Blog for hpHosts, and whatever else I feel like writing about ....

Wednesday, 18 November 2009

If ya want my money, 'an' ya think I'm gullible, c'mon Saphie scam me now!

Okay, so I completely ruined what used to be a great Rod Stewart song - but it's been worth it. I was alerted by my friend Dee Hughes over at Freeware Home, of a rogue domain one of her visitors came across during a Google search for Outlook Express that led via the Sponsored results (surprise surprise) to expressdownloadz.com (see left).

She asked if I could dig up anything on this domain as she'd not found any contact information or anything that would help her take it down. Naturally I offered to help (I do love exposing these scheming wan**rs). Off I trotted to expressdownloadz.com, and low and behold, instantly identified the type of scam, and thus, how to track it.

expressdownloadz.com is identical to thousands of other itty bitty phishy sites out there, and it's stats are as follows;

IP: 72.10.171.202
IP PTR: Resolution failed
ASN: 36666 72.10.168.0/22 GTCOMM - GloboTech Communications
Created: October 19th 2009

It's WhoIs record is hidden, but I doubt it's actually accurate either way (impossible to tell obviously, as Domains By Proxy aren't exactly going to hand over the information without a court order).

There are a plethora of other malicious domains within this /24, and given how long some of them have been there, I'm guessing GloboTech couldn't give a hoot aslong as they keep paying their bills;

0-antivirus.org
11-download.com
2009-download.org
6-download.com
9-digital-media.net
9-downioad.com
9-download.org
9-reloaded.com
antivirusbox-online.net
antivirusguardian.com
anti-virus-guardian.com
antivirus-pro.info
anti-virus-tech.com
antivirus-zone.net
avg-antivirus.biz
bytes-d0wnload.com
cast-download.com
castdownload.org
d0wnloadz.org
digital-media-pro.net
divx-top.net
dj-download.org
download-openoffice.org
dvdshrinkonline.com
earth-d0wnload.com
express6-download.com
expressd0wnload.com
express-d0wnload.com
express-d0wnloadz.com
express-download.org
expressdownloadz.com
free-antivirus-software.org
free-download-place.org
free-zonealarm.com
gtdominicana.com
guide-assurance.com
java-download.info
java-free.org
liens-emule.com
mail.gtdominicana.com
mail-download.info
mail-downloads.com
mail-program.com
mail-software.info
messenger2009.org
messenger-9.org
messenger9-d0wnload.com
movie-maker-pro.com
openofficedownload.org
openofficefree.org
open-office-software.org
place4friends.com
quick-downloads.org
registrycleaners-top-pick.com
secure-antivirus.net
software500.com
virtualdj-download.com
vista-ready.com
www.0-antivirus.org
www.11-download.com
www.2009-download.org
www.6-download.com
www.9-digital-media.net
www.9-downioad.com
www.9-download.org
www.9-reloaded.com
www.antivirusbox-online.net
www.antivirus-d0wnload.com
www.antivirusguardian.com
www.anti-virus-guardian.com
www.antivirus-pro.info
www.anti-virus-tech.com
www.antivirus-zone.net
www.avg-antivirus.biz
www.bytes-d0wnload.com
www.cast-download.com
www.castdownload.org
www.d0wnloadz.org
www.digital-media-pro.net
www.divx-top.net
www.dj-download.org
www.download-openoffice.org
www.dvdshrinkonline.com
www.earth-d0wnload.com
www.express6-download.com
www.expressd0wnload.com
www.express-d0wnload.com
www.express-d0wnloadz.com
www.express-download.org
www.expressdownloadz.com
www.free-antivirus-software.org
www.free-download-place.org
www.free-zonealarm.com
www.gtdominicana.com
www.guide-assurance.com
www.java-download.info
www.java-free.org
www.liens-emule.com
www.mail-download.info
www.mail-downloads.com
www.mail-program.com
www.mail-software.info
www.messenger2009.org
www.messenger-9.org
www.messenger9-d0wnload.com
www.movie-maker-pro.com
www.openofficedownload.org
www.openofficefree.org
www.open-office-software.org
www.place4friends.com
www.quick-downloads.org
www.registrycleaners-top-pick.com
www.secure-antivirus.net
www.software500.com
www.virtualdj-download.com
www.vista-ready.com


If you're unlucky enough to believe what expressdownloadz.com are "offering", then you're taken from there, to;

freedownloadzone.com/join.php?s=Outlook Express&kw=outlook express&t=outlook-express_w2&si=index.php&ml=12&d=Expressdownloadz.Com&dn=Expressdownloadz.Com&TargetSite=FDZ&lp=default

freedownloadzone.com is the site that asks you to create an "account", and asks for your payment information, entering this of course is a majorly bad idea, but lets carry on regardless.




Notice where you are yet? That's right folks .... you're now at;

https://secure.cardtransaction.com/icc-rs/order2.asp?ref=Expressdownloadz.Com&d=Expressdownloadz.Com&id=&t=outlook-express_w2

secure.cardtransaction.com has a DCV certificate from RapidSSL. Both this domain, and freedownloadzone.com are located on the same IP block, 70.33.253.0/24, which is owned by Peer1. Not surprisingly, this also houses a plethora of other similar domains, including;

2009-anti-virus-download.com
2009-antivirus-download.com
2009-edition.org
2009-version.info
5-anti-virus.info
5-antivirus-download.com
8-anti-virus-download.com
antivirus-1.info
anti-virus-1.org
antivirus-center.org
anti-virus-removal.info
anti-virus-solution.org
burning-programs.com
dealsmint.com
download-all-free.com
downloaditfree.net
flash-player-10.org
free-antivirus2009.com
free-anti-virus-software.com
full-edition.info
get-flash-player-10.com
get-muzic.com
itunes-8.com
itunes-muzic.com
mp3sharinghq.net
musicmembersarea.com
muzic-share.com
open-office-2009.com
open-office-download.org
open-office-pro.com
open-office-software.com
org-eng.info
pdf-platinum.info
personal-antivirus.org
popupremoval.com
share-free.info
vlc-software.com
wire2009.com
www.2009-anti-virus-download.com
www.2009-antivirus-download.com
www.2009-edition.org
www.2009-version.info
www.5-anti-virus.info
www.5-antivirus-download.com
www.8-anti-virus-download.com
www.antivirus-1.info
www.anti-virus-1.org
www.antivirus-center.org
www.anti-virus-removal.info
www.anti-virus-solution.org
www.burning-programs.com
www.dealsmint.com
www.download-all-free.com
www.downloaditfree.net
www.flash-player-10.org
www.free-antivirus2009.com
www.free-anti-virus-software.com
www.full-edition.info
www.get-flash-player-10.com
www.get-muzic.com
www.itunes-8.com
www.itunes-muzic.com
www.mp3sharinghq.net
www.musicmembersarea.com
www.muzic-share.com
www.open-office-2009.com
www.open-office-download.org
www.open-office-pro.com
www.open-office-software.com
www.org-eng.info
www.pdf-platinum.info
www.personal-antivirus.org
www.share-free.info
www.vlc-software.com
www.wire2009.com


Getting on. The addresses you'll notice at the bottom of these sites, is;

Saphie Number1
Third Floor, Conway House
7-9 Conway Street
St Helier
Jersey, JE2 3NT

What you'll not know, is that this address is NOT the actual address for Saphie Number1. It's a "drop box" of sorts. It works by having someone in Jersey, allow companies to have mail sent to their address (saving their having to pay UK tax from what I've been told). These people are then paid by the companies, a percentage, to forward the mail to the company, once it arrives.

However, there's another address involved. The "company" that appears on your bill when you've handed over your payment information, is helpmedownload.com. Popping over there, the address they provide as their "Correspondence address" is;

Saphie Number One Limited
26 York Street
London W1U 6PZ, UK

This is the same address as is provided in the cardtransaction.com WhoIs records, but nope - it's not their real address either. This address belongs to, how did he put it, a "call answering service", run by a company called "Sage Systems" (26 York Street is Sage Systems HQ). Interestingly, I couldn't find anything on Sage Systems at that address, but did find a Virtual Office company called W1Office at that address.

Virtual Office
Communications House
26 York Street
London
W1U 6PZ
Sales: 020 7788 7788
Service: 020 7788 7878

Head Office
43-45 Portman Square
London
W1H 6HN
Sales: 0845 000 7788
Service: 0845 000 7878

W1 Office
Company Name: W1 Office Limited
Company Number: 05303127
Vat Number: 853 55 00 32
Data Protection: Z895601X
Royal Mail: PB003216
City of Westminster: 044

Registered Address
26 York Street
London
W1U 6PZ


I called them up to ask about Sage Systems and was told;

"it may be one of our clients"

I told W1Office what was going on, and they're apparently going to look into it. They also provided me with the number of the person that created the account with them but unfortunately, it turned out to be a fax number, not a telephone number (0207 068 5500).

Helpmedownload.com have their own "main" website too (Saphie Number1 = Helpmedownload.com), which provides the following contact information;

USA

Billing & Tech Support:

1-866-730-0934
1-888-527-9381

UK

Billing & Tech Support:

0808 238 0026
0808 238 0045

Canada

Billing & Tech Support:

1-866-730-0934

Australia

Billing & Tech Support:

1-800-469-290
1-800-146-928
1-800-357-380

All other

Billing & Tech Support:

1-866-978-4842


I've now been on the phone with one of their reps for around 30 mins or so, and they're still trying to tell me the process is simple, easy to understand, clear as far as what they're charging for, and they're thus, not scamming people. Couldn't explain however, why for example, the "3 step process", tries to charge for support and such TWICE.

Alas, she's not been through the process herself apparently as she "doesn't need help downloading software", so as I pointed out - she can't tell me about something she's not been through herself - which is why I'm on hold now. She's now going through the process herself apparently (personally I think she's gone for a smoke/drink/toilet break, but it's an 0808 number, so their bill, so I don't care).

.... sorry folks, was on the phone.

Okie, so here's where we are. The person I spoke to on the phone passed me to her supervisor who advised me;

1. He is not authorized to tell me WHO is in charge in his company
2. He CAN NOT pass me to a manager so we can get this cleared up
3. His manager monitors the support@helpmedownload.com inbox, but REFUSED to tell me HOW I am supposed to know it is a manager responding via e-mail, given he couldn't provide me with so much as his managers name
4. His name is "Murphy" (he has no surname apparently), and the location of the place he is currently at (woops, he let that slip!), is in the Philippines (he would not tell me if that was the main helpmedownload.com address, if not, what address it was, or indeed, provide ANY address related to the company!!!!!)
5. Their e-mail address is support@helpmedownload.com and that is the ONLY way in which we can get answers (yes, of course it is Murphy!!!).

... and that's just the parts of the phone call I can remember (sorry folks, was getting very frustrated). In the end, he simply said he would not answer any more of my questions as he was not authorized to speak to me (err, that part is confusing).

After being on the phone with them for over an hour, I ended up getting far too frustrated to continue, given they refused to answer any of my questions, and refused to put me on to anyone that could answer any of my questions, and refused to tell me so much as the name of the person within the company (i.e. a manager, director etc), that was authorized to speak to me on the subject of such.

I urge you to call one of the numbers above (they're toll free/freephone, so won't cost you anything, but you'll get to have so much fun (sic)). Try getting a straight answer from them, try getting to speak to someone in charge of this scam err, company.

If you've been scammed by any of the domains listed above, first things first, contact your credit card company and ask them for a charge back!!!. Next, inform the UK Watchdog (if UK based), or your countries equivalent.

I'd also urge you to contact W1Office with your complaints. Hopefully, the more people that do, the sooner W1Office will boot the company.

It should be noted, the above are by no means the only domains involved in this scam, or other scams similar to this one. There are thousands of them out there, so be careful folks! (and if you find one that's not listed in hpHosts already, feel free to drop me a note!).

In the meantime, if I've forgotten to mention anything (been one of those err, couple hours or so, hehe), do let me know.

4 comments:

Rune said...

http://en.wikipedia.org/wiki/Daniel_S._Pe%C3%B1a_Sr.
Possibly related.

MysteryFCM said...

It certainly is related, thank you :o)

OldTabby said...

Thanks for your hard work/fun Steven. The one thing your report highlights is how difficult it is to track down these scam artists & what an impossible task it is for a webmaster to try to block their ads!!

We all bitch that the agencies should be more responsible about the ads they accept but when the real advertiser is hidden under layers & layers of disinformation you start to see how impossible that is too!

Yes I know it's great to find a website without ads BUT behind any good website is at least one person putting in an average 4+ hours a day 365 days a year. Trust me, we hate ads worse than you do but we have to eat ;-)

HelpMeDownload said...

Hello,

I am a customer service representative of HelpMeDownload.Com. I sincerely apologize for the inconvenience. Regarding the charges that you got, we will be more than happy to resolve the issue either via web chat below, or email, or calling our toll free number.

Thank you for your time,
HELPMEDOWNLOAD.COM
US Phone Support 1-800-978-7657
UK Phone Support 0808 238 0026
AU Phone Support 1-800-469-290

Web-chat is now available! You can visit the website: helpmedownload.com for online chat support.
Our Operations is available 24/7.