Advert.

Do NOT tell your scammer he is posted here, or report their accounts as it puts others at risk!

Fake sites used in Russian romance scams

Report any emails with fake links attempting to steal your ID, and any fake sites used by scammers.

pravdaclinic.com

Unread postby firefly » Wed Nov 29, 2017 5:09 pm

split from viewtopic.php?f=11&t=57866; the fake site claims to be Pravda Clinic; the fake character used in scam claimsto be working there.

From the fake site details:

IP: 194.58.112.174

Domain name: PRAVDACLINIC.COM
Updated Date: 2017-09-14
Creation Date: 2017-09-14
Registrar Registration Expiration Date: 2018-09-14
Registrar: Registrar of domain names REG.RU LLC
Registry Registrant ID:
Registrant Name: Vladimir Polkhov
Registrant Organization: Private Person
Registrant Street: Menzhinskogo 28-165
Registrant City: NY
Registrant State/Province: NY
Registrant Postal Code: 10033
Registrant Country: US
Registrant Phone: +79524420363
Registrant Email: polh@list.ru

The registrant details are entirely fake: there is no Menzhinskogo Street in New York, USA. And also USA doesn't use Russian mobile numbers...

The same registrant was reported before on our forum in viewtopic.php?f=11&t=44745 with the email address irina@ruralclinics.net (the domain name is no more active).

Other active domain names belonging to the same registrant and used in romances scams reported online:

- astrclinic.com - used online with elena@astrclinic.com
- letclinics.com - used online with liza@letclinics.com, tanya@letclinics.com
- ugclinic.com - used online with Yulia@ugclinic.com.
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

ya-com.in

Unread postby firefly » Wed Nov 29, 2017 6:37 pm

Split from viewtopic.php?f=11&t=63374

From the fake site details:

Domain Name:YA-COM.IN
Created On:28-Nov-2017
Last Updated On:28-Nov-2017
Expiration Date:28-Nov-2018
Sponsoring Registrar:Endurance Domains Technology LLP (R173-AFIN)
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Status:ADDPERIOD
Registrant ID:EDT_73158459
Registrant Name:Vasya Vasilev
Registrant Organization:N/A
Registrant Street1:Karlovo nam. 288/17
Registrant City:Praha
Registrant State/Province:Praha
Registrant Postal Code:12000
Registrant Country:CZ
Registrant Phone:+420.603303905
Registrant Email:vasyaya3479@gmail.com
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

post-ru.com

Unread postby firefly » Sat Dec 02, 2017 4:31 am

Split from viewtopic.php?f=11&t=63374

IP used: 37.48.115.99

From the fake site details:

Domain Name: POST-RU.COM
Updated Date: 2017-10-10
Creation Date: 2017-10-10
Registrar Registration Expiration Date: 2018-10-10
Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com

Registrant Name: Cassandra Moore
Registrant Organization:
Registrant Street: 249 Sully Dowdings Road, Pine Creek
Registrant City: Bundaberg
Registrant State/Province: Other
Registrant Postal Code: 4670
Registrant Country: AU
Registrant Phone: +61.488561467
Registrant Email: fezergarxxx@yandex.ru
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

myggmail.com

Unread postby firefly » Sun Dec 17, 2017 6:07 pm

split from viewtopic.php?f=11&t=63856

The domain name impersonates Gmail.

From the fake site details - https://db.aa419.org/fakebanksview.php?key=128772:

Domain Name: MYGGMAIL.COM
Updated Date: 2017-11-24
Creation Date: 2017-11-24
Registrar Registration Expiration Date: 2018-11-24
Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com

Registry Registrant ID: Not Available From Registry
Registrant Name: Potap
Registrant Street: Myasnickaya
Registrant City: Moscow
Registrant State/Province: Moscow
Registrant Postal Code: 101000
Registrant Country: RU
Registrant Phone: +7.9371180433
Registrant Email: im_secure@list.ru

The same registrant owned also another gmail spoof, Bookgmail.biz, reported online in romance scams.
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

wergmail.com

Unread postby firefly » Sat Mar 31, 2018 4:31 am

viewtopic.php?f=11&t=36477&start=70

The domain name is used only for the email address.

From the fake site details:

Domain name: wergmail.com
Updated Date: 2018-01-17
Creation Date: 2018-01-17
Registrar Registration Expiration Date: 2019-01-17
Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED

Registry Registrant ID: Not Available From Registry
Registrant Name: Marco Naumann
Registrant Organization: NA
Registrant Street: Lange Strasse 89
Registrant City: Puchheim
Registrant State/Province: Bavaria
Registrant Postal Code: 82167
Registrant Country: de
Registrant Phone: +49.089452246
Registrant Fax: +49.089452246
Registrant Email: admin@bussinessassistance.com

Since the begin of this year, the same registrant details are used to create 52 domains...
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

kalgmail.com

Unread postby firefly » Fri Apr 27, 2018 6:44 pm

Split from viewtopic.php?f=11&t=36477&start=70

From the fake site details:

Domain name: kalgmail.com
Updated Date: 2018-01-17
Creation Date: 2018-01-17
Registrar Registration Expiration Date: 2019-01-17
Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED

Domain Status: clientHold
Registry Registrant ID: Not Available From Registry
Registrant Name: Marco Naumann
Registrant Organization: NA
Registrant Street: Lange Strasse 89
Registrant City: Puchheim
Registrant State/Province: Bavaria
Registrant Postal Code: 82167
Registrant Country: de
Registrant Phone: +49.089452246
Registrant Fax: +49.089452246
Registrant Email: admin@bussinessassistance.com

Between January - March 2018, the same person registered 61 domain names, blacklisted for spreading malware.

Banking Trojans and Pandas? Recently, the FortiGuard Labs Web Filtering team has come across a Fake DHL Notification in a Hancitor malspam that led to the Zeus Panda banking Trojan. It provides a link downloading a malicious word document that will infect the victim's computer. FortiGuard Labs has blocked several domains that were identified in this campaign. Reverse WHOIS from one of the C2 domains onkesandre[.]com reveals the Threat Actor admin[@]bussinessassistance.com, who owns a total of 67 domains.

FortiGuard Labs has blacklisted all the domains associated with this threat actor.
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

yandiex.com

Unread postby firefly » Fri Jun 22, 2018 8:43 pm

split from viewtopic.php?f=11&t=68359, where the romance scam using the fake site only for the email address is reported.

The fake site impersonates Yandex.

For the fake site details: https://db.aa419.org/fakebanksview.php?key=131831.

From the fake site details:

Domain Name: YANDIEX.COM
Updated Date: 2018-05-15
Creation Date: 2018-03-15
Registrar Registration Expiration Date: 2019-03-15
Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com

Registry Registrant ID: Not Available From Registry
Registrant Name: Zasada
Registrant Organization: awer
Registrant Street: Siissd 12 33
Registrant City: Priamurskey
Registrant State/Province: Yevrejskaya avtonomnaya oblast
Registrant Postal Code: 679180
Registrant Country: RU
Registrant Phone: +7.9696274035
Registrant Email: defenderder@yandex.ru
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

cupidprofiles.pro

Unread postby firefly » Sat Nov 17, 2018 4:36 am

cupidprofiles.pro is a fake site recently created (2018-10-11) used only for the email address. There is no content on the fake site - the domain name redirects to other domains and there is no possibility for anyone to create an account on that site. The domain name is used for spamming romance scam messages.

The serving IP address:

Originating IP: 176.119.3.7
Originating ISP: Fop Gubina Lubov Petrivna
City: Lugansk
Country of Origin: Ukraine

Email:

Hey there, I am Sofiya.As a rule my email address is littered with junk letters, but I want to use it to find new friends. May by some of them can become the love of my life. I am a nice girl have a robust health, keen on skiing. I prefer to spend free time with my friends or take yoga classes. Tell me some about yourself. May I ask where do you live now and how old are you? Write me at goldkis19@gmail.com. Regards!


Header:

ARC-Authentication-Results: i=1; mx.google.com;
spf=neutral (google.com: 192.99.216.145 is neither permitted nor denied by best guess record for domain of venuscristinah@cupidprofiles.pro) smtp.mailfrom=venuscristinah@cupidprofiles.pro
Return-Path: <venuscristinah@cupidprofiles.pro>
Received: from pk1.esnoei.net (mail.hostpm.com. [192.99.216.145])
Received-SPF: neutral (google.com: 192.99.216.145 is neither permitted nor denied by best guess record for domain of venuscristinah@cupidprofiles.pro) client-ip=192.99.216.145;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 192.99.216.145 is neither permitted nor denied by best guess record for domain of venuscristinah@cupidprofiles.pro) smtp.mailfrom=venuscristinah@cupidprofiles.pro
Return-path: <venuscristinah@cupidprofiles.pro>
Received: from venuscristinah by keeperzi.pk1.esnoei.net with local (Exim 4.23) id INktB1-7zFNwR-dw for xxx;
To:
Subject: I wish to find my the only one
Message-Id: <INktB1-7zFNwR-dw@keeperzi.pk1.esnoei.net>
From: Bryanna <venuscristinah@cupidprofiles.pro>

Originating IP: 192.99.216.145
Originating ISP: Ovh Sas
City: Montréal
Country of Origin: Canada
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

skv-net.ru

Unread postby firefly » Sat Dec 01, 2018 11:16 pm

split from viewtopic.php?f=11&t=57723&start=40 where the domain name is used only for the email address irina.lushezarnaya@skv-net.ru

domain: SKV-NET.RU
nserver: ns1.fozzy.com.
nserver: ns2.fozzy.com.
state: REGISTERED, DELEGATED, UNVERIFIED
person: Private Person
registrar: DOMENUS-RU

created: 2018-11-14T11:12:41Z
paid-till: 2019-11-14T11:12:41Z
free-date: 2019-12-15
source: TCI

The only thing found on the site is:

Welcome to Fozzy Hosting!
This is the default page for all new accounts.
Replace it with your site files.


Meaning no user can register an email account there as long as there is no site giving the option of registering that account.
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

skv-mail.com

Unread postby firefly » Sun Dec 02, 2018 7:27 pm

split from viewtopic.php?f=11&t=72438

The only content on the site is:

This is default page for all new hosting accounts.
Please change it with your website content.


Meaning no user can register an email account there as long as there is no site giving the option of registering that account.

Fake site details:

Domain Name: SKV-MAIL.COM
Updated Date: 2018-10-10
Creation Date: 2018-10-10
Registrar Registration Expiration Date: 2019-10-10
Registrar: URL SOLUTIONS INC.

Registry Registrant ID:
Registrant Name: ALEKSANDR KRYLOV
Registrant Organization: KRYLOV COMPANY
Registrant Street: STROITELEY, 124, TsENTR
Registrant City: IJEVSK
Registrant State/Province: UDMURTIYa
Registrant Postal Code: 167002
Registrant Country: RU
Registrant Phone: +7.9278791173
Registrant Email: krylov.alexcrylov@yandex.ru
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
viewtopic.php?f=11&t=26504
Image
User avatar
firefly
"Nut job" admin.
 
Posts: 70956
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

PreviousNext

Return to Fake sites/Phishing sites.

Who is online

Users browsing this forum: No registered users and 19 guests