web server is checking to see if you are asking for the information from a phone or from a computer.  Because they know they only sent their spam via "SMS-blasting" they believe that every legitimate potential victim should be coming from a phone.  Since I don't have a great set of rich monitoring tools on my phone, I'll just tell my Virtual Machine's Chrome instance that it should lie when it visits web servers and pretend to be an iPhone. I'm being a bit lazy here and using another Chrome Plug-in, this one called "User Agent Changer," which gives me a menu like this: 

Once I change my Chrome Virtual Machine to pretend to be "Safari on iPhone" we revisit the URL that was sent to my phone: 


Notice on line 5 that where it previously said I was "Windows NT 10" it nows says I am "(iPhone; CPU iPhone OS 9_2 like Mac OS X)." (Which is super out-of-date, but apparently good enough for this criminal's scheme, because now I get this!


We've written several times in the past about these never-ending surveys.  Their objective is to gather as much personal data from you as they can and to show you as many advertisements as they can.  They then experience revenue by both showing you ads during the survey, but also by selling the personal information that they gather you to organizations that need "qualified sales leads."  They will tell those organizations that you are looking for things like savings on college tuition, health insurance, car insurance, electronics, a new vehicle, etc, and you will start getting more spam messages from those organizations who will have believed that you asked for their spam! 

We asked our friends at Zetalytics, via their Zone Cruncher tool, "So where in the world is the IP address n9cxr[.]info?"  They told us that it is located in Hong Kong on a server that is hosted by Alibaba Inc.  


That's very interesting!  Thanks, Zetalytics!  Could you also tell us OTHER DOMAIN NAMES that have recently been seen on that same IP address?  After all, we've received three such domains in the three messages that I received on my personal phone!

All of those domains are of course registered at the scummy domain registrar NameCheap.  They claim that if we inform them of bad domains, they will de-register them.  Once I post this, I'll send them a copy and report back what happens.


By the way, the content is not exactly the same with each visit.  My next visit to the n9cxr URL gave me this pop-up instead:


So how are we getting to the fake AT&T page?  That's where a tool that CAUCE Director Neil Schwartman showed me comes in.  While I don't recommend the company necessarily, this little Chrome plug-in is gold for mapping out redirect paths!  (Search for the Chrome Extension "Ayima Redirect Path" and please remember you should only be reviewing potentially hostile URLs in a Virtual Machine!)



What does all that mean? It tells us that the first URL's webserver claimed that the page we were looking for "dhmxmcmBTQ" had been temporarily redirected to "themechallenge[.]club" and that we should ask that server for a particular "key."
That key caused the server to send us a Javascript that redirected us to another URL on their website, which in turn did a "META Redirect" to the webserver "go.metreysi[.]info" where we should tell them we were sent by a certain "cnv_id."  That server then pretended that we had clicked on it, and sent us via another "302 temporary redirect" to a webserver called "redirect.usersupport[.]net." UserSupport then did yet another redirect which took us to the webside "att.usersupport[.]net."

More domains to look up in ZoneCruncher!

https://themechallenge[.]club/click.php?key=abrrkduwznt79g18cx66

go.metreysi[.]info => hosted on LeaseWeb at 23.108.57[.]187
redirect.usersupport[.]net => hosted on 2606:4700:3032::6815:2b25
att.usersupport[.]net => hosted on 2606:4700:3031::ac43:da02


I'm guessing that all of these other "go" sites that are sharing the same IP address will also be involved in illegal "redirection" scams that start off with SMS Blasting.


By the way, do you remember the "key" we had to pass?  In a similar way to our User-Agent, if you visit one of these sites and fail to pass it a "key" it will just redirect you to 127.0.0.1, which means, "visit your own machine." 

Not just AT&T!

One of Zetalytics other tricks is being able to show me other hostnames on the same domain.  (The term for this is called "PassiveDNS")

It looks like "UserSupport[.]net" is also being used to imitate TikTok, CostCo, Walmart, and Google, shipping company UPS, FedEx, and US Postal Service, and Cell phone providers, AT&T, Comcast, Spectrum, T-Mobile, and Verizon!


Because I haven't received those particular SMS messages, I can't navigate to them.  (I have the wrong "key" to get the chain started.) But I'd love to see some more of these if you would be willing to share a screenshot! 

List of SMS-spam-abusing .info (and .xyz) domains believed to be associated with these campaigns.  It sort of makes sense that there are exactly 100 of them.

1find[.]info
1fwnx[.]info
1nvc[.]info
2edcc[.]info
2gtex[.]info
2ofgm[.]info
3mgie[.]info
3ohmd[.]info
4gogm[.]info
4onnr[.]info
4onnr[.]info
6ghme[.]info
6nbfu[.]info
6omrf[.]info
6wqbv[.]info
7botm[.]info
7gboe[.]info
7gboe[.]info
7uwhn[.]info
7wxcd[.]info
8bmxw[.]info
9bmdx[.]info
a2sct[.]info
a7tev[.]info
appsc[.]info
appsf[.]info
bjdz2[.]xyz
bmeq9[.]info
bookc[.]info
bookx[.]info
cartm[.]info
cartm[.]info
cartz[.]info
faceg[.]info
faceg[.]info
faceh[.]info
facem[.]info
faceu[.]info
facey[.]info
fuwd2[.]info
gg0l[.]info
gi3t[.]info
gi3t[.]info
gitn4[.]info
goen4[.]info
gotr6[.]info
gr8f[.]info
havec[.]info
havec[.]info
havec[.]info
havec[.]info
havec[.]info
havec[.]info
havej[.]info
havew[.]info
hidej[.]info
hidej[.]info
hidem[.]info
hidep[.]info
hidep[.]info
j1bcs[.]info
j1bcs[.]info
j2bmf[.]info
k2ave[.]info
k4acr[.]info
k4acr[.]info
k8bvz[.]info
kpl5[.]info
kpp8[.]info
kpp8[.]info
kse0[.]info
ktf4[.]info
l1bmz[.]info
l5brv[.]info
lgte3[.]info
m2cxn[.]info
m6cda[.]info
mbdz2[.]xyz
mqbvn[.]info
n4csv[.]info
n9cxr[.]info
nameb[.]info
pexw0[.]xyz
qkkk2[.]xyz
raini[.]info
rainl[.]info
rainz[.]info
s1vrk[.]info
s2avr[.]info
s2avr[.]info
s4asc[.]info
s6axe[.]info
s7axm[.]info
s8avx[.]info
toer9[.]info
toer9[.]info
vbjh9[.]xyz
wodm7[.]info
wordc[.]info
wosn9[.]info