Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Below please find notes detailing a counterfeit ring peddling fake Michael Kors products via SPAM e-mail. These scammers use a standard template and use services from Global Frag Networks and Yesup Ecommerce Solutions Inc. to facilitate their criminal enterprise.
- The subjects used in their e-mails normally look something like this:
- - Michael Kors on Sale - Up to 80% off Online.
- - Discount Michael Kors Handbags Online, Up To 85% OFF!
- - Up to 85% Off Michael Kors Bags & Wallet Sale Season Off Clearance. Free Shipping
- 20191103
- SPAM Domain: isuniao.com
- SPAM IP: 107.179.67.226
- SPAM IP Tracking: https://www.abuseipdb.com/check/107.179.67.226
- SPAM ISP: Bill Van / Global Frag Networks
- Counterfeit website: https://mks.qxmks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.28.25.44
- Counterfeit Hosting Provider: Hides Behind Cloudflare
- 20191022
- SPAM Domain: cpw353.com
- SPAM IP: 104.223.202.202
- SPAM IP Tracking: https://www.abuseipdb.com/check/104.223.202.202
- SPAM ISP: Bill Van / Global Frag Networks
- Counterfeit website: https://mks.zimks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.27.141.58
- Counterfeit Hosting Provider: Hides Behind Cloudflare
- 20190909
- SPAM Domain: 23.228.90.107
- SPAM IP: 43.227.113.71
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.228.90.107
- SPAM ISP: Bill Van / Global Frag Networks
- Counterfeit website: https://mks.vbmks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.31.70.131
- Counterfeit Hosting Provider: Hides Behind Cloudflare
- 20190907
- SPAM Domain: maiaiche.com
- SPAM IP: 43.227.113.71
- SPAM IP Tracking: https://www.abuseipdb.com/check/43.227.113.71
- SPAM ISP: Flat B 6/F. Kam Fai Building
- Counterfeit website: https://mks.vgmks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.28.9.157
- Counterfeit Hosting Provider: Hides Behind Cloudflare
- 20190817
- SPAM Domain: heimaico.com
- SPAM IP: 23.228.90.106
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.228.90.106
- SPAM ISP: Spiderly / Global Frag Networks
- Counterfeit website: https://mks.wvmks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.148.87.114
- Counterfeit Hosting Provider: Bill Van / Global Frag Networks
- 20190729
- SPAM Domain: 1wwe.com
- SPAM IP: 23.228.82.2
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.228.82.2
- SPAM ISP: Spiderly / Global Frag Networks
- Counterfeit website: https://mks.vemks.com/
- Conterfeit domain registrar: NameSilo, LLC
- Counterfeit website IP: 104.31.82.205
- Counterfeit Hosting Provider: Hides Behind Cloudflare
- 20190714
- SPAM Domain: a0058.com
- SPAM IP: 134.73.166.194
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.247.114.20
- SPAM ISP: Spiderly / Global Frag Networks
- Counterfeit website: https://mks.a0058.com/
- Counterfeit website IP: 198.144.157.212
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20190628
- SPAM Domain: cpw272.com
- SPAM IP: 23.247.114.20
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.247.114.20
- SPAM ISP: Spiderly / Global Frag Networks
- Counterfeit website: https://mks.cpw272.com/
- Counterfeit website IP: 198.144.157.217
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20190612
- SPAM Domain: hcieqp.com
- SPAM IP: 134.73.30.162
- SPAM IP Tracking: https://www.abuseipdb.com/check/134.73.30.162
- SPAM ISP: Global Frag Networks
- Counterfeit website: https://mks.hcieqp.com/
- Counterfeit website IP: 198.144.157.213
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20190512
- SPAM Domain: 103563.com
- SPAM IP: 23.247.114.18
- SPAM IP Tracking: https://www.abuseipdb.com/check/23.247.114.18
- SPAM ISP: Spiderly Ltd / Global Frag Networks
- Counterfeit website: https://mks.103563.com/
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20190322
- SPAM Domain: hdx222.com
- SPAM IP: 134.73.166.224
- SPAM ISP: EliDC / Colo Crossing
- Counterfeit website: https://mks.hdx222.com/
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20181123
- SPAM Domain: hmpay.cc
- SPAM IP: 198.58.119.19
- SPAM ISP: Linode LLC
- Counterfeit website: http://znfl.hmpay.cc/mtad/tl.php?p=UNIQUE_TEXT_STRING_HERE
- Counterfeit Hosting Provider: AliCloud
- 20181122
- SPAM Domain: zmlyg.com
- SPAM IP: 104.148.126.250
- SPAM ISP: Global Frag Networks
- Counterfeit website: https://jup.zmlyg.com/
- Counterfeit Hosting Provider: Yesup Ecommerce Solutions Inc.
- 20180729
- SPAM Domain: 91053.net
- SPAM IP: 212.83.178.134
- Counterfeit website: http://91053.net/oem/tl.php?p=UNIQUE_TEXT_STRING_HERE
- 20180518
- SPAM Domain: mkcosier.top
- SPAM IP: 114.67.72.160
- Counterfeit website: http://iereiex.top/mkipop
- 20180503
- SPAM Domain: aidcu.top
- SPAM IP: 116.196.64.105
- Counterfeit website: http://www.aidhu.top/l.php?UNIQUE_TEXT_STRING_HERE
- 20180503
- SPAM Domain: amazons7.top
- SPAM IP: 125.94.44.60
- Counterfeit website: http://www.4v33t.top
- 20180420
- SPAM Domain: pckww.com
- SPAM IP: 1166.48.179.71
- Counterfeit website: http://mk.pckww.com
- 20180406
- SPAM Domain: pcrww.com
- SPAM IP: 166.48.179.195
- Counterfeit website: http://mk.pcrww.com
- 20180324
- SPAM Domain: pbrww.com
- SPAM IP: 62.210.61.195
- Counterfeit website: http://mk.pbrww.com
- 20180324
- SPAM Domain: pbpww.com
- SPAM IP: 103.215.213.65
- Counterfeit website: http://mk.pbpww.com
Add Comment
Please, Sign In to add comment