Blog for hpHosts, and whatever else I feel like writing about ....

Wednesday 2 June 2010

UPDATE: Malware, scams and Redstation

Just an update folks. Whilst the sites are still live, the downloads appear to have gone *for now* (pretty confident they'll be back). I did hear back from Redstation, who asked for evidence, and such was passed to them.

If you've paid for ANY of the software they're scamming and infecting for, contact your credit/debit card company and ask for a charge back.

In the case of these particular domains, the company responsible for the scams (and likely for the malware aswell, given the source is the same domains), is;

Company: Soletto Group, S.A.
aka: Nextcard Ltd, Netlink Network Corp
ICO Reg. Number: Z2140425
Support: support.uk@soletto.net
Phone Support: 02071939823

Contrary to their UK phone number, they're not UK based, they're actually in Panama;

Soletto Group S.A.
ADR Tower, 8th floor,
Samuel Lewis Avenue, and 58th Street,
Obarrio Urbanization,
Panama City
PA
Phone: +507.6022067111 (voice) +507.111111

Check your bills for any reference to this name, or indeed, any other name you do not recognize, and report it both to your local police force, and to the credit/debit card company.

I'm continuing to monitor them, both for new domains, and incase they popup elsewhere (we already know they're using OVH aswell), and I'll update you when further information comes to light.

References:

WARNING: Malware, scams and RedStation (AS35662, 81.94.192.0/20)
http://hphosts.blogspot.com/2010/05/warning-malware-scams-and-redstation.html

Legitimate Software Typosquatted in SMS Micro-Payment Scam
http://ddanchev.blogspot.com/2009/07/legitimate-software-typosquatted-in-sms.html

No comments: