<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Credit card criminals Devbill have a new home !!! in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r15294105</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 17:15:15 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 17:15:15 EDT</lastBuildDate>

<item>
<title>Re: Credit card criminals Devbill have a new home !!!</title>
<link>http://www.dslreports.com/forum/remark,15298267</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : I re searched using different variations on the above "new" names and have now found old reports of fraudulent charges under 3 of them, the others still appear fresh.<br><br><B>CYBERMAMBO.com :</B> I found a fraud report from back on 01/04/05 &raquo;<A HREF="http://64.233.187.104/search?q=cache:6LQah_JNBf8J:www.complaints.com/directory/2005/march/11/22.htm+CYBERMAMBO&hl=en" >64.233.187.104/search?q=cache:6L&middot;&middot;&middot;BO&hl=en</A><br><br><B>AZBUSPROD.com :</B> Multiple fraudulent charges show up as AZ BUSINESS PRODUCTS &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&c2coff=1&q=%22AZ+BUSiness+PRODucts%22+9.95" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;%22+9.95</A><br><br><B>JMBUSPROD.com :</B> Also multiple fraudulent charges under JM BUSINESS PRODUCTS &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&c2coff=1&q=JM+BUSiness+PRODucts+9.95" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;cts+9.95</A><br><br>Again all the cloned websites are set up for two primary reasons. <br><br>1) To enable the criminal to apply and get approved for an online merchant card processing account, using the website and domain name as a reference. They can then batch upload the the charges against the stolen card accounts.<br><br>2) To enable victims who discover and question the nominal charge a method of contacting the scammers. They will then issue a credit which reduces the "charge back ratio", saves them money, and slows the flagging process. Victims can either contact them via email or the cheap rent a voip mailbox. If they initiate contact the victims will be told that someone must have stolen and used their card data to buy products from them online. This steers suspicion away from the scammers.<br><br>So the website is just a front, or cover. There is really nothing for sale, and it is not even capable of completing an online purchase.<br><br>All the websites even have a meta tag in the main header field requesting that search engines not follow any of the links or index any of the pages !!.<br><br><B><I>>META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"></I></B><br><br>Victims should never provide details to the scammers to enable them to issue a credit, that helps them. Always have your bank charge it back, and always cancel the card immediately.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15298267</guid>
<pubDate>Sat, 21 Jan 2006 19:00:44 EDT</pubDate>
</item>

<item>
<title>Credit card criminals Devbill have a new home !!!</title>
<link>http://www.dslreports.com/forum/remark,15294105</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : In the "where are they now" category, I did a recheck on one of the largest and longest running credit card scammers on the net. Now into their third year of operation with no end in sight. Operating dozens of domain names with <A HREF="http://www.dslreports.com/forum/remark,14453535">identical webpage layouts</A>, then refreshing with new names as the old ones expire. Hitting thousands of credit cards for 9.95 or similar amounts. Some of the earliest scam domain names were <A HREF="http://web.archive.org/web/20040701163038/pansalcorp.com/index.php">PANSALCORP.com</A> and <A HREF="http://web.archive.org/web/20040925174342/http://usoftwebsys.com/">USOFTWEBSYS.com</A> They  even showed up in a post on the <A HREF="http://www.dslreports.com/forum/remark,10741367">DSLR security forum</A> back in July of 2004.<br><br>Their fraudulent charges were last reported in the <A HREF="http://www.dslreports.com/forum/remark,14286212">Trouble Bubble thread</A>. Many of the charges were reported in combination with the digital Age fraud charges. There are victim reports as recent as a month ago still under some of the old names. It appeared that after <A HREF="http://www.dslreports.com/forum/remark,14473570">two years of hosting</A> them, Everyones Internet, Inc. (EV1.NET) did finally <A HREF="http://www.dslreports.com/forum/remark,14479512">pull the plug</A>. Though they did leave one of the scammers DNS dewhosting.com alone, which is still there.<br><br>Now they have a new home on Sagonet complete with their own bloc of 10 IP's and have moved some of the "old" scamming sites there.: <A HREF="http://www.google.com/search?hl=en&lr=&c2coff=1&q=%22BURDETTINC.com%22&btnG=Search">BURDETTINC.com</A>, <A HREF="http://www.google.com/search?hl=en&lr=&c2coff=1&sa=G&q=%22ABSOLUTE-SOFT.com%22">ABSOLUTE-SOFT.com</A>, <A HREF="http://www.google.com/search?hl=en&lr=&c2coff=1&q=%22KCSOFTLLC.com%22&btnG=Search">KCSOFTLLC.com</A>, ARTMAGICINC.com, and AZBUSPROD.com (aka AZ BUSINESS PRODUCTS) <br><br>In addition, they now have new pages up for fresh domains, so I can guarantee you that victim reports of fraudulent charges will soon follow for these names, soon after Google picks them up: <B>WEB-TEMPLATES-FOR-YOU.com , ALTAVISTAWEBDESIGN.com , JMBUSPROD.com , EBONEY-WEBDESIGN.com , and  CYBERMAMBO.com</B><br><br>I scanned the IP's in the bloc and listed all the websites hosted. Some of the dns is not completed yet, and Artmagic.com is up and down:<br><br>scan range [66.118.179.120 - 66.118.179.129] <br><br>ABSOLUTE-SOFT.com  = IP &raquo;<A HREF="http://66.118.179.120" >66.118.179.120</A> (413) 812-5720 <br><br>KCSOFTLLC.com = IP &raquo;<A HREF="http://66.118.179.121" >66.118.179.121</A> (509)-461-1556<br><br>ARTMAGICINC.com = IP &raquo;<A HREF="http://66.118.179.122" >66.118.179.122</A><br><br>AZBUSPROD.com  = IP &raquo;<A HREF="http://66.118.179.123" >66.118.179.123</A>  (403) 770-0283 <br><br>CYBERMAMBO.com = IP &raquo;<A HREF="http://66.118.179.124" >66.118.179.124</A>  (270) 637-5080 <br><br>JMBUSPROD.com   = IP &raquo;<A HREF="http://66.118.179.125" >66.118.179.125</A>   (403) 668-1201 <br><br>EBONEY-WEBDESIGN.com = IP &raquo;<A HREF="http://66.118.179.126" >66.118.179.126</A>  (860) 656-7718  <br><br>ALTAVISTAWEBDESIGN.com = IP &raquo;<A HREF="http://66.118.179.127" >66.118.179.127</A> (757) 271-6046 <br><br>WEB-TEMPLATES-FOR-YOU.com = IP &raquo;<A HREF="http://66.118.179.128" >66.118.179.128</A>  (203) 608-0313 <br><br>BURDETTINC.com = IP &raquo;<A HREF="http://66.118.179.129" >66.118.179.129</A> (801) 407-1342 <br><br>All of the domains and even the IP registration are fake, and/or carded victims. Sagonet.com needs to kick these criminals off now !!.<br><br><I>CustName:   George Morris <B>-------> LOOK</B><br>Address:    200 Manhattan Ave<br>City:       New York<br><br>StateProv:  NY<br>PostalCode: 10025<br>Country:    US<br>RegDate:    2005-10-14  <B>-------> LOOK</B><br>Updated:    2005-10-14<br><br>NetRange:   66.118.179.120 - 66.118.179.129 <br>CIDR:       66.118.179.120/29, 66.118.179.128/31 <br>NetName:    SAGO-66-118-179-120<br>NetHandle:  NET-66-118-179-120-1<br>Parent:     NET-66-118-128-0-1<br>NetType:    Reassigned<br>Comment:    NOCWorx SWIP Interface v1.5 - &raquo;<A HREF="http://interworx.info" >interworx.info</A><br>RegDate:    2005-10-14<br>Updated:    2005-10-14<br><br>RAbuseHandle: ABUSE32-ARIN<br>RAbuseName:   Abuse Team <br>RAbusePhone:  +1-866-510-4000<br>RAbuseEmail:  abuse[AT]sagonet.com <br><br>RTechHandle: ZS203-ARIN<br>RTechName:   Sago Networks <br>RTechPhone:  +1-866-510-4000<br>RTechEmail:  ipadmin[AT]sagonet.com <br><br>OrgTechHandle: TECHN20-ARIN<br>OrgTechName:   Technical Support <br>OrgTechPhone:  +1-866-510-4000<br>OrgTechEmail:  support[AT]sagonet.com<br><br><B>ZS203-ARIN</B>:<br><br>Name:       Sago Networks <br>Handle:     ZS203-ARIN<br>Company:    <br>Address:    4465 W. Gandy Blvd. Suite 800<br>City:       Tampa<br>StateProv:  FL<br>PostalCode: 33611<br>Country:    US<br>Comment:     <br>RegDate:    2002-03-01<br>Updated:    2002-03-01<br>Phone:      +1-866-510-4000  (Office)<br>Email:      ipadmin[AT]sagonet.com</I><br><br>All the scammers new domains get DNS from:<br><br><I>Name Servers:<br>   dns1.name-services.com<br>   dns2.name-services.com<br>   dns3.name-services.com<br>   dns4.name-services.com<br>   dns5.name-services.com<br><br>Domain name: NAME-SERVICES.COM<br><br>Administrative Contact:<br>   eNom, Inc.<br>   DNS Manager (paul.stahura@enom.com)<br>   +1.4258838860<br>   Fax: +1.4258833553<br>   P.O. Box 7449<br>   2002 156th Avenue NE, Ste. 300<br>   Bellevue, WA 98007<br>   US</I><br><br>These scumbags have used card processors and addresses in the USA, Canada, and Europe. They have hit cards that were never used, cards that were just issued, and hit cards repeatedly if they were not cancelled.<br><br>MGD<br><br>INSOFTTECH EADENSSOFT JM BUSINESS PRODUCTS<br><br><SMALL>EDIT = added archived web page links for PANSALCORP.com and USOFTWEBSYS.com</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15294105?c=955640&ret=L2ZvcnVtL3IxNTI5NDEwNS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="343234 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/955640.thumb600~d1edf30840a2ec2f65abece9f87ed847/CYBERMAMBO.png/thumb.jpg" ALT="Click for full size"></A><br>CYBERMAMBO</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15294105?c=955641&ret=L2ZvcnVtL3IxNTI5NDEwNS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="344936 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/955641.thumb600~3f75cc209f9acc01812b5e46f8859b3e/Eboney_WebDesign.png/thumb.jpg" ALT="Click for full size"></A><br>EBONEY-WEBDESIGN</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15294105?c=955642&ret=L2ZvcnVtL3IxNTI5NDEwNS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="341256 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/955642.thumb600~82959c31866f629c46fff301bbc84f85/AltaVistaWebDeaign.png/thumb.jpg" ALT="Click for full size"></A><br>ALTAVISTAWEBDESIGN</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15294105?c=955643&ret=L2ZvcnVtL3IxNTI5NDEwNS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="340674 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/955643.thumb600~ee76a6b3207d1557df1b7e3b4838731b/Web_Templates_For-You.png/thumb.jpg" ALT="Click for full size"></A><br> U</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15294105</guid>
<pubDate>Sat, 21 Jan 2006 01:11:29 EDT</pubDate>
</item>

</channel>
</rss>
