<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r20055975</link>
<description></description>
<language>en</language>
<pubDate>Wed, 10 Feb 2010 08:41:56 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 08:41:56 EDT</lastBuildDate>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20771638</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by  mrchris <A HREF="/useremail/u/697274"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Why do these folks bother making these websites when you can find what you want for free if you looked hard enough on Google?<br> </div>They are not making these sites to sell anything.  If you had read any of  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s posts in detail you would see that the majority (if not all) of these fake web sites use a special ROBOTS.TXT file that hides them from search engines and web indexers on purpose as they really don't want people/customers going to their sites. They are fronts for a well organized and large criminal enterprise in the former Soviet Block than funnel up to $50,000 USD per month through <b>each</b> front web site making fraudulent charges to Credit Cards.<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20771638</guid>
<pubDate>Thu, 10 Jul 2008 18:36:46 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20769900</link>
<description><![CDATA[<A HREF="/useremail/u/697274"><b>mrchris</b></A> : Why do these folks bother making these websites when you can find what you want for free if you looked hard enough on Google?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20769900</guid>
<pubDate>Thu, 10 Jul 2008 13:01:54 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20756147</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Looks like Godaddy has suspended mobileglobus.com for invalid whois data. Maybe the real Bill Hutchinson of 3100 Monticello got tired of fielding calls, about the domain that he did not register.<br><br>GoDaddy Whois results:<br><br><div class="bquote">Domain Status:  On-hold<br><br>Error Message<br>Server response:<br>mobileglobus.com<br><br>This domain name has been suspended due to invalid Whois information.<br><br>If you are the registrant of this domain name please contact us at: invalidwhois[at]secureserver.net<br></div>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20756147</guid>
<pubDate>Mon, 07 Jul 2008 22:05:07 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20570248</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by Almost Defrauded :</small><br><br>...... I mentioned this to the guy from the bank and he seemed disinterested, told me the charge had been reversed and got me off the phone before I got to the juicy stuff on this thread or had a chance to insist they cancel the account and issue a new card.  .... </div>That is a common occurence because of the amount.<br><br><div class="bquote"><small>said by Almost Defrauded :</small><br><br>...... Should I expect them to continue to charge the account? .... </div>Yes, guaranteed to happen.<br><br><div class="bquote"><small>said by Almost Defrauded :</small><br><br>...... I'm guessing I should be getting the card canceled and a new card issued... </div>Yes, that is the only way to stop the process. They have your card data and will continue to use it.<br><br><div class="bquote"><small>said by Almost Defrauded :</small><br><br>...... I went back and saw no other fraudulent activity for the last year but I did notice an authorization about 9 months ago from FRONTIER EQUITI for $1.00 that never was charged.  Has anyone else seen that entity tied to this crime ring?  I'm guessing it was a check to make sure the card would work.<br><br>Thanks again for posting on this topic.<br> </div>I do not recall seeing that name, however, you are correct in that the cime syndicate routinely pings a portion of the hijacked card where the current status is unknown. Over the years they accomplish this validation by routinely hijacking legitimate merchant accounts of small businesses to ping them. They will run several thousand pings, usually over the weekend when the business is closed, sticking them with a hefty bill for the process.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20570248</guid>
<pubDate>Sat, 31 May 2008 18:50:22 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20569482</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I noticed a charge this morning on my account for $2.56 from IMAGESPARADISE.COM that did not look familiar so I called my bank (Bank of America) to dispute it.  When I finally got a live person I happened to be doing a google search on the site and came across this thread and others indicating the fruadulent nature of the company.  I mentioned this to the guy from the bank and he seemed disinterested, told me the charge had been reversed and got me off the phone before I got to the juicy stuff on this thread or had a chance to insist they cancel the account and issue a new card.  <br><br>So it looks like they are trying smaller dollar amounts now.<br><br>Should I expect them to continue to charge the account?  I'm guessing I should be getting the card canceled and a new card issued...I went back and saw no other fraudulent activity for the last year but I did notice an authorization about 9 months ago from FRONTIER EQUITI for $1.00 that never was charged.  Has anyone else seen that entity tied to this crime ring?  I'm guessing it was a check to make sure the card would work.<br><br>Thanks again for posting on this topic.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20569482</guid>
<pubDate>Sat, 31 May 2008 15:31:00 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20534459</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : OOOPS !!, to see those empty contents when you click on the above links you will be redirected to a "secure login" The account is: user ID = test password = test.<br><br>Then click on "access gallery"<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20534459</guid>
<pubDate>Sat, 24 May 2008 17:23:21 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20534437</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : If you recall in an earlier post, Mr. Allison told me that he knew of several people personally that dowloaded intangibles from the mobileglobus.com site and were "very happy" with the "products".<br><br>The problem is that there is nothing to download from the fraudulent site. The vetting standards are so low, or non existant, that there is no need to even complete the fake site.<br><br>A login gets you to here:<br><br>[att=1]<br><br>A generates a script error:<br><br><div class="bquote">Warning: Smarty error: math: parameter y is empty in /home/content/g/d/f/gdfg34453/html/libs/Smarty.class.php on line 1095</div>The field set for a credit card number is assigned as a "text" entry, and always generates an error:<br><br><textarea name="code" class="text" cols=50 rows=10>&lt;td width="175"&gt;Card Type&lt;/td&gt;&#012;    &lt;td&gt;&#012;  &lt;select name="card_type"  class="combo"&gt;&#012;    &lt;option value="visa"&gt;Visa&lt;/option&gt;&#012;    &lt;option value="mc"&gt;Master Card&lt;/option&gt;&#012;    &lt;option value="ae"&gt;American Express&lt;/option&gt;&#012;    &lt;option value="discover"&gt;Discover&lt;/option&gt;&#012;  &lt;/select&gt;&lt;/td&gt;&#012;&lt;/td&gt;&#012;  &lt;/tr&gt;&#012;  &lt;tr&gt;&#012;    &lt;td width="175"&gt;Card Number&lt;/td&gt;&#012;    &lt;td&gt;&lt;input name="card" type="text" id="card" size="32" /&gt;&lt;/td&gt;&#012;&lt;/td&gt;&#012;</textarea><!--end code block--><br>Note the "text":<br>Card Number<br>    input name="card" type="text" id="card"<br><br>[att=3]<br><br>Sign in and review the available downloads, and you are greeted by, Nothing:<br><br>[att=2]<br><br>Links for all the empty graphics such as: &raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/themes/nature/nat011.thm">www.mobileglobus.com/themes/natu&middot;&middot;&middot;t011.thm</A><br><br>yield:<br><br>[att=4]<br><br>You can bypass log in and see these for yourself:<br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=nature&page=2">www.mobileglobus.com/index.php?a&middot;&middot;&middot;e&page=2</A> Try any page number, any category, empty !!<br><br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=cartoon">www.mobileglobus.com/index.php?a&middot;&middot;&middot;=cartoon</A><br><br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=abstract">www.mobileglobus.com/index.php?a&middot;&middot;&middot;abstract</A><br><br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=animal">www.mobileglobus.com/index.php?a&middot;&middot;&middot;y=animal</A><br><br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=land">www.mobileglobus.com/index.php?a&middot;&middot;&middot;ery=land</A><br><br>&raquo;<small>https</small>://<A HREF="https://www.mobileglobus.com/index.php?action=gallery&gallery=cars">www.mobileglobus.com/index.php?a&middot;&middot;&middot;ery=cars</A><br><br>This is all nothing new, In December of 2007, one brave soul used a virtual card to enroll in one of the fraud globus group sites just to see what was there. Of course as expected he found nothing to download:<br><br> <blockquote><small>quote:</small><hr>JDDD <br><br> Re: Heard of Picture globus?? <br> <br>Okay, So i have one of those nifty options for my card to get a "temporary" card number for online purchases. I paid the $2.99 to see if the site was a scam. Sure enough it is. they claim to be a stock photo company. You pay a monthly fee and download as many images as you want. the charge is $9.99 a month so that is what they charged you for, 1 month of service. However (and this is the funny part) They are letting people register and sign up for subscriptions but they do not have a SINGLE image available. nothing, nada, zilch. So I would recommend staying away from this site and if you do decide to PLEASE DON'T GIVE THEM YOUR REAL CARD NUMBER AND INFO. <br><br> <br><br>hope this helps save some of you some headaches.<br><hr></blockquote><br><br>REF: &raquo;<A HREF="http://community.mpix.com/forums/t/58259.aspx?PageIndex=1" >community.mpix.com/forums/t/5825&middot;&middot;&middot;eIndex=1</A><br><br>There is a posting on Fatwallet from early December 2007 where Allison's apparent partner Eric Robertson, IM's a member who complained of the fraud charges and asked him:<br><br> <blockquote><small>quote:</small><hr>........I would also like to ask you to either remove the thread from the forum or delete our company's name from the topic name. We are just starting out and this thread is harming our business. I hope that you understand it is not our fault that someone used your card to register with us..........<hr></blockquote><br>&raquo;<A HREF="http://www.fatwallet.com/forums/finance/782097" >www.fatwallet.com/forums/finance/782097</A><br><br>It is hard to believe that almpst a half year later, one of these cyber-mules has not figured it out. Just searching under any of the mutiple names would produce pages of fraud data for them to see.<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534437?c=1310493&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="41223 bytes" WIDTH=600 HEIGHT=359 SRC="/r0/download/1310493.thumb600~32be20dc63f5169eb84d87f5680e81a6/MobileGlobus_account.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534437?c=1310494&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="128546 bytes" WIDTH=600 HEIGHT=704 SRC="/r0/download/1310494.thumb600~208cf8aac2d7645083426a8fbb6d29f2/Allison_mobileGlobus003.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534437?c=1310495&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="143854 bytes" WIDTH=600 HEIGHT=369 SRC="/r0/download/1310495.thumb600~d00ad5ff4edc87e31a8d638653bb1a1c/MobileGlobus_cardentry.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534437?c=1310496&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="20495 bytes" WIDTH=600 HEIGHT=219 SRC="/r0/download/1310496.thumb600~7df3a7a0eede094f5bfbdd19f4a0a5b8/MobileGlobus_pagenotfound.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20534437</guid>
<pubDate>Sat, 24 May 2008 17:17:22 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20534264</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  K Patterson <A HREF="/useremail/u/1338989"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Man, is he in for a surprise. ..... </div>I hope it happens sooner than later.<br><br><div class="bquote"><small>said by  K Patterson <A HREF="/useremail/u/1338989"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>....One alternative would be to let Bill Hutchinson know how he has been implicated in this fraud.  My guess is that he may have some ways of getting thru to  Mr. Allison.  It looks like it was his card that was used.<br><br>Kip<br> </div>After reviewing my notes, apparently I missed listing one of the earlier sites on that list.<br><br><b>PHOTOMERIDIAN.COM</b> &raquo;<A HREF="http://PHOTOMERIDIAN.COM" >PHOTOMERIDIAN.COM</A><br><br>Was operating in the last quarter of 2007.<br>&raquo;<A HREF="http://www.google.com/search?hl=en&q=PHOTOMERIDIAN.COM&btnG=Google+Search" >www.google.com/search?hl=en&q=PH&middot;&middot;&middot;e+Search</A><br><br><pre><br>Registrant:<br>   Domains by Proxy, Inc.<br>   DomainsByProxy.com<br>   15111 N. Hayden Rd., Ste 160, PMB 353<br>   Scottsdale, Arizona 85260<br>   United States<br> <br>   Domain Name: PHOTOMERIDIAN.COM<br>      Created on: 26-Aug-07<br>      Expires on: 26-Aug-08<br>      Last Updated on: 26-Aug-07<br></pre><br><br>on 11/06/2007 a poster reported the link<br><br>  <blockquote><small>quote:</small><hr>Follow the link and get this message: <br><br>"This site is currently unavailable. <br><br>If you are the owner of this site, please contact us at 1-480-505-8855 at your earliest convenience." <br><br>Something's up for sure. <br><hr></blockquote><br>&raquo;<A HREF="http://www.dpchallenge.com/forum.php?action=read&FORUM_THREAD_ID=691308" >www.dpchallenge.com/forum.php?ac&middot;&middot;&middot;D=691308</A><br><br>Godaddy's failure to either promptly address these criminal's using their services for free, or keeping them from re-enrolling with fraudulent payments is totally irresponsible.<br><br>Worse yet, Mr. Allison's <b>MOBILEGLOBUS.COM</b> site is back up and running &raquo;<A HREF="http://mobileglobus.com" >mobileglobus.com</A> courtesy of GoDaddy free hosting.<br><br>[att=1][att=2]<br><br>Support: Eric Robertson <br>e-mail: support@mobileglobus.com <br>tel: (210) 807-4272 <br><br>&raquo;<A HREF="http://www.google.com/search?hl=en&q=210-807-4272+" >www.google.com/search?hl=en&q=210-807-4272+</A><br><br>Still not back is Mr. Allison's personal sites for <b>Mike Allison Communications, LLC</b> and <b><br>Mike Allison Consulting</b>. Those are presumably the LLCs that the authorize.net merchant accounts are under. <br><br>[att=3]<br><br>Nor do we know the other two sites that Allison has running. Though I see <b>photogeyser.com</b> &raquo;<A HREF="http://photogeyser.com" >photogeyser.com</A> is still active.<br><br>Still no return calls from Allison, so his current activity status is unknown. However with the site going back up, it is presumed that he is still firmly planted in the crime syndicates corner. He may be considered a "dream catch" recruit by any organized crime syndicate. <br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534264?c=1310477&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="358363 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/1310477.thumb600~f34545c5727de5f8554355aed23aa8bf/MobileGlobus_main.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534264?c=1310478&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="158458 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/1310478.thumb600~6c7a090294323d8a4a0483a078e5702f/mobileglobus_contact.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20534264?c=1310479&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="28944 bytes" BORDER=0 WIDTH=436 HEIGHT=1542 SRC="/r0/download/1310479~0ec279fdca0f18c060029fdd61d7bddc/Allison_mobileGlobus1.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20534264</guid>
<pubDate>Sat, 24 May 2008 16:25:01 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20525572</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks, here is the PDF attachment<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/r0/download/1309916~82895a58380ea5a687110ac12a5c62c1/WhoIs%20mobileglobus.pdf">WhoIs mobile&middot;&middot;&middot;obus.pdf</A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20525572</guid>
<pubDate>Thu, 22 May 2008 19:38:03 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20518363</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by gant :</small><br><br> I have a PDF file that I printed off the GoDaddy WhoIs listing yesterday, to confirm what they were showing yesterday.  Unfortunately I cannot see how to attach it to this post.<br> </div>Type your post, hit Preview, and on the left is a new button that reads "+ upload attachments". Now click that and a new section expands with 4 spots for adding files. Browse to the file you want to attach and then click Upload attachment.<br><br>[att=1][att=2]<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20518363?c=1309435&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="39627 bytes" BORDER=0 WIDTH=489 HEIGHT=248 SRC="/r0/download/1309435~a017e0caf9119cc47e6729799c0161ba/001.jpg"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20518363?c=1309436&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="28060 bytes" BORDER=0 WIDTH=518 HEIGHT=201 SRC="/r0/download/1309436~11f5315d0fdebb3df4e4554339df02f2/002.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20518363</guid>
<pubDate>Wed, 21 May 2008 15:37:59 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20517936</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <div class="bquote"><small>said by  K Patterson <A HREF="/useremail/u/1338989"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>That just doesn't make sense.  Bill Hutchinson is a heavy hitter - Romney's campaign committee, for instance.<br><br>did ddigital get the site name wrong?  There is only a placeholder at mobileglobus.com.<br>...<br> </div>This I did not know.  In case of doubt, I have a PDF file that I printed off the GoDaddy WhoIs listing yesterday, to confirm what they were showing yesterday.  Unfortunately I cannot see how to attach it to this post.<br><br>A good friend in Florida was scammed this month from "mobileglobus.com" therefore I googled this name and followed the links - and then I found this (your) web forum with lots of useful information,  Also sustained hard work by MGD - well done.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20517936</guid>
<pubDate>Wed, 21 May 2008 14:17:18 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20515048</link>
<description><![CDATA[<A HREF="/useremail/u/1338989"><b>K Patterson</b></A> : Man, is he in for a surprise.<br><br>One alternative would be to let Bill Hutchinson know how he has been implicated in this fraud.  My guess is that he may have some ways of getting thru to  Mr. Allison.  It looks like it was his card that was used.<br><br>Kip]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20515048</guid>
<pubDate>Tue, 20 May 2008 22:34:09 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20514086</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : GoDaddy has apparently taken down mobileglobus.com. In the 05/17 post above by "<b>ddigital</b>" the domain was privacy cloaked by GoDaddy's Domains by Proxy, Inc service. When GoDaddy pulls a site and/or revokes the domain, they remove the cloaking service. The registration posted above by "<b>gant</b>" is how the criminals registered the domain back on 01/28. Probably paid for with hijacked card data, and registered in the victim's name. They they used the same card to pay for the domain cloaking service to make it harder to track and shut down.<br><br>I spoke with Mike Allison several days ago, thanks to info provided by  mae_aa419 <A HREF="/useremail/u/1548874"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> Mike was running merchant accounts for three websites including mobileglobus.com. He also ran merchant accounts for several of the previous "globus" sites that are now shut down. Mike is completely duped and insisted that he is running a legit operation. When asked about the fraudulent charges on all the previous sites listed for him that are now defunct, he stated that someone hacked into them and stole their products using dozens of stolen credit cards.!! Mike stated that he was expanding his operation by hiring staff, because the business was doing so well and expanding.<br><br>Mr. Allison was adamant that he was running a legitimate business operation in partnership with Hermeselectro.com. He refused to name the other two websites that are currently in operation. Also, he refused to state where he wires the proceeds, other than to confirm it is a foreign country. He did acknowledge that they all use authorize.net as a payment gateway. Mike also stated that he was aware of several people that had purchased tangible products from the sites, and were very happy with them. I told him that this was not possible.<br><br>I sent Mike several links to show him the robust documentation of the fraud, and the crime syndicate behind it. I also gave him contact information for a Texas police officer that he should call, who would corroborate what I told him. Mike was going to digest this information and then get back with me, he has not. He also has not returned any of my subsequent calls.<br><br>At the time I contacted Mike, both mobileglobus.com and Mike's personal site: mikeallisoncommunications.reliabilitymall.com were active. Without followup contact it is impossible to know if he informed the criminals and they convinced him to go into hide mode. if so, they may have him wire funds abroad daily, to keep the account balance low.<br><br>Go here: &raquo;<A HREF="http://www.data.bbb.org/houston/search.html" >www.data.bbb.org/houston/search.html</A> and enter "Mike Allison" in the search box.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20514086</guid>
<pubDate>Tue, 20 May 2008 19:22:42 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20513517</link>
<description><![CDATA[<A HREF="/useremail/u/1338989"><b>K Patterson</b></A> : That just doesn't make sense.  Bill Hutchinson is a heavy hitter - Romney's campaign committee, for instance.<br><br>did ddigital get the site name wrong?  There is only a placeholder at mobileglobus.com.<br><br>Edit:  Looking at cached pages in Google, it appears that it once was a fraud site.<br><br>The whois was updated today.  I wonder if somebody put Hutchinson's name in there as a red herring??<br><br>Kip]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513517</guid>
<pubDate>Tue, 20 May 2008 17:28:44 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20513410</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I turned up the following:<br><br>Registrant:<br>Bill Hutchinson<br>3100 Monticello<br>Dallas, Texas 75205<br>United States<br>Registered through: GoDaddy.com, Inc.<br>(&raquo;<A HREF="http://www.godaddy.com" >www.godaddy.com</A>)<br>Domain Name: MOBILEGLOBUS.COM<br>Created on: 28-Jan-08<br>Expires on: 28-Jan-09<br>Last Updated on: 20-May-08<br>Administrative Contact:<br>Hutchinson, Bill BillHutchinson@live.com<br>3100 Monticello<br>Dallas, Texas 75205<br>United States<br>(214) 443-4225<br>Technical Contact:<br>Hutchinson, Bill BillHutchinson@live.com<br>3100 Monticello<br>Dallas, Texas 75205<br>United States<br>(214) 443-4225<br>Domain servers in listed order:<br>NS21.DOMAINCONTROL.COM<br>NS22.DOMAINCONTROL.COM<br><br>Bill is one of Dunhill Partners:<br>&raquo;<A HREF="http://www.dunhillpartners.com/team.html" >www.dunhillpartners.com/team.html</A><br><br>Houston BBB info links another name to "mobileglobus":<br><br>Mike Allison Communications, LLC<br>563 Bird Song <br>League City, TX 77573<br>            (281) 332-9334 <br>www.mobileglobus.com<br>www.mikeallisoncommunications.reliabilitymall.com<br>Mike Allison Consulting<br>563 Bird Song <br>League City, TX 77573<br>            (281) 332-9334 <br>www.mobileglobus.com<br>www.mikeallisoncommunications.reliabilitymall.com<br><br>Hope this helps!!<br>Discalimer:  All the above are of course entirely coincidental]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513410</guid>
<pubDate>Tue, 20 May 2008 17:06:38 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20498148</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I've been hit by the same scam, only it appears that there is a new domain *and* a new company to add to the mix.<br><br>The domain name is mobileglobus.com. A whois entry doesn't turn up much as they have registered it via proxy:<br><br>================<br>Registrant:<br>   Domains by Proxy, Inc.<br><br>   Registered through: GoDaddy.com, Inc. (&raquo;<A HREF="http://www.godaddy.com" >www.godaddy.com</A>)<br>   Domain Name: MOBILEGLOBUS.COM<br><br>   Domain servers in listed order:<br>      NS21.DOMAINCONTROL.COM<br>      NS22.DOMAINCONTROL.COM<br>=================<br><br>The web site pattern matches the other scam image sites. The amount I was charged was $9.87.<br><br>The second charge was through a "P&P Services Inc". The link below (also mentioned earlier in this thread) makes reference to the same company:<br><br>&raquo;<A HREF="http://www.ripoffreport.com/reports/0/316/RipOff0316667.htm" >www.ripoffreport.com/reports/0/3&middot;&middot;&middot;6667.htm</A><br><br>The charge in this case was less; it was $5.56. Anyone have any ideas how to investigate this "P&P Services Inc" any further? A basic Google search doesn't turn up much.<br><br>BTW, great job on tracking all of this!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20498148</guid>
<pubDate>Sat, 17 May 2008 14:16:01 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20491721</link>
<description><![CDATA[<A HREF="/useremail/u/1536239"><b>JJBrannon</b></A> : I was hit with a photosmix.com in my last billing cycle which I caught last evening while reviewing my accounts.<br><br>The charge stood out like a nudist at a church service because this account -- my oldest credit card -- has only been used for about the last two years for a 4% balance transfer I was paying down.<br><br>But the reaction of the card issuer's security department was worse than the charge.  They sought to terminate the account and issue a new number without any guarantee that this wouldn't adversely affect my credit history. <br><br>As a former credit investigator for a credit card bank myself, I thought it likely that this action would erase my longest credit record and my FICO rating.<br><br>JJB]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20491721</guid>
<pubDate>Fri, 16 May 2008 08:36:41 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20430500</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Don't know if it's relevant, but all of this reminds me of a scam I was reading about on the Paypal/ebay forums a few months ago. feebay removed the thread from their forum, but here's some background:<br><br>&raquo;<A HREF="http://voip-hype.com/voip-provider-betamax-apparently-victim-of-a-scam/" >voip-hype.com/voip-provider-beta&middot;&middot;&middot;-a-scam/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20430500</guid>
<pubDate>Sun, 04 May 2008 15:23:18 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20420048</link>
<description><![CDATA[<A HREF="/useremail/u/1338989"><b>K Patterson</b></A> : I took the liberty of starting a new topic, hoping that others will add text or links for each of the frauds listed and that it will be stickied.<br><br>"The FBI wants you to know:"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20420048</guid>
<pubDate>Fri, 02 May 2008 08:34:50 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20419893</link>
<description><![CDATA[<A HREF="/useremail/u/475168"><b>pleekmo</b></A> : <div class="bquote"><small>said by  Zenith <A HREF="/useremail/u/1536650"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>As long as you credit it being authored by  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and include <A HREF="http://www.dslreports.com/forum/r20407182-">a link</a> back to <A HREF="http://www.dslreports.com/forum/r20407182-">the post</a>,,,,,, ;)  I would guess he would not mind, but I am guessing and cannot speak for him.<br> </div>I would credit it to MGD for sure. MGD is doing a good thing and deserves all credit for the impact that's been made against the bad guys.<br> </div>I copied and pasted the analysis into my blog but also noted that I'd cribbed it from here and gave links to this thread and another similar one here, as well.  Though perhaps I should give a more explicit credit...<br><small>--<br>HCN: Because you deserve a rest!<br><br>Proud member of the Free Omelas Liberation Front.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20419893</guid>
<pubDate>Fri, 02 May 2008 07:18:57 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20418117</link>
<description><![CDATA[<A HREF="/useremail/u/1536650"><b>Zenith</b></A> : <div class="bquote"><small>said by  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>As long as you credit it being authored by  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and include <A HREF="http://www.dslreports.com/forum/r20407182-">a link</a> back to <A HREF="http://www.dslreports.com/forum/r20407182-">the post</a>,,,,,, ;)  I would guess he would not mind, but I am guessing and cannot speak for him.<br> </div>I would credit it to MGD for sure. MGD is doing a good thing and deserves all credit for the impact that's been made against the bad guys.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20418117</guid>
<pubDate>Thu, 01 May 2008 19:50:04 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20417920</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : As long as you credit it being authored by  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and include <A HREF="http://www.dslreports.com/forum/r20407182-">a link</a> back to <A HREF="http://www.dslreports.com/forum/r20407182-">the post</a>,,,,,, ;)  I would guess he would not mind, but I am guessing and cannot speak for him.<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20417920</guid>
<pubDate>Thu, 01 May 2008 18:57:42 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20417849</link>
<description><![CDATA[<A HREF="/useremail/u/1536650"><b>Zenith</b></A> : I copied your "how it works post" and pasted it into a word document. Hope you don't mind. Would you have a problem with my pasting it on other forums that may be discussing these type scams?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20417849</guid>
<pubDate>Thu, 01 May 2008 18:41:49 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20417664</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My dad just got the photosmix.com charge and thanks to this post we're getting everything fixed. :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20417664</guid>
<pubDate>Thu, 01 May 2008 17:49:49 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20407544</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Amazing post. Thanks for taking the time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20407544</guid>
<pubDate>Tue, 29 Apr 2008 19:27:21 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20407182</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by kooooo :</small><br><br>Can someone explain to me how this scam makes money? .... </div>To add to what  pcdebb <A HREF="/useremail/u/254898"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> posted.<br><br>The essence of the scheme is that a considerable percentage of the victims may not catch the charge. It can easily be overlooked when an account has multiple cards that are in frequent use. In some cases a person may think their spouse made the charge, and vice versa. <br><br>The amounts of the fraudulent charges vary between $3 and $15 and are below the threshold where many people will actively pursue it. Several victims have reported that when they finally caught on, they went back over prior statements, and found several months worth of charges that went unnoticed.<br><br>For those that catch and pursue it, there is always a phone number listed on the line item charge, and also listed on the contact info on the hidden website. When a victim calls, the criminals will issue an immediate credit for the charge, and thus avoid the high chargeback fee. In fact, the banks unwittingly assist the criminals sustain each fraudulent operation by telling the cardholder to contact the merchant directly, first. That is exactly what the syndicate wants to happen if the victim discovers the charge, and pursues it. <br><br>That is why it is crucial that a victim report the charge as "fraudulent", and insist that it is classified as such. Besides triggering the card to be replaced, it will also generate a chargeback. It is the increasing chargeback ratio that usually causes the merchant account to be cancelled... eventually. Some of these individual sites have been in operation for well over a year. I have seen some that went down in a few months, it all depends on the mix of victims. If the criminals could issue credits to all the victims who complained then the account may never trigger an alert.<br><br>I am aware of one specific instance where the criminals were notified about the growing ratio of chargebacks. They responded that their site was being abused by "criminals" trying to buy items with stolen card data. The account rep's response was that after reviewing their website, they should institute an account enrollment policy where purchasers are required to enroll before being able to complete a transaction. He said that would be a deterrent to keep fraudsters away. The criminals responded that this was an excellent suggestion, thanked him, and said that they would immediately adopt that new procedure.<br><br>Copies of the criminals handbook/operational manual published in the other thread, show that the merchant account application for each fake site lists an anticipated mpnthly billing revenue of between $40,000 to $50,000 per site. One recent interception had records showing ~ $180,000 successfully processed in less than 4 months, and included a $20,000 wire transfer in the process of heading out to Cyprus being recalled. There can be a lag time of 30 to 60 days for all charge backs to filter through. A rough estimate is that 35 to 40, or more, sites are fully active at any given time. It is an assembly line process, new sites are being created all the time.<br><br>Once an operation is up and running, it is only excessive chargebacks that can bring it down, that, or the duped cyber-mule catching on. Because of the trivial amount, many victims are told by the issuing bank to contact the vendor directly "it is probably a billing error, or a purchase that you do not recognize".<br><br>Remember the criminals have perfected this operation over many years. They know exactly where the weak points are in the system and how to capitalize on them. One example of that, was a sting operation where potential roadblocks were created during the set up process, in order to confirm known theories of the operation. One of the fake websites that was already set up awaiting the cyber-mules merchant account approval, had the domain registered in a different state with a victim's card, and listed in their name. The syndicate was told that the merchant account approval was on hold, because Authorize.net had questioned why the related website was registered to someone other than the LLC that was applying for the account. The criminals responded that this could not be a valid reason for the hold up, because they knew that authorize.net nor the bank, never checks to see who owns the domain for the website that the LLC that was applying for the merchant account for.<br><br>Also, the criminals have recently began to address the excessive charge back ratio by submitting fake documents to the banks in response to dispute notices. They provide a false log of a user id and password including an IP address that the victim supposedly used to set up the account with. There is at least one recent victim report of the bank reversing and reinstating the fraud charge, upon receipt of those false documents.<br><br>MGD<br><br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20407182</guid>
<pubDate>Tue, 29 Apr 2008 18:16:47 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20406928</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by kooooo :</small><br><br>Can someone explain to me how this scam makes money? Don't chargebacks cost a merchant $20-$30 per incident? Also, if your chargeback rates are too high, it's my understanding you lose your merchant account.  <br> </div>At $50,000 per month, they don't care that much until the Charge Backs freeze/lock/close the account and that makes them open ten (10) more sites with ten (10) new Merchant Accounts.  They have a separate group that does nothing but recruit mules to setup these sites.<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20406928</guid>
<pubDate>Tue, 29 Apr 2008 17:26:36 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20406644</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : <div class="bquote"><small>said by kooooo :</small><br><br>Can someone explain to me how this scam makes money? Don't chargebacks cost a merchant $20-$30 per incident? Also, if your chargeback rates are too high, it's my understanding you lose your merchant account.  <br> </div>essentially for every chargeback (read: each transaction that is caught by the account holder) there is, there is 100 that will go undetected.  and they are probably registered with a merchant (authorize.net for example) that dont care.<br><small>--<br><A HREF="http://pcdebbhealth.blogspot.com/">a time for change...</a> | <A HREF="http://www.dslreports.com/forum/sports">1st & 10</a> | <A HREF="http://www.dslreports.com/forum/hamradio">Ham is good</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20406644</guid>
<pubDate>Tue, 29 Apr 2008 16:35:28 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20406411</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Can someone explain to me how this scam makes money? Don't chargebacks cost a merchant $20-$30 per incident? Also, if your chargeback rates are too high, it's my understanding you lose your merchant account.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20406411</guid>
<pubDate>Tue, 29 Apr 2008 16:01:14 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20402364</link>
<description><![CDATA[<A HREF="/useremail/u/648660"><b>acadiel</b></A> : The Consumerist just picked this up.<br><br>&raquo;<A HREF="http://consumerist.com/385004/watch-out-for-987-credit-card-scam-from-photoproslandcom#viewcomments" >consumerist.com/385004/watch-out&middot;&middot;&middot;comments</A><br><br>I wish they would have pointed here, because MGD has done quite a bit of work trying to find out who these scammers are.<br><small>--<br><A HREF="http://www.guidry.org/newbbs">acadiel's blog is here</a><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20402364</guid>
<pubDate>Mon, 28 Apr 2008 21:09:07 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20362652</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you for the information in this forum. I have just cancelled my credit card after seeing an item appeared in my Citiibank statement from PHOTOS PARADISE 214-7175031 TN for $8.88. The merchant category shows up as COMPUTERS, COMPUTER PERIPHERAL EQUIPMENT.<br><br>I found the following domain registration information which tracks with the culprits already listed in this forum:<br><br>Registrant:<br>HAITAO ZHANG<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br><br>Registered through: GoDaddy.com, Inc. (&raquo;<A HREF="http://www.godaddy.com" >www.godaddy.com</A>)<br>Domain Name: PHOTOSPARADISE.COM<br>Created on: 12-Jan-08<br>Expires on: 13-Jan-09<br>Last Updated on: 12-Jan-08<br><br>Administrative Contact:<br>ZHANG, HAITAO haitao.zhang44@yahoo.com<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br>+852 8198 0611<br><br>Technical Contact:<br>ZHANG, HAITAO haitao.zhang44@yahoo.com<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br>+852 8198 0611<br><br>Domain servers in listed order:<br>NS07.DOMAINCONTROL.COM<br>NS08.DOMAINCONTROL.COM<br><br>Registry Status: clientDeleteProhibited<br>Registry Status: clientRenewProhibited<br>Registry Status: clientTransferProhibited<br>Registry Status: clientUpdateProhibited]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20362652</guid>
<pubDate>Mon, 21 Apr 2008 12:07:30 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20339927</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by  jskdn <A HREF="/useremail/u/1357157"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> After reporting it I called back my credit card company to tell them about what I read here. I am afraid that they won't follow up on it through legal channels as they should. <b>But they did try to sell me a service to watch my credit for $12.95 month. </b> <br> </div>Isn't that just so great of them.  First they pass on all losses to the customer in higher interest rates plus higher base fees and then they want to charge extra to protect your account instead of changing their way of doing business that allows these blatant thefts of small amounts to go untouched and left alone as if it were OK to be done.<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20339927</guid>
<pubDate>Tue, 15 Apr 2008 19:34:22 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20339863</link>
<description><![CDATA[<A HREF="/useremail/u/1357157"><b>jskdn</b></A> : I too just had charges on my credit card bill from Stock Image Planet Com and WISEE GOODS for the same amounts as Molly01. It appears that they are trying to steal small amounts from large numbers of people. After reporting it I called back my credit card company to tell them about what I read here. I am afraid that they won't follow up on it through legal channels as they should. But they did try to sell me a service to watch my credit for $12.95 month.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20339863</guid>
<pubDate>Tue, 15 Apr 2008 19:23:27 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20312483</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : I'm glad you found the fingerprinting on why they all showed up. I forgot to look at the robots files so thank you very much for finding the "in common" error.  Hopefully they will continue to make these and other errors on the way to their eventual demise. ;)<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20312483</guid>
<pubDate>Thu, 10 Apr 2008 04:28:30 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20312349</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Interesting results.....<br><br> </div>.<br>Nice catch, what they all appear to have in common is a bad robots.txt file. They left out the forward slash ": / " after "Disallow", to specify "all", or the entire site. What that screw up does is disallow nothing, which yields an allow all. &raquo;<A HREF="http://stockimageplanet.com/robots.txt" >stockimageplanet.com/robots.txt</A><br><br>A correct version, further above:  &raquo;<A HREF="/r0/download/1292657~c58bd62c7c7fb538b4903f355b0b54c3/wiseegoods_robots.png">/r0/download/1&middot;&middot;&middot;bots.png</A><br><br>Note to Igor in the Ukraine, being close, don't count.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20312349</guid>
<pubDate>Thu, 10 Apr 2008 02:58:21 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20311962</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : Interesting results.....<br><br>&raquo;<A HREF="http://www.google.com/search?q=%22Our+web-site+is+unique%22,+because+unlike+many+%22other+stock+photography%22&hl=en&filter=0" >www.google.com/search?q=%22Our+w&middot;&middot;&middot;filter=0</A><br><br>[att=1]<br><br>Regards,<br><br>Doctor Olds<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20311962?c=1295800&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="80998 bytes" WIDTH=600 HEIGHT=545 SRC="/r0/download/1295800.thumb600~9ccb8bd7ebefacc98e457a5b7ac7d11d/InterestingGoogle.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20311962</guid>
<pubDate>Thu, 10 Apr 2008 00:18:43 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20304562</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you so much for the information. I have never dealt with this before and have now been hit twice in two days within the last week. Once for LoadofPhotos.com for $9.87 and over the weekend from Wiseegoods.com for $4.95. You were very informative and even though I have a new debit card coming, I think I will definitely follow up with a complaint or hand-written letter to help draw attention to this ridiculous new fear invading our everyday life.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20304562</guid>
<pubDate>Tue, 08 Apr 2008 19:19:07 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20279173</link>
<description><![CDATA[<A HREF="/useremail/u/1196800"><b>SSSR</b></A> : I just got hit on 3/26 from STOCK IMAGE PLANET COM for $9.87 and I also have a temporary hold from WISEE GOODS LLC for $2.95. I'll be calling my bank to report this fraud.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20279173</guid>
<pubDate>Thu, 03 Apr 2008 21:19:04 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20262083</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Hermes Electro AKA hermeselectro.com was first discussed in the original forum thread on the "globus" group here: &raquo;<A HREF="/forum/r19881855-pictureglobuscom-imaglobuscom-and-templateglobuscom-now">pictureglobus.com, imaglobus.com, and templateglobus.com now</A> In that thread it was identified as a Command & Control hub site, because it was from that domain that victims were sent the bogus records of how their cards were used for account enrollments. Hong-Kong Content Trade AKA hkc-trade.com was subsequently identified earlier in this thread as an identical second C&C hub site.<br><br>They both list addresses in Hong Kong along with local voice mail telephone numbers. It has not been determined if those numbers are relaying calls elsewhere, or if there is a local management mule fielding calls on behalf of the criminals. There is little doubt that the real criminals operating this division, are also located in Russia and/or the Ukraine. <br><br>New evidence for this image / pic group show that people with online resumes are being directly targeted for cyber-mule recruitment. Here is an actual unsolicited pitch sent from online resume trolling.<br><br>  <blockquote><small>quote:</small><hr>From: hzhang@hkc-trade.com<br><br>Subject: Job.com Position offered to VICTIM NAME - $70k/year - Independent Representative Position<br><br>Dear "Potential Cyber-Mule"<br> <br>My name is Haitao Zhang. I work as a Local Advisor for Honk-Kong Content Trade Company.<br> <br>Your resume, found on job.com has been chosen by our HR department, and I would like to offer you the position of an Independent Representative we currently have available at our company.<br> <br>Bellow I have provided some general information about our company and position description.<br> <br>----------------------------------------------------------------------<br>About Versum Electro Company<br>----------------------------------------------------------------------<br>Honk-Kong Content Trade is a fast growing company working on the international market since 2002. We are proud to announce that it has been over 5 years of our successful operation. During this relatively short period of time we managed to build strong business relationships with all of our clients as well as created a bright team of motivated professionals.<br> <br>The main activities of the company in Europe include but are not limited to:<br> <br>- Electronic wholesales and retailing<br>- Online e-content sales<br>- E-business systems development<br> <br> <br>----------------------------------------------------------------------<br>Independent Representative Position<br>----------------------------------------------------------------------<br>In connection with forthcoming expansion into the United States market we are hiring an honest, punctual candidate for the Independent Representative position.<br> <br>The primary role of the Independent Representative:<br> <br>Provide support for contract and agreement registration, required for on-line trade platforms. Manage funds and organize profit distribution.<br> <br>The position which is being offered implies both part-time and full-time involvement thus allowing you to adjust your schedule and allocate enough time to complete the required tasks. We will be helping and assisting you during the entire work process, providing all the necessary information, technical support and expert guidance.<br> <br>The salary consists of two parts and will grow depending on your performance.<br>1. Base salary of $2000.00 (three thousand) US<br>2. 1% from sales (may grow up to 5%)<br> <br>On average you will be receiving 4-5 thousand dollars each month during the first few month of your work.<br> <br>Payments are made twice a month.<br> <br>If you are interested in this offer and would like to receive more information, please send your resume and motivation letter to resume@hkc-trade.com<br> <br>You can contact me about this position by:<br>Email: hzhang@hkc-trade.com<br>Phone: (+10) 852 8198 0664<br> <br>You are also welcome to visit our website at: &raquo;<A HREF="http://www.hkc-trade.com" >www.hkc-trade.com</A><br> <br>Your prompt response on this offer would be greatly appreciated.<br> <br>Sincerely,<br> <br>----------------------------------------------------------------------<br>Haitao Zhang<br>Local Advisor<br>Honk-Kong Content Trade Inc.<br>hzhang@hkc-trade.com<br> <br>Phone: (+10) 852 8198 0664<br>&raquo;<A HREF="http://www.hkc-trade.com" >www.hkc-trade.com</A><br><hr></blockquote><br><br>.<br><br>The fraudulent funds from accounts set up in this pic/image/ globus group are confirmed as being laundered via these recent wire transfers out of US banks<br><br>One routing sends the stolen funds to <b>FBME Bank Ltd</b> (Federal Bank of the Middle East Ltd) headquartered in Nicosia, Cyprus, with foreign branches loacted in Russia and Tanzania. &raquo;<A HREF="http://www.fbme.com/" >www.fbme.com/</A> and &raquo;<A HREF="http://www.fbme.com/index.cfm?id=104" >www.fbme.com/index.cfm?id=104</A><br><br>The fraudulent proceeds were routed out of the country via <b>Deutsche Bank Trust Company</b>, New York, &raquo;<A HREF="http://www.db.com/index_e.htm" >www.db.com/index_e.htm</A><br><br>The specific wire transfer details are:<br><br><hr><br>Beneficiary Account: Name: VIDESS S.A No.: 073725<br>IBAN: CY2011501002073725USDCACC001<br>Beneficiary Bank: FBME BANK Limited, <br>Nicosia, Cyprus <br>Swift Code: FBMECY2N<br>Correspondent Bank: Deutsche Bank Trust Company,<br>New York, USA Swift <br>Code: BKTRUS33<br>Account No: 04-053-863<br><hr><br><br>Note the beneficiary name <b>VIDESS S.A</b> from non other than the Ukraine:<br><br>[att=1]<br><br>A single web page, appears to be a jack of all nefarious trades website.<br><br>VIDESS S.A, AKA &raquo;<A HREF="http://videss.org" >videss.org</A> just oozing with legitimacy:<br><br>  <blockquote><small>quote:</small><hr>"VIDESS" was founded during 2003 with professional staff, making custom graphic, web and 3D design, for the Internet Industry and over. We have a great experience and huge creative potential. <b>The central "VIDESS" office is in Ukraine,</b> but our ties and works are successfully used with the companies all over the world.<br><hr></blockquote><br><br>The videss.org domain has a cloaked registration:<br><br><pre><br>Whois Record<br>Domain ID:D104264057-LROR<br>Domain Name:VIDESS.ORG<br>Created On:23-Apr-2004 20:03:36 UTC<br>Last Updated On:11-Mar-2008 23:52:19 UTC<br>Expiration Date:23-Apr-2012 20:03:36 UTC<br>Sponsoring Registrar:EstDomains, Inc. (R1345-LROR)<br>Status:CLIENT DELETE PROHIBITED<br>Status:CLIENT RENEW PROHIBITED<br>Status:CLIENT TRANSFER PROHIBITED<br>Status:CLIENT UPDATE PROHIBITED<br>Registrant ID:PP-SP-001<br>Registrant Name:Domain Admin<br>Registrant Organization:PrivacyProtect.org<br>Registrant Street1:P.O. Box 97<br>Registrant Street2:All Postal Mails Rejected, visit Privacyprotect.org<br>Registrant Street3:<br>Registrant City:Moergestel<br>Registrant State/Province:<br>Registrant Postal Code:5066 ZH<br>Registrant Country:NL<br>Registrant Phone:+45.36946676<br>Registrant Phone Ext.:<br>Registrant FAX:<br>Registrant FAX Ext.:<br>Registrant Email:<br></pre><br><br>They are hosted in New Jersey on Net Access Corporation (NAC.NET) on IP 64.21.13.112<br><br>A second recent transfer of funds from the fraudulent card billing of this group was sent to the account of <b>BETA-METAL LTD</b> located in Kyev, Ukraine, via a bank in Riga, Lativa called <b>JSC Rietumu Banka</b> &raquo;<A HREF="http://www.rietumu.com/eng.nsf/page?ReadForm&pid=1&page=level_31&menuref=63FC8EAD057CCDE9C2256BA600372683" >www.rietumu.com/eng.nsf/page?Rea&middot;&middot;&middot;00372683</A><br><br><hr><br>Beneficiary Name:   BETA-METAL LTD<br>Beneficiary Address:  Grushevskogo 28/2, Kyev, Ukraine. 01021<br>IBAN: LV55 RTMB 0006 0380 6245   <br>(multicurrency)   <br>Bank: JSC Rietumu Banka<br>Bank address:   54 Brivibas street, Riga, LV-1011, <br>LATVIA S.W.I.F.T.:   RTMBLV2X<br><hr><br><br>So far the only reference to BETA-METAL LTD that I can find is this: &raquo;<A HREF="http://64.233.169.104/search?q=cache:6LFZJsGQ1BgJ:www.kocaelitabip.org.tr/NeW//index.php%3Foption%3Dcom_content%26task%3Dview%26id%3D384%26Itemid%3D68+%22BETA-METAL+LTD%22&hl=en&ct=clnk&cd=1&gl=us" >64.233.169.104/search?q=cache:6L&middot;&middot;&middot;=1&gl=us</A><br><br>Clearly, the names and addresses of the C&Cs in Honk Kong are a distraction, intended to throw the focus away from the real location. Find and follow the money !! <br><br>MGD<br><small>EDIT= formatting</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20262083?c=1292696&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="287421 bytes" WIDTH=600 HEIGHT=452 SRC="/r0/download/1292696.thumb600~bd12804e6639b8f26a10a2d42ba2d193/Videss_org.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20262083</guid>
<pubDate>Tue, 01 Apr 2008 05:06:31 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20261448</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by GINAH   :</small><br><br>Thank you for this information! Same thing happened to me.  ........... I had a charge about six days ago from wiseegoods, llc with phone number 954-603-7710.  I emailed the Fla. Attorney General's office and filed a complaint.  I then found out that the Miramar Police Dept is investigating Wiseegoods and will likely be a federal case. ........ </div>You are welcome, and glad that you posted.<br><br>You are the first victim whose fraud charges actually tie this Globus / Pic / image scam subset back to the main template Ebook group  &raquo;<A HREF="/forum/r19620593-Ebook-websites-fraud-charges-DevbillDigitalAgePluto">Ebook websites, fraud charges,  Devbill/DigitalAge/Pluto</A> You have one fraud charge from each division. I assume they were on the same card, though there are victims who get hit on two different cards.<br><br>Thanks again, as this is the first time that I have seen a reference to Wiseegoods. Which apparently has been around since January of 2007, and is hosted on GoDaddy. I can confirm that they are in fact part of the main group, as there are several victim reports who also had additional fraud charges from other sites in  the main group, Interactive designs, etc.<br><br>The domestic based portion of wiseegoods was set up by a duped US cyber-mule who was recruited via an employment offer.<br><br><b>wiseegoods.com</b> AKA <b>WISEEGOODS.COM LLC</b> <b>954-603-7710</b><br>.<br>[att=1]<br><br>The domain is registered to the cyber-mule, which fits the pattern of the template group.<br><br><pre><br>[wiseegoods.com IP 68.178.254.16]<br>.<br>Registration Service Provided By: NameCheap.com<br>Contact: support@NameCheap.com<br>.&#9;<br>Domain name: wiseegoods.com<br>.<br>Registrant Contact:<br>   WiseEGoods.com LLC<br>   Basil Lynch (thewisemanster@gmail.com)<br>   +1.6109563936<br>   Fax: +1.5555555555<br>   16781 S.W. 36 Court<br>   Miramar, FL 33027<br>   US<br>.<br>Status: Locked<br>.<br>Name Servers:<br>   ns1.secureserver.net<br>   ns2.secureserver.net<br>.   <br>Creation date: 15 Jan 2007 07:56:35<br>Expiration date: 15 Jan 2009 07:56:35<br></pre><br><br>In addition, Mr. Lynch would have registered an LLC in order to obtain a business bank account, and merchant processing account which uses Authorize.net / Cybersource.<br>.<br>[att=2]<br>.<br><pre><br>Florida Limited Liability Company  <br>WISEEGOODS.COM LLC<br>. <br>Filing Information <br>Document Number L07000001015 <br>FEI Number 113800709 <br>Date Filed 01/03/2007 <br>State FL <br>Status ACTIVE <br>.<br>Principal Address <br>16781 S.W. 36 COURT<br>MIRAMAR FL 33027<br>.  <br>Mailing Address <br>16781 S.W. 36 COURT<br>MIRAMAR FL 33027 <br>. <br>Registered Agent Name & Address <br>LYNCH, BASIL<br>16781 S.W. 36 COURT<br>MIRAMAR FL 33027 US<br>. <br>Manager/Member Detail <br>Name & Address <br>Title MGRM <br>LYNCH, BASIL<br>16781 S.W. 36 COURT<br>MIRAMAR FL 33027<br>.  <br>Annual Reports <br>Report Year Filed Date <br>2008 03/07/2008 <br></pre> <br><br>As usual, wiseegoods.com was set up exclusively to launder hijacked card data into cash, so it needed to be hidden from the rest of the internet, by blocking search engine archiving:<br><br>[att=3]<br><br>The cyber-mule, Mr Lynch, obviously would have been totally unaware of what he was setting himself up for. Once he is alerted, the merchant account should be closed immediately, the bank account frozen, and any recent foreign wire transfers of the fraudulent funds should try and be recovered. All communication with the crime syndicate should be stopped at once.<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20261448?c=1292655&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="437416 bytes" WIDTH=600 HEIGHT=434 SRC="/r0/download/1292655.thumb600~2398c2134508910e6911876adaff9d62/wiseegoods_main.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20261448?c=1292656&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="11716 bytes" BORDER=0 WIDTH=331 HEIGHT=665 SRC="/r0/download/1292656~8b61cb5cee800362dbb1bc66612140a8/wiseegoods_corp.png"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20261448?c=1292657&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="2646 bytes" BORDER=0 WIDTH=389 HEIGHT=119 SRC="/r0/download/1292657~c58bd62c7c7fb538b4903f355b0b54c3/wiseegoods_robots.png"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20261448</guid>
<pubDate>Tue, 01 Apr 2008 00:06:13 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20256850</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : another victim...I check my credit card account on line and was surprised to see the charge, especially since I was at a funeral all day out of state...I have called visa and canceled my card and had a new card reissued. They have turned this over to their fraud department. I will also put a fraud alert with all the credit reporting companies and urge others to do so as well.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20256850</guid>
<pubDate>Mon, 31 Mar 2008 10:20:16 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20255435</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you for this information! Same thing happened to me.  I had a charge on my bank account via my debit card from Michael P Hamilton for $9.64. Thanks to your post I understand better how this sort of thing works.  I had a charge about six days ago from wiseegoods, llc with phone number 954-603-7710.  I emailed the Fla. Attorney General's office and filed a complaint.  I then found out that the Miramar Police Dept is investigating Wiseegoods and will likely be a federal case.  So I am guessing that Wiseegoods and Michael P Hamilton are scams run by the same or similar crooks. Folks, please watch out for Wiseegoods also.  Thanks again!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20255435</guid>
<pubDate>Mon, 31 Mar 2008 06:08:37 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20247464</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by Doug55 :</small><br><br>Please add LoadOfPhotos.com to the list. ...<br> </div>Thank You, I have added them to the original list on the previous page<br><br><div class="bquote"><small>said by  madneon <A HREF="/useremail/u/918624"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Yes I too am a victim of Loadofphotos.com for 9.87 I have also replaced my card. I am VERY careful with my card any clues on how these people are getting hold of them and is loadofphotos a real web site because it it still up and running.<br> </div>[att=1][att=2]<br><br>No they are a 100% fraud, fake site, just a front operation used to launder hijacked card data into cash. They are a subset of the larger: &raquo;<A HREF="/forum/r19620593-Ebook-websites-fraud-charges-DevbillDigitalAgePluto">Ebook websites, fraud charges,  Devbill/DigitalAge/Pluto</A> same modus-operandi. <br><br>It is very difficult to know for sure the source of the card data. It is doubtful that the data is coming from any recent e-commerce transactions since many of the cards are pre pinged before the charge. That tells us that they are testing the validity of the data before submitting the actual fraud charge. If the data was tied to actual recent transactions, that would not be necessary, since they would be known good data.<br><br>Somewhere behind this operation is a domestic cyber-mule who would have set up the merchant and banking accounts to process the fraud payments. What makes this this criminal operational group so disturbing is the complete lack of any vetting process whatsoever. The ability to set up and intergrate with the financial card processing system with such obvious fraudulent credentials is outrageous.<br><br>The websites are registered using GoDaddy's cloaking "hide a criminal" service called "Domainsby Proxy". That enables them to mask a clearly fraudulent domain registration. The sites contain no contact info, such as the business name that the merchant account was set up as. Just a bogus individuals name and voice mail phone number. Combine that with the fact that they are supposed to be selling an "intangible product", nothing to ship, and it just SCREAMS FRAUD. There isn't even any folders on the sites that contain graphic images that they are supposed to be selling. being blocked form search engines so no one could find them is just icing on the fraud cake.<br><br>We can go back and look at one of the earlier failed sites for an example of the deliberate obfuscation of the business registration chain.<br><br>The domain itself was cloaked via GoDaddy. they also own the cloaking service Domains by Proxy, Inc:<br><br><pre><br>Registrant:<br>Domains by Proxy, Inc.<br>.<br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br>.<br>Registered through: GoDaddy.com, Inc.<br>Domain Name: ZENITHGRAPHIC.COM<br>Created on: 04-Oct-07<br>Expires on: 05-Oct-08<br>Last Updated on: 04-Oct-07<br></pre><br><br>On this one only, the contact detail on the website included the name of the related LLC:<br><br>[att=3]<br><br>listed under the bogus names was:<br><br><pre><br>Support: Alex McGuire<br>e-mail: support@zenithgraphic.com <br>tel: (504) 208-4860<br>.<br>General: Edris Hoover<br>info@zenithgraphic.com<br>tel: (505) 350-8506<br>.<br>Jupiter, LLC    -------> LOOK<br>8210 Robin Ave NE<br>Albuquerque, NM 87110<br></pre><br><br>So the suspected recruited cyber-mule would have registered a cover LLC from that 8210 Robin Ave NE, Albuquerque, NM 87110 address. A check of the New Mexico Division of Corporation's database confirms this:<br><br><pre><br>New Mexico Public Regulation Commission<br>----------------------------------<br>JUPITER, LLC <br>SCC Number:  2937704  <br>Tax & Revenue Number:   <br>Organization Date:  SEPTEMBER 18, 2007, in NEW MEXICO  <br>Organization Type:  DOMESTIC LIMITED LIABILITY  <br>Organization Status:  EXEMPT  <br>Good Standing:   <br>Purpose:  N/R  <br>----------------------------------<br>.<br>ORGANIZATION DATES<br>Taxable Year End Date:     <br>Filing Date:     <br>Expiration Date:     <br>.<br>SUPPLEMENTAL POST MARK DATE<br>Supplemental:     <br>----------------------------------<br>MAILING ADDRESS<br>8210 ROBIN AVE NE ALBUQUERQUE , NEW MEXICO 87110 <br>PRINCIPAL ADDRESS<br>8210 ROBIN AVE NE ALBUQUERQUE NEW MEXICO 87110 <br>PRINCIPAL ADDRESS (Outside New Mexico)<br>----------------------------------<br>.<br>REGISTERED AGENT<br>BUSINESS FILINGS INCORPORATED <br>.<br>123 EAST MARCY STREET SANTA FE NEW MEXICO 87501 <br> <br>Agent Designated:    <br>Agent Resigned:  <br>----------------------------------<br>.<br>COOP LICENSE INFORMATION<br>Number:     <br>Type:     <br>Expiration Year:     <br>----------------------------------<br>.<br>ORGANIZERS<br>BUSINESS FILINGS INCORPORATED    <br>----------------------------------<br>.<br>DIRECTORS<br>Date of Election of Directors: <br>----------------------------------<br></pre><br>.<br>Since there are no reports of fraud charges under the zenithgraphic.com name, I assume the cyber-mule who registered Jupiter on behalf of the criminals dropped out before it got off the ground. All of the other sites hide that business information in order to preserve the fraud. No merchant account provider performing  even minimal vetting would not authorize an account set up based on this configuration format.<br><br>It is bad enough that consumer's card data cannot be kept secure, but to then provide open door access to the merchant financial system so that the hijacked data can be readily laundered into cash, is nothing short of incredible negligence.<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20247464?c=1291827&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="284908 bytes" WIDTH=600 HEIGHT=561 SRC="/r0/download/1291827.thumb600~f6aa6f78aa59c8f65e71e3e3a18e0cf3/loadofphotos_main_crop.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20247464?c=1291828&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="277767 bytes" WIDTH=600 HEIGHT=527 SRC="/r0/download/1291828.thumb600~ae37e3d9eebda72309159e79d01ebd37/loadofphotos_contact_crop.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20247464?c=1291829&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="161471 bytes" WIDTH=600 HEIGHT=536 SRC="/r0/download/1291829.thumb600~2f6b88ed80455c595e8a8bbb1349268d/zenithgraphic_contact.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20247464</guid>
<pubDate>Sat, 29 Mar 2008 12:59:26 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20247196</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : I would suggest to all victims who filed their fraud complaint only via the telephone to follow up with a letter addressed to the fraud department of your credit card company.<br><br>A physical letter addressed to you credit card company's fraud department will insure that your complaint is investigated as fraud vs. secretly "disputed" and swept under the rug.  I would also suggest that in the letter you state that you have also filed a complaint through ic3.gov.  After receiving my letter my credit card company immediately changed my charge reversal from "adjustment" to "fraud adjustment".  <br><br>I know it is a lot of effort for $10 but if the credit card companies are forced to report this as fraud they will eventually work towards stopping the criminal operation.  <br><br>Also, on the security forum there is more information on the Hannaford data breach.  The credit card information was intercepted at the store during the transaction and then sent overseas...<br><br>&raquo;<A HREF="http://www.boston.com/business/articles/2008/03/28/advanced_tactic_targeted_grocer/" >www.boston.com/business/articles&middot;&middot;&middot;_grocer/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20247196</guid>
<pubDate>Sat, 29 Mar 2008 12:08:17 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20246398</link>
<description><![CDATA[<A HREF="/useremail/u/918624"><b>madneon</b></A> : Yes I too am a victim of Loadofphotos.com for 9.87 I have also replaced my card. I am VERY careful with my card any clues on how these people are getting hold of them and is loadofphotos a real web site because it it still up and running.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20246398</guid>
<pubDate>Sat, 29 Mar 2008 08:25:38 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20235066</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I just recieved my cc statement and noticed the unauthorized charge from stockimagemix.com for $9.87. I called the number listed next to the charge and of course, it is not a working number. I immediately reported the fraud to my cc company. They credited the charge,flagged the account,cancelled the card/account number. I also filed a complaint with the Better Business Bureau (&raquo;<A HREF="http://www.bbbsoutheastflorida.org" >www.bbbsoutheastflorida.org</A>) and ic3.gov. <br><br>Without an address, I had to list the provided phone number(SE FL prefix)and URL. An address is required -- simply "Unknown" those areas of the form. Definitely provide the URL for this forum in your complaint.<br><br>I highly recommend that all victims follow up and do the same -- with enough pressure, HOPEFULLY, something will happen and these awful creatures will be stopped.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20235066</guid>
<pubDate>Thu, 27 Mar 2008 13:51:06 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20225033</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Please add LoadOfPhotos.com to the list. I was charged $9.87 today. Contacted BofA to reverse charge and get me a new card. Also had a pending charge from Michael P Andrew that has since been canceled. Load Of Photos is same site with Alex McGuire name and GoDaddy registration. Reported to IC3.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20225033</guid>
<pubDate>Tue, 25 Mar 2008 19:48:23 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20224786</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : MGD,<br><br>I have reported these sites to godaddy, both to president@godaddy.com and abuse@godaddy.com.  I am not satisfied with their response:<br><br>From godaddy:<br><br>"If you were, in fact, fraudulently charged through use of one or more of these sites, we can only recommend that you contact local law enforcement.<br><br>We have forwarded this to our Abuse Department for further investigation of potentially illegal activity. Of course, we cannot guarantee that any action will be taken, but we appreciate that you have brought this matter to our attention."<br><br>I would add to the steps to take if you are a victim of this fraud to contact both president@godaddy.com and abuse@godaddy.com.  Perhaps if they get enough complaints they will do what you advise and shut these guys down. A few policy changes to verify legit entities is all it would take to stop this fraud.  <br><br>Again, thanks for all of your work.  BTW, I did get a chargeback that stated "fraud adjustment".  Can I get my credit card company to give me the details of the chargeback?  <br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20224786</guid>
<pubDate>Tue, 25 Mar 2008 19:02:30 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20221090</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>MGD,<br><br>Please add stockimagemix.com to the database.  Another one with the exact same home page... unbelievable.  Same bogus support name of Alex McGuire, etc.  <br><br>Support: Alex McGuire <br>e-mail: support@stockimagemix.com <br>tel: (561) 283-4229 <br> </div><div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>MGD,<br><br>And stockimageplanet.com   <br><br>Support: Alex McGuire <br>e-mail: support@stockimageplanet.com <br>tel: (941) 312-2230<br> </div>Done,  <br><br>Below is a current list of the group, the current status needs to be updated as it is over a week old:<br><br><pre><br>Fraud Domain         Date of Reg  Registrar      Hosted IP     Provider   Status Contact N   umber<br>-----------          ---------    --------        --------     -------    -----   --------   ---<br>.<br>PHOTOSMIX.COM        17-Dec-07  DomainsByProxy  72.167.110.64* GoDaddy.com  Down  941-312-   2213 <br>.                          back up 03/12/08 on  208.109.181.27           (03/07/08) <br>.                                                 <br>PICTURESJUNGLE.COM   27-Nov-07  DomainsByProxy  72.167.116.221 GoDaddy.com  UP    706-955-   4677<br>.<br>POLISHPICTURESONLINE 30-Dec-07  GoDaddy.com     72.167.58.216  GoDaddy.com Parked 214-556-   6190 <br>.COM<br>.<br>PHOTOGEYSER.COM      14-Nov-07  DomainsByProxy  72.167.107.98  GoDaddy.com  UP    301-979-   9960<br>.<br>IMAGESPARADISE.COM   07-Feb-08  GoDaddy.com     216.69.131.90  GoDaddy.com  UP    214-556-   6153 <br>.<br>PROPHOTOSLAND.COM[*] 05-Dec-07  DomainsByProxy *216.69.138.250 GoDaddy.com  UP    609-916-   0040<br>.              *(Was For Sale scammers recovered)*Hosted at 208.109.165.98 Prior to 03/16/   08<br>.                                                                             <br>PHOTOSPARADISE.COM   12-Jan-08  GoDaddy.com     216.69.140.242 GoDaddy.com  UP    214-717-   5031 <br>.                                                                               & 214-556-   6153<br>.<br>GLOSSYELDORADO.COM   15-Feb-08  GoDaddy.com     72.167.168.179 GoDaddy.com  UP    No Numbe   r<br>.<br>IMGPARADISE.COM      11-Jan-08  DomainsByProxy  72.167.78.41   GoDaddy.com  UP    213-984-   4966<br>.<br>IMAGLOBUS.COM        26-Aug-07  DomainsByProxy  72.167.3.161   GoDaddy.com  UP    210-807-   4272<br>.<br>TEMPLATEGLOBUS.COM   16-Oct-07  DomainsByProxy* 72.167.23.251  GoDaddy.com  Down**210-807-   4272<br>.                                           208.109.182.137 ** as of 03/12/08 Spam-and-abu   se<br>. <br>PICTUREGLOBUS.COM    13-Nov-07  DomainsByProxy  72.167.106.230 GoDaddy.com  Down  210-807-   4272<br>.                                                                         03/09/08 <br>.<br>ZENITHGRAPHIC.COM    04-Oct-07  DomainsByProxy  72.167.27.37   GoDaddy.com  UP    504-208-   4860<br>.                                                                              &  505-350-   8506<br>.                                                                                   <br>STOCKIMAGEMIX.COM    18-Dec-07  DomainsByProxy  72.167.56.91   GoDaddy.com  UP    561-283-   4229 <br>.                                    <br>STOCKIMAGEPLANET.COM 10-Dec-07  DomainsByProxy  208.109.174.94 GoDaddy.com  UP    941-312-   2230<br>.                                                          <br>LOADOFPHOTOS.COM     05-Dec-07  DomainsByProxy  72.167.9.148   GoDaddy.com  UP    870-619- 4035                   <br>.<br>.<br>C&C support sites<br>-----------------<br>.<br>HERMESELECTRO.COM    15-Aug-07  GoDaddy.com     208.109.138.8 GoDaddy.com   UP (10)8528120   4462<br>.<br>HKC-TRADE.COM        28-Nov-07  GoDaddy.com     72.167.4.140  GoDaddy.com   UP (10)8528198   0664<br></pre><br>.<br>Let me know if there are any missing from that list.<br><br>The last two that you posted, both have the robots.txt file set to block search engine archiving:<br><br>  &raquo;<small>https</small>://<A HREF="https://www.stockimagemix.com/robots.txt">www.stockimagemix.com/robots.txt</A><br><br>User-agent: *<br>Disallow:<br><br>STOCKIMAGEPLANET.COM[att=1]<br>STOCKIMAGEMIX.COM[att=2]<br><br>I am positive that the names listed on any of these sites are fictitious. Not long after the first generation "globus" sites were posted by  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> in this post &raquo;<A HREF="/forum/r19881855-pictureglobuscom-imaglobuscom-and-templateglobuscom-now">pictureglobus.com, imaglobus.com, and templateglobus.com now</A> I ran searches on the names through the Texas division of corporations, and did not find any relevant business registrations under the related names:<br><br><div class="bquote">CONTACT NAME:  MGD<br><br>SESSION STATUS: Open<br> <br>DATE:  020108KBDNCR<br><br>2/1/2008 2:04:31 PM<br> <br>------------------------------------------------------------<br> <br>Client     Reference   Document Number Document     Type   Status Received Date Document Fee <br>[ NONE ] 201976250002  Corporations - Names Availability (No decision making) {globus}  Processed 2/1/2008 2:07:05 PM $1.00 <br>[ NONE ] 201976250003  Corporations - Find by Assumed Name {imaglobus}  Processed 2/1/2008 2:13:41 PM $1.00 <br>[ NONE ] 201976250004  Corporations - Find-Global {pictureglobus}  Processed 2/1/2008 2:18:50 PM $1.00 <br>[ NONE ] 201976250005  Corporations - Find by Registered Agent {Robertson}  Processed 2/1/2008 2:20:37 PM $1.00 <br>[ NONE ] 201976250006  Corporations - Find by Registered Agent {eric Robertson}  Processed 2/1/2008 2:22:17 PM $1.00 <br>[ NONE ] 201976250007  Corporations - Find {Atala}  Processed 2/1/2008 2:25:22 PM $1.00 <br></div>This fraud division is probably the most egregious example of failure in the merchant account vetting process seen so far.<br><br>We have sites where not only are the domain registrations cloaked, but there is also invalid contact information listed on the sites. Nothing more than a bogus name, and a cell phone number. <br><br>The major security flaw in the merchant account vetting process, and one of obvious malfeasance, is that there is no check to make sure that the domain is actually registered by the business entity applying for the merchant account. In theory a business registered as Igor Cyber Scammer LLC. could open a merchant account for homedepot.com or Sears.com. Just the fact alone that an e-commerce site with no B&M location has a hidden domain registration should be enough to set alarm bells ringing. That's before we even get to the fact that an e-commerce site is hiding its existence from every search engine. The fact that there are no folders containing graphic images "the intangible product for sale", is just icing on the cake.<br><br>We do know who the merchant account provider is, yes, as usual it is Authorize.net / cybersource. That has been established from data supplied from victim debriefings. Credit issuing notifications sent to victims who complained, came from the authorize.net account control panel:<br><br><div class="bquote">From MICHAEL ALLISON "REDACTED" 2008<br>Return-Path: <br>Authentication-Results: mta116.mail.re3.yahoo.com  from=ghg.net; domainkeys=neutral (no sig)<br>Received: from 64.94.119.18  (EHLO anetrelay2f.authorize.net) (64.94.119.18)<br>  by mta116.mail.re3.yahoo.com with SMTP; Mon, 21 Jan 2008 12:37:10 -0800<br>Received: from extta5f.authorize.net [64.94.118.194]<br>    by anetrelay2f.authorize.net (StrongMail Enterprise 3.2.2.2(3.00.287)); "REDACTED" -0800<br>Received: from mail pickup service by extta5f.authorize.net with Microsoft SMTPSVC;<br>     "REDACTED" -0700<br>From: "MICHAEL ALLISON" MIKEALLISON@ghg.net<br>To: "REDACTED"<br>Subject: TEMPLATEGLOBUS.COM Customer Receipt/Purchase Confirmation<br>Date: "REDACTED" -0700<br>Importance: Normal<br>Message-ID: <br>Content-Length: 572<br>Sent: "REDACTED", 2008 "REDACTED"<br>Subject: TEMPLATEGLOBUS.COM Customer Receipt/Purchase Confirmation<br><br>========= <br>GENERAL <br>INFORMATION <br>=========<br><br>Merchant <br>: <br>TEMPLATEGLOBUS.COM<br>Date/Time <br>: <br>"REDACTED"<br>"REDACTED"<br>PM<br>Transaction <br>ID <br>"REDACTED"<br>========= <br>ORDER <br>INFORMATION <br>=========<br>Type <br>: <br>REFUND<br></div>Though GoDaddy is on record at the beginning as refusing to shut the hosting operation down without legal action, which is out of character of their normal trigger happy removal behavior. They have now done so to at least one of the sites. By doing so, they have also unmasked the original cloaked domain registration, which is SOP.<br><br>TEMPLATEGLOBUS.COM is showing terminated as of 03/12/08 for "Spam and Abuse".<br><br>The original TEMPLATEGLOBUS.COM cloaked domain registration: <br><br><div class="bquote">Registrant:<br>   Domains by Proxy, Inc.<br>   DomainsByProxy.com<br>   15111 N. Hayden Rd., Ste 160, PMB 353<br>   Scottsdale, Arizona 85260<br>   United States<br><br>   Domain Name: TEMPLATEGLOBUS.COM<br>      Created on: 16-Oct-07<br>      Expires on: 16-Oct-08<br>      Last Updated on: 28-Nov-07<br><br>   Administrative Contact:<br>      Private, Registration  TEMPLATEGLOBUS.COM@domainsbyproxy.com<br>      Domains by Proxy, Inc.<br>      DomainsByProxy.com<br>      15111 N. Hayden Rd., Ste 160, PMB 353<br>      Scottsdale, Arizona 85260<br>      United States<br>      (480) 624-2599      Fax -- (480) 624-2599<br><br>  Domain servers in listed order:<br>      NS29.DOMAINCONTROL.COM<br>      NS30.DOMAINCONTROL.COM<br></div>Once the site violated the TOS and was shut down around 2008-03-12, that cloaking service also ceased. The domain reverted to the actual data entered at the time of the original registration. <br><br><div class="bquote">Registrant:<br>   ERNEST TAYLOR <br>   29159 PERCH LAKE RD<br>   WATERTOWN, New York 13601<br>   United States<br><br>   Domain Name: TEMPLATEGLOBUS.COM<br>      Created on: 16-Oct-07<br>      Expires on: 16-Oct-08<br>      Last Updated on: 28-Nov-07<br><br>   Administrative Contact:<br>      TAYLOR, ERNEST  templateglobus@yahoo.com<br>      29159 PERCH LAKE RD<br>      WATERTOWN, New York 13601<br>      United States<br>      (315) 629-5442      Fax -- <br><br>   Domain servers in listed order:<br>      NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM<br>      NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM<br></div>Good reason to want to hide it, there are no records of an Ernest Taylor at that address. A reverse check of the street address shows a different first and last name. That phone number is not even for that locale, the number shows for a party in Evans Mills, NY 13637.<br><br>Clearly, with a little lobbying Godaddy could be motivated to pull the hosting on the entire operational group. Fraud and cyber crime are TOS violations, and there is more than ample evidence to confirm that they are all fraudulent.<br><br>In addition, the terms of service page on all the fraud sites are hijacked word for word from the legit gettyimages.com &raquo;<A HREF="http://www.gettyimages.com" >www.gettyimages.com</A> See: &raquo;<A HREF="http://www.gettyimages.com/Corporate/Terms.aspx" >www.gettyimages.com/Corporate/Terms.aspx</A><br><br>In fact on zenithgraphic.com they did not even remove Getty Images name: <br>&raquo;<small>https</small>://<A HREF="https://www.zenithgraphic.com/index.php?action=terms">www.zenithgraphic.com/index.php?action=terms</A><br><br>If those terms are unique to Getty Images and not generic, then Getty would have a cause for action for copyright violations.<br><br>Some pressure applied to GoDaddy now to pull the rug from this criminal operation, should be effective. To continue to host this obvious fraudulent enterprise would amount to knowingly aiding on ongoing criminal enterprise. Victims of this fraud might well consider that actionable.<br><br>EDIT= Added LOADOFPHOTOS.COM to master list 03/29/08<br><br>MGD <div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20221090?c=1290271&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="284334 bytes" WIDTH=600 HEIGHT=549 SRC="/r0/download/1290271.thumb600~a964a05d4905609f6374668fa3bfb314/stockimageplanet_main_crop.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20221090?c=1290272&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="335432 bytes" WIDTH=600 HEIGHT=552 SRC="/r0/download/1290272.thumb600~54787cdea09d86b35c5bbb284e1aa676/stocimagemix_main_crop.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20221090</guid>
<pubDate>Tue, 25 Mar 2008 05:15:55 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20207496</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Looks like photosmix.com and prophotosland.com are back up and running so beware... their site states "Our hosting provider has accidently delegated our domain to a different company... "  not sure what this means as they still have the same GoDaddy logo..... </div>That was no "accident", upon reviewing the domain transaction history, the most likely reason is that the payment for the original registration was charged back to GoDaddy. These criminals use hijacked victim financial data to pay for all the support and hosting services.<br><br>The domains were originally registered using go GoDaddy's domainsbyproxy cloaking service that hides the details of the registration for an additional fee. That service is a crime magnet, and should never be available for sites that are set up for e-commerce. The can only be a nefarious purpose in hiding the ownership of a commercial site engaged in payment processing.<br><br>On or about March 08th, GoDaddy took possesion of the <b>photosmix.com</b> domain and put it up for sale:<br><br><pre><br>----------------------------------------<br>Domain:  photosmix.com <br>.<br>Domain History<br>.  <br><b>Cache Date:  2008-03-08</b><br>.  <br>Registrar:  GODADDY.COM, INC.  <br>. <br>----------------------------------------<br>.<br>Registrant:<br>   Godaddy Software<br>   14455 N Hayden Rd<br>   Suite 219<br>   Scottsdale, AZ 85260<br>   United States<br>.<br>   Domain Name: PHOTOSMIX.COM<br>      Created on: 17-Dec-07<br>      Expires on: 18-Dec-08<br>      Last Updated on: 07-Mar-08<br>.<br>   Administrative Contact:<br>      <b>domains for sale, Godaddy Software  <br>      domains4sale[@]godaddy.com</b><br>      Godaddy Software<br>      14455 N Hayden Rd<br>      Suite 219<br>      Scottsdale, AZ 85260<br>      United States<br>      480-505-8800      Fax -- 480-505-8844<br>.<br>----------------------------------------<br></pre><br><br>That ownership reversion indicates that payment funds were charged back. Ridiculous as it may seem, the criminals would still have an opportunity to "make good" on the funds and recover the domain. Which they apparently did around March 16th, as the domain then reverted back to a domainsbyproxy cloaked status:<br><br><pre><br>----------------------------------------<br>.<br>Domain:  photosmix.com<br>. <br>Domain History<br>.  <br><b>Cache Date:  2008-03-16</b><br>.  <br>Registrar:  GODADDY.COM, INC.  <br>.<br>Registrant:<br>   Domains by Proxy, Inc.<br>   DomainsByProxy.com<br>   15111 N. Hayden Rd., Ste 160, PMB 353<br>   Scottsdale, Arizona 85260<br>   United States<br>.<br>   Domain Name: PHOTOSMIX.COM<br>      Created on: 17-Dec-07<br>      Expires on: 18-Dec-08<br>      Last Updated on: 12-Mar-08<br>.<br>   Administrative Contact:<br>      Private, Registration  PHOTOSMIX.COM@domainsbyproxy.com<br>      Domains by Proxy, Inc.<br>      DomainsByProxy.com<br>      15111 N. Hayden Rd., Ste 160, PMB 353<br>      Scottsdale, Arizona 85260<br>      United States<br>      (480) 624-2599      Fax -- (480) 624-2599<br>.<br>----------------------------------------<br></pre> <br><br>MGD<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20207496</guid>
<pubDate>Sat, 22 Mar 2008 13:21:49 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20206853</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by deanhuff  :</small><br><br>Add another for MICHAEL P HAMILTON $9.64 on 03/15/2008.  Bank of America gave me a new account number and re-imbursed the money.<br><br>I also had another charge for around $3 from "M BAR C RANCH" in Pending state but never posted. ......<br> </div>I assume the "M BAR C RANCH" appeared first, that would be a "ping" charge to validate the account. I wonder if these people &raquo;<A HREF="http://www.m-bar-c.org/" >www.m-bar-c.org/</A> have a merchant account that was hacked. <br><br>[EDIT= They do have a merchant account: &raquo;<small>https</small>://<A HREF="https://payments.auctionpay.com/ver3/?id=w038846">payments.auctionpay.com/ver3/?id=w038846</A> ]<br><br><div class="bquote"><small>said by deanhuff  :</small><br><br>.....I saw on the news that a local grocer called Sweetbay had a security breach and gave out a bunch of card numbers.  Sure enough, I had 1 Sweetbay transaction in early December.<br> </div>I am fairly certain that the Hannaford data would not be sufficient to be proccessed for this CNP type of fraud transactions. "IF", what Hannaford's reps stated is true, that customers names were NOT intercepted, then the data that the hackers got was the TRACK 2 card data. That would only enable them to use the data for fraudulent POS (Point of Sale) transactions. Typically that data is encoded on to white stock" and used where the card is not presented, e.g. gas stations etc. A common cheap method that they can use the stolen data for store POS fraud purchases is to clone the data on to used VISA / MC branded gift cards. That way they can be presented and swiped without causing suspicion.  <br><br>I have not seen any reports yet of the specific fraud use of the 1,800 victims of the Hannaford data so far. If the type of data leaked is correct, fraud use should be limited to POS transactions.<br><br>Up until your card was replaced, you could have been the victim of fraud from that as well. However, for an online CNP transaction, the full name and address would have been needed, along with the CVV2 security code. The security code is only printed on the card, and is not embedded in any of the track magnetic data. <br><br>A merchant gateway account for an online only entiity, such as these scams, will usually require the use of (AVS) and (CVV2) to restrict fraud. &raquo;<A HREF="http://en.wikipedia.org/wiki/Address_Verification_System" >en.wikipedia.org/wiki/Address_Ve&middot;&middot;&middot;n_System</A> <br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20206853</guid>
<pubDate>Sat, 22 Mar 2008 10:52:33 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20206667</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by Victim 1947 :</small><br><br>A charge of $9.64 from a Michael P Hamilton in Maryland (213-984-4966) posted to my Chase on 3-14-08.  A foreign voice recording, gave an indiscernible .com name, not Hamilton, not prophotoland, etc.  Sounds like "time share" but is indiscernible.  I see $9.64 has been used on previous attacks. Chase described Hamilton as an Art Dealer, but said they would do the charge back.  They did not want to close/replace the card. So I asked the rep to clearly state for their recording that they were declining to close the account for fraud. They said they will investigate. I'll monitor the account daily. <br> </div>That was a fraud charge from Imgparadise.com:<br><br>[att=1]<br><br>They are part of this sub group of Globus / Image / Pictures themed fraud sites laundering hijacked card data. &raquo;<A HREF="/forum/r19881855-pictureglobuscom-imaglobuscom-and-templateglobuscom-now">pictureglobus.com, imaglobus.com, and templateglobus.com now</A><br><br>I suspect "Michael P Hamilton in Maryland" may be a secondary merchant account, set up in a cyber mule's name after the original one was terminated for excessive chargebacks.<br><br>The phone number 213-984-4966 and the recording is definitely part of this group;<br><br>[att=2]<br><br>The reason Chase probably described them as an "Art Dealer", is from their interpretation of the vendor classification code assigned to the merchant account.<br><br>Chase will eventually have to cancel and replace your card. Yes, do keep a close eye on it, you will get more charges. <br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20206667?c=1289297&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="355127 bytes" BORDER=0 WIDTH=595 HEIGHT=718 SRC="/r0/download/1289297~08464fa04526994d1ae24d2f82cd59ba/Imgparadise_contact.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1289298~342da01f2c70f194be301b533f3986e8/213-984-4966.wav"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/sound.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>213-984-4966.wav</big></A> <small>453,498 bytes</small></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20206667</guid>
<pubDate>Sat, 22 Mar 2008 10:00:26 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20202865</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by jim123 :</small><br><br>how do they get the card # ????<br> </div>They need more than just the card number.  A card number alone is nearly useless.<br><br>Some of the data theft comes from this avenue:<br><br>&raquo;<A HREF="/forum/r20168287-10-Largest-Data-Breaches-Since-2000-Millions-Affected">10 Largest Data Breaches Since 2000 - Millions Affected</A><br><br>Where there is a will, there is a way.<br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20202865</guid>
<pubDate>Fri, 21 Mar 2008 14:25:01 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20202621</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : <div class="bquote"><small>said by jim123 :</small><br><br>how do they get the card # ????<br> </div>That's the big question. This gang gets numbers for cards that are actively in use, used VERY infrequently and some that have never been used before. They also seem to submit a fairly high number of wrong numbers that get rejected, too, so their data is far from perfect.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20202621</guid>
<pubDate>Fri, 21 Mar 2008 13:45:47 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20200819</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : how do they get the card # ????]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20200819</guid>
<pubDate>Fri, 21 Mar 2008 06:11:17 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20187595</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : <div class="bquote"><small>said by deanhuff :</small><br><br>I saw on the news that a local grocer called Sweetbay had a security breach and gave out a bunch of card numbers.  Sure enough, I had 1 Sweetbay transaction in early December.<br> </div>It was their parent company "Hannaford", which Sweetbay Supermarkets is one of their stores, but I do believe many of their other chains are affected as well.<br><small>--<br><A HREF="http://pcdebbhealth.blogspot.com/">a time for change...</a> | <A HREF="http://www.dslreports.com/forum/sports">1st & 10</a> | <A HREF="http://www.dslreports.com/forum/hamradio">Ham is good</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187595</guid>
<pubDate>Tue, 18 Mar 2008 21:07:39 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20187112</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : MGD,<br><br>And stockimageplanet.com   <br><br>Support: Alex McGuire <br>e-mail: support@stockimageplanet.com <br>tel: (941) 312-2230]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187112</guid>
<pubDate>Tue, 18 Mar 2008 19:40:29 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20187083</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : MGD,<br><br>Please add stockimagemix.com to the database.  Another one with the exact same home page... unbelievable.  Same bogus support name of Alex McGuire, etc.  <br><br>Support: Alex McGuire <br>e-mail: support@stockimagemix.com <br>tel: (561) 283-4229 ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187083</guid>
<pubDate>Tue, 18 Mar 2008 19:36:02 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20186137</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Add another for MICHAEL P HAMILTON $9.64 on 03/15/2008.  Bank of America gave me a new account number and re-imbursed the money.<br><br>I also had another charge for around $3 from "M BAR C RANCH" in Pending state but never posted.<br><br>I saw on the news that a local grocer called Sweetbay had a security breach and gave out a bunch of card numbers.  Sure enough, I had 1 Sweetbay transaction in early December.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20186137</guid>
<pubDate>Tue, 18 Mar 2008 16:28:52 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20183831</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : A charge of $9.64 from a Michael P Hamilton in Maryland (213-984-4966) posted to my Chase on 3-14-08.  A foreign voice recording, gave an indiscernible .com name, not Hamilton, not prophotoland, etc.  Sounds like "time share" but is indiscernible.  I see $9.64 has been used on previous attacks. Chase described Hamilton as an Art Dealer, but said they would do the charge back.  They did not want to close/replace the card. So I asked the rep to clearly state for their recording that they were declining to close the account for fraud. They said they will investigate. I'll monitor the account daily. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20183831</guid>
<pubDate>Tue, 18 Mar 2008 12:09:00 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20175189</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Looks like photosmix.com and prophotosland.com are back up and running so beware... their site states "Our hosting provider has accidently delegated our domain to a different company... "  not sure what this means as they still have the same GoDaddy logo.  GoDaddy may have received enough abuse complaints that they made them change something... but obviously they are still operational.  Perhaps MGD, you will know what this means.<br><br>I am guessing there will be another round of charges in the next few weeks...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20175189</guid>
<pubDate>Sun, 16 Mar 2008 17:57:12 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20172325</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Chalk me up for Photogeyser.com.  Glad I stumbled on this forum.  Going to call my bank and have a new card issued.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20172325</guid>
<pubDate>Sun, 16 Mar 2008 00:47:14 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20163903</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Hi MGD,<br><br>It was a small credit union as you guessed and believe me, I will be talking to someone pretty high up about their policy.  I will most likely also close the account as I have not been happy with their response.  <br><br>Thanks for all of your work on this!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20163903</guid>
<pubDate>Fri, 14 Mar 2008 11:05:52 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20163056</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>add www.photosmix.com to your database.  Phone 941-312-2213 out of Florida.  Same visuals/text as photogeyser and prophotosland.com.  Alex McGuire is also the contact on this one.  Just looks like a different version. <br> </div><b>www.photosmix.com</b><br><div class="borderless siteshot"><small>Snapped 2008-03-14 07:08:24 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/79/71079.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/79/71079.gif"></A><br>&raquo;<A HREF="http://www.photosmix.com" >www.photosmix.com</A></small></div><br><br>&raquo;<A HREF="http://www.photosmix.com/robots.txt" >www.photosmix.com/robots.txt</A><br><pre><br>User-agent: *<br>Disallow:<br></pre><br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20163056</guid>
<pubDate>Fri, 14 Mar 2008 07:24:41 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20162854</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : GLOSSYELDORADO.COM<br><br>[att=1]<br><br>A new twist on the search engine blocking, specifically line items Google:<br><br>[att=2]<br><br>No contact phone number, only the made up name Cristian Darrie.<br><br>And a familiar bogus GoDaddy domain registation, and GoDaddy hosting:<br><br>Registrant:<br>HAITAO ZHANG<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br><br>Registered through: GoDaddy.com, Inc. <br>Domain Name: GLOSSYELDORADO.COM<br>Created on: 15-Feb-08<br>Expires on: 15-Feb-09<br>Last Updated on: 15-Feb-08<br><br>Administrative Contact:<br>ZHANG, HAITAO haitao.zhang44@yahoo.com<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br>85281980611<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20162854?c=1286371&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="665866 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/1286371.thumb600~0da2613ed49a3142cf898a31396d1eeb/glossyeldorado_main.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20162854?c=1286372&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG TITLE="3207 bytes" BORDER=0 WIDTH=348 HEIGHT=166 SRC="/r0/download/1286372~39d65af1d11b17dd295b7ff95e7448f1/Glossyeldorado_robots.png"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20162854</guid>
<pubDate>Fri, 14 Mar 2008 04:06:00 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20162812</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Another one to watch out for... www.glossyeldorado.com.  Gotta love that name :)<br><br>MGD... please add to the db! ..............</div>Done !!<br><br><div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>.......The most annoying thing for me is that my credit card company charged me $10.00 for a new card... to make sure the $9.87 doesn't turn into a recurring charge I am made to pay $10.00.  I will be cancelling that card.  <br> </div>That is unbelievable !!<br><br>You are actually saving them money by telling them to cancel and reissue the card. You are not liable for fraudulent charges, it becomes their problem. The alternative is to allow these criminals to hit the card with new charges every two weeks, and let the Bank deal with them. Until such time as they catch on, and decide to re issue it at their own expense.<br><br>If this is a National or large Regional Bank, please name them. The only possibility that I am thinking of, is that they are a small credit union or something. Either way it is ridiculous to charge a customer, who through no fault of their own, becomes the victim of card fraud. I am not even sure that it is legal under Federal Law to do so. I could see it if you had lost the card, or otherwise contributed to the problem. Just on principle alone I would raise all kinds of commotion with that institution. It has to be a small non profit credit union or something, correct?. If not, they via their CSR are entirely clueless. They just don't get it.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20162812</guid>
<pubDate>Fri, 14 Mar 2008 03:21:14 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20154841</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Another one to watch out for... www.glossyeldorado.com.  Gotta love that name :)<br><br>MGD... please add to the db!<br><br>There are other sites that talk about this scam:<br><br>&raquo;<A HREF="http://www.ripoffreport.com/reports/0/316/RipOff0316667.htm" >www.ripoffreport.com/reports/0/3&middot;&middot;&middot;6667.htm</A><br><br>The most annoying thing for me is that my credit card company charged me $10.00 for a new card... to make sure the $9.87 doesn't turn into a recurring charge I am made to pay $10.00.  I will be cancelling that card.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20154841</guid>
<pubDate>Wed, 12 Mar 2008 19:06:44 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20128229</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Add one more to the photosmix.com scam.  Showed up on our bill today.  Hope all who get this report it as a fraud-- these folks need to be stopped.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20128229</guid>
<pubDate>Fri, 07 Mar 2008 20:30:46 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20127259</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hi MGD,<br><br>Please also add www.photosmix.com to your database.  Phone 941-312-2213 out of Florida.  ..... </div>Yes indeed, good find. They are confirmed as a fraud operation. Also had the robots.txt no follow search block. As a matter of fact, the site went down while I was checking it. Not sure why, or if it will stay down. Many of these set ups are paid for with hijacked card data. GoDaddy needs to get with program and put a stop to this fraud hosting and domain registration cloaking.<br><br>The names on the sites, such as Alex McGuire are boogus.<br><br><div class="bquote">[photosmix.com IP 72.167.110.64]<br><br>Registrant:PHOTOSMIX.COM<br>Domains by Proxy, Inc.<br><br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br><br>Registered through: GoDaddy.com, Inc.<br>Domain Name: PHOTOSMIX.COM<br>Created on: 17-Dec-07<br>Expires on: 18-Dec-08<br>Last Updated on: 17-Dec-07<br><br>Administrative Contact:<br>Private, Registration PHOTOSMIX.COM@domainsbyproxy.com<br>Domains by Proxy, Inc.<br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br>(480) 624-2599 Fax -- (480) 624-2599<br><br>Domain servers in listed order:<br>NS19.DOMAINCONTROL.COM<br>NS20.DOMAINCONTROL.COM<br></div>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20127259</guid>
<pubDate>Fri, 07 Mar 2008 17:29:05 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20126985</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : add me to the www.photosmix.com scam. Will proceed as stated in this thread. Thanks for the very complete info on this fraud.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20126985</guid>
<pubDate>Fri, 07 Mar 2008 16:37:11 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20124501</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : www.photosmix.com happened to me as well.  I've filed a complaint with the fraud department of my bank, used the government website listed above, and e-mailed the abuse@godaddy.com website, as they are the host for this website (their "secure site" logo is at the bottom left).  I may even go file a complaint with the local police department today, and even go so far as contacting the better business bureau.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20124501</guid>
<pubDate>Fri, 07 Mar 2008 09:03:07 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20121858</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hi MGD,<br><br>Please also add www.photosmix.com to your database.  Phone 941-312-2213 out of Florida.  Same visuals/text as photogeyser and prophotosland.com.  Alex McGuire is also the contact on this one.  Just looks like a different version. <br> </div>Same thing happened to me, a charge was listed on my account for $9.87 from www.photosmix.com. Did you ever get through to the phone number listed on the website? After reading this forum, I called once and didn't bother trying again, and called my bank instead. They reimbursed me but it's kind of a hassle now that I have do the paperwork to file it as a fraudulent charge and everything... and I also have to wait for a new card in the mail...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20121858</guid>
<pubDate>Thu, 06 Mar 2008 19:19:27 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20085751</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Hi MGD,<br><br>Please also add www.photosmix.com to your database.  Phone 941-312-2213 out of Florida.  Same visuals/text as photogeyser and prophotosland.com.  Alex McGuire is also the contact on this one.  Just looks like a different version. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20085751</guid>
<pubDate>Fri, 29 Feb 2008 17:52:50 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20075928</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  jswanson <A HREF="/useremail/u/1532053"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>This is the same small charge $9.87 credit card fraud scheme posted on other threads although I have not yet seen these two sites specifically mentioned.  <br> .......</div>Oh Excellent, thank you for Heads Up!!<br><br>And lets continue with  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s digging.  pcdebb <A HREF="/useremail/u/254898"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> is indeed correct, into the data base they go.<br><br>I can confirm positively that these are the next round of "Globus" fraud sites from  Doctor Olds <A HREF="/useremail/u/372021"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s thread: &raquo;<A HREF="/forum/r19881855-pictureglobuscom-imaglobuscom-and-templateglobuscom-now">pictureglobus.com, imaglobus.com, and templateglobus.com now</A><br><br>I need to see if anyone who is a slickdeals member can either IM or post to this thread: &raquo;<A HREF="http://forums.slickdeals.net/showthread.php?t=694416&page=16&highlight=picturesjungle.com" >forums.slickdeals.net/showthread&middot;&middot;&middot;ngle.com</A><br><br>The poster "Minette" may have some valuable info I need. They got charged $9.87 by PROPHOTOSLAND.COM on 1/27 and subsequently got hit by according to them:<br><br><i>"a company called "Alkay Services LLC", this time on ANOTHER credit card I own, for the amount of $9.64. Same business (photo) according to my bank (Chase).</i><br><br>I need the phone number that may have been listed on the line item charge, or at least part of it. if it was not listed on the charge the card issuer should be able to give it to them. If anyone else has a "Alkay Services LLC" charge and has or can get the number. This group is also using the same deflecting tactic as the globus group, by telling victims someone registered on the site with their car. More than likely any victim who bought that lie and got a credit will have been hit with a second charge the next month. Any subsequent second hit names and full info is vital in following the trail.<br><br>The C&C website for the Globus was the bogus "Hermes Electro" hermeselectro.com: &raquo;<A HREF="http://hermeselectro.com" >hermeselectro.com</A> pretending to be in Hong Kong:<br><br>[att=4][att=1]<br><br>The C&C for this picture, image, photo, fraud group is a bogus site "Hong-Kong Content Trade", hkc-trade.com: &raquo;<A HREF="http://hkc-trade.com/" >hkc-trade.com/</A><br><br>A direct clone of the other one:<br><br>[att=2][att=3]<br><br>There are no records that indicate a business by those names exist at either of those addresses.<br><br>Need to add picturesjungle.com &raquo;<A HREF="http://www.picturesjungle.com/index.php?action=contact" >www.picturesjungle.com/index.php&middot;&middot;&middot;=contact</A> to the list also.<br><br>I am off the belief that the names listed on the sites such as Eric Robertson, also of Globus fame, and Cristian Darie etc. are all fictitious. Having spent countless hours checking LLCs' and corp registrations in the state of Texas, including multiple county FBN lists, I do not believe they exist. At least until something substantial comes up to indicate otherwise.<br><br>You will notice from the added info to the sites listed above, that not only are the current crop using GoDaddy hosting, so were the Globus group.<br><br>I am not sure if it was posted, but one of the early victims of the Globus run, was told by GoDaddy that they would not shut them down without legal action. I will try and find a copy.<br><br>This group probably represents one of the most egregious lack of due care by a hosting company. Providing these criminals with a conduit, which enables them access to payment gateways allowing them to fraudulently process thousands of credit cards is unbelievable.<br><br>Lets just look at the worst case:<br><br>We have hosting provided to supposed e-commerce sites, where one can readily see from the robots.txt file, that no one could even find them. Plus their domain registration is cloaked, hidden. The only information published is a bogus name, and a cell phone contact number.<br><br>Now we are seeing supposed e-commerce sites registered to bogus locations in Hong Kong, and they are using contact phone numbers in various US states. The entire set up configuration reeks of fraud, a four year old could spot it, before the first charge ever hit.<br><br><div class="bquote">http://www.polishpicturesonline.com/index.php?action=contact<br>Support: Cristian Darie<br>e-mail: support@polishpicturesonline.com<br>tel: 214-556-6190   no scam reports <br><br>214-556-6190 Type: Land Line<br>Provider: MCI Worldcom Communications Inc<br>Location: Plano, TX<br><br>Registered through: GoDaddy.com, Inc.<br>Domain Name: POLISHPICTURESONLINE.COM<br>Created on: 30-Dec-07<br>Expires on: 30-Dec-09<br>Last Updated on: 30-Dec-07<br><br>Administrative Contact:<br>ZHANG, HAITAO support@hkc-trade.com<br>Honk-Kong Content Trade Company<br>426 King's Road<br>North Point, N/A 000000<br>Hong Kong<br>85281980664<br><br>Domain servers in listed order:<br>NS19.DOMAINCONTROL.COM<br>NS20.DOMAINCONTROL.COM<br><br>&raquo;<A HREF="http://www.prophotosland.com/index.php?action=contact" >www.prophotosland.com/index.php?&middot;&middot;&middot;=contact</A><br>Support: Alex McGuire<br>e-mail: support@prophotosland.com<br>tel: 609-916-0040<br><br>(609) 916-0040 Type: Land Line<br>Provider: Focal Communications Corp<br>Location: Pleasantville, NJ<br><br>PROPHOTOSLAND.COM<br><br>Registrant:<br>Domains by Proxy, Inc.<br><br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br><br>Registered through: GoDaddy.com, Inc. <br>Domain Name: PROPHOTOSLAND.COM<br>Created on: 05-Dec-07<br>Expires on: 05-Dec-08<br>Last Updated on: 05-Dec-07<br><br>Domain servers in listed order:<br>      NS15.DOMAINCONTROL.COM<br>      NS16.DOMAINCONTROL.COM<br><br>&raquo;<A HREF="http://www.imagesparadise.com/index.php?action=contact" >www.imagesparadise.com/index.php&middot;&middot;&middot;=contact</A><br>Support: Cristian Darie <br>e-mail: support@imagesparadise.com <br>tel: 214-556-6153 <br><br>(214) 556-6153 Type: Land Line<br>Provider: MCI Worldcom Communications Inc<br>Location: Plano, TX<br><br>Registered through: GoDaddy.com, Inc.<br>Domain Name: IMAGESPARADISE.COM<br>Created on: 07-Feb-08<br>Expires on: 07-Feb-09<br>Last Updated on: 07-Feb-08<br><br>Administrative Contact:<br>ZHANG, HAITAO haitao.zhang44@yahoo.com<br>426 King's Road<br>Hong Kong, North Point --<br>Hong Kong<br>85281980623<br><br>Domain servers in listed order:<br>NS23.DOMAINCONTROL.COM<br>NS24.DOMAINCONTROL.COM<br><br>&raquo;<A HREF="http://www.photogeyser.com/index.php?action=contact" >www.photogeyser.com/index.php?action=contact</A><br>Support: Eric Robertson<br>e-mail: support@photogeyser.com<br>tel: (301) 979-9960<br><br>(301) 979-9960Type: Land Line<br>Provider: Verizon<br>Location: Washington, MD<br><br>PHOTOGEYSER.COM<br>Registrant:<br>Domains by Proxy, Inc.<br><br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br><br>Registered through: GoDaddy.com, Inc. <br>Domain Name: PHOTOGEYSER.COM<br>Created on: 14-Nov-07<br>Expires on: 14-Nov-08<br>Last Updated on: 14-Nov-07<br><br>Domain servers in listed order:<br>      NS15.DOMAINCONTROL.COM<br>      NS16.DOMAINCONTROL.COM<br><br>&raquo;<A HREF="http://www.picturesjungle.com/index.php?action=contact" >www.picturesjungle.com/index.php&middot;&middot;&middot;=contact</A><br>Support: Alex McGuire <br>e-mail: support@picturesjungle.com <br>tel: (706) 955-4677<br><br>(706) 955-4677Type: Land Line<br>Provider: Level 3 Communications<br>Location: Augusta, GA<br><br>PICTURESJUNGLE.COM<br>Registrant:<br>Domains by Proxy, Inc.<br><br>DomainsByProxy.com<br>15111 N. Hayden Rd., Ste 160, PMB 353<br>Scottsdale, Arizona 85260<br>United States<br><br>Registered through: GoDaddy.com, Inc.<br>Domain Name: PICTURESJUNGLE.COM<br>Created on: 27-Nov-07<br>Expires on: 27-Nov-08<br>Last Updated on: 27-Nov-07<br><br>Domain servers in listed order:<br>NS27.DOMAINCONTROL.COM<br>NS28.DOMAINCONTROL.COM<br><br>HKC-TRADE.COM<br>Registrant:<br>HKC Trade Co.<br><br>426 King's Road<br>Honk Kong, North Point -<br>Hong Kong<br><br>Registered through: GoDaddy.com, Inc.<br>Domain Name: HKC-TRADE.COM<br>Created on: 28-Nov-07<br>Expires on: 29-Nov-08<br>Last Updated on: 28-Nov-07<br><br>Administrative Contact:<br>ZHANG, HAITAO haitao.zhang44@yahoo.com<br>HKC Trade Co.<br>426 King's Road<br>Honk Kong, North Point -<br>Hong Kong<br>+852 2562 8127<br><br>Domain servers in listed order:<br>NS27.DOMAINCONTROL.COM<br>NS28.DOMAINCONTROL.COM<br></div>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20075928?c=1280304&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="180987 bytes" WIDTH=600 HEIGHT=623 SRC="/r0/download/1280304.thumb600~50e39ed20e77892dca23af362a82c210/Hermes_electro_contact.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20075928?c=1280305&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="297272 bytes" WIDTH=600 HEIGHT=630 SRC="/r0/download/1280305.thumb600~b12d5fcbdc44015d849a6f45bb2e0150/hkc-trade_main.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20075928?c=1280306&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="168510 bytes" WIDTH=600 HEIGHT=628 SRC="/r0/download/1280306.thumb600~561351af28deb993f6a2b3cdc42d5cad/hkc-trade_contact.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20075928?c=1280309&ret=L2ZvcnVtL3IyMDA1NTk3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="257717 bytes" WIDTH=600 HEIGHT=604 SRC="/r0/download/1280309.thumb600~45574565fa806d8b0f1c01e43bc218db/Hermes_electro_main.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20075928</guid>
<pubDate>Thu, 28 Feb 2008 05:52:22 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20071341</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This just happened to me with prophotosland - I contacted my credit card's fraud dept. and filed a complaint.<br><br>The weird thing is that they were telling me that that charge was from a local mall (which I have not shopped at in weeks and at which there is no such store) and that my card was swiped (I had my card with me). <br><br>Card closed, charge replaced, but am curious about how it came up as a local charge with my card swiped...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20071341</guid>
<pubDate>Wed, 27 Feb 2008 13:00:18 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20071174</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This has happened to me recently.  I will go to that web site asap.  also this must be wide spread.  It looks like the credit card companys would pick up on this.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20071174</guid>
<pubDate>Wed, 27 Feb 2008 12:33:56 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20070859</link>
<description><![CDATA[<A HREF="/useremail/u/397739"><b>fireflier</b></A> : Interesting that the name "Jupiter, LLC" is shown there.  Wasn't the name jupiter involved in some other less recent CC charging scams?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20070859</guid>
<pubDate>Wed, 27 Feb 2008 11:37:43 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20056859</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : And this oddball one.<br><br><b>www.zenithgraphic.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-25 02:54:57 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/38/69238.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/38/69238.gif"></A><br>&raquo;<A HREF="http://www.zenithgraphic.com/" >www.zenithgraphic.com/</A></small></div><br><br>&raquo;<A HREF="http://www.zenithgraphic.com/cookies.txt" >www.zenithgraphic.com/cookies.txt</A><br><pre><br>Page Not Found<br></pre><br><br>&raquo;<small>https</small>://<A HREF="https://www.zenithgraphic.com/index.php?action=contact">www.zenithgraphic.com/index.php?&middot;&middot;&middot;=contact</A><br>Support: Alex McGuire<br>e-mail: support@zenithgraphic.com<br>tel: (504) 208-4860<br><br>General: Edris Hoover<br>info@zenithgraphic.com<br>tel: (505) 350-8506<br><br>Jupiter, LLC<br>8210 Robin Ave NE<br>Albuquerque, NM 87110<br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20056859</guid>
<pubDate>Mon, 25 Feb 2008 02:55:09 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20056464</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : And another....<br><br><b>www.imgparadise.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-25 00:11:46 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/29/69229.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/29/69229.gif"></A><br>&raquo;<A HREF="http://www.imgparadise.com/" >www.imgparadise.com/</A></small></div><br><br>&raquo;<A HREF="http://www.imgparadise.com/robots.txt" >www.imgparadise.com/robots.txt</A><br><pre><br>Page Not Found<br></pre><br><br>&raquo;<small>https</small>://<A HREF="https://www.imgparadise.com/index.php?action=contact">www.imgparadise.com/index.php?action=contact</A><br>Support: Cristian Darie<br>e-mail: support@imgparadise.com<br>tel: (213) 984-4966 <br><br>Cute. NOT!<br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20056464</guid>
<pubDate>Mon, 25 Feb 2008 00:13:05 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20056423</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : Found another one:<br><br><b>www.photosparadise.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-25 00:02:59 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/28/69228.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/28/69228.gif"></A><br>&raquo;<A HREF="http://www.photosparadise.com/" >www.photosparadise.com/</A></small></div><br><br>&raquo;<A HREF="http://www.photosparadise.com/robots.txt" >www.photosparadise.com/robots.txt</A><br><pre><br>Page Not Found<br></pre><br><br>&raquo;<small>https</small>://<A HREF="https://www.photosparadise.com/index.php?action=contact">www.photosparadise.com/index.php&middot;&middot;&middot;=contact</A><br>Support: Cristian Darie<br>e-mail: support@photosparadise.com<br>tel: (214) 556-6153 <br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20056423</guid>
<pubDate>Mon, 25 Feb 2008 00:03:34 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20055975</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> :  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> should probably add these to the list  :huh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20055975</guid>
<pubDate>Sun, 24 Feb 2008 22:23:51 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20055914</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : <b>www.imagesparadise.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-24 21:52:03 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/24/69224.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/24/69224.gif"></A><br>&raquo;<A HREF="http://www.imagesparadise.com/" >www.imagesparadise.com/</A></small></div><br><br>&raquo;<A HREF="http://www.imagesparadise.com/robots.txt" >www.imagesparadise.com/robots.txt</A><br><pre><br>Page Not Found<br></pre><br><br>&raquo;<small>https</small>://<A HREF="https://www.imagesparadise.com/index.php?action=contact">www.imagesparadise.com/index.php&middot;&middot;&middot;=contact</A><br>Support: Cristian Darie<br>e-mail: support@imagesparadise.com<br>tel: (214) 556-6153 <br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20055914</guid>
<pubDate>Sun, 24 Feb 2008 22:13:37 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20055625</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Another one is popping up with similar text... home page is different but text and some photos are the same:<br><br>&raquo;<A HREF="http://imagesparadise.com/" >imagesparadise.com/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20055625</guid>
<pubDate>Sun, 24 Feb 2008 21:04:47 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20054795</link>
<description><![CDATA[<A HREF="/useremail/u/372021"><b>Doctor Olds</b></A> : Two are hidden by their robots.txt contents and the last one doesn't have a robots.txt file at all.<br><br><hr><br><br><b>www.prophotosland.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-24 17:38:38 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/11/69211.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/11/69211.gif"></A><br>&raquo;<A HREF="http://www.prophotosland.com/" >www.prophotosland.com/</A></small></div><br><br>&raquo;<A HREF="http://www.prophotosland.com/robots.txt" >www.prophotosland.com/robots.txt</A><br><pre><br>User-agent: *<br>Disallow: /<br></pre><br><hr><br><br><b>www.photogeyser.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-24 17:38:20 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/12/69212.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/12/69212.gif"></A><br>&raquo;<A HREF="http://www.photogeyser.com/" >www.photogeyser.com/</A></small></div><br><br>&raquo;<A HREF="http://www.photogeyser.com/robots.txt" >www.photogeyser.com/robots.txt</A><br><pre><br>User-agent: *<br>Disallow: /<br></pre><br><hr><br><br><b>www.polishpicturesonline.com</b><br><br><div class="borderless siteshot"><small>Snapped 2008-02-24 17:37:57 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br><A TITLE="Zoom" HREF="http://i.dslr.net/urls/13/69213.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/13/69213.gif"></A><br>&raquo;<A HREF="http://www.polishpicturesonline.com/" >www.polishpicturesonline.com/</A></small></div><br><br>&raquo;<A HREF="http://www.polishpicturesonline.com/robots.txt" >www.polishpicturesonline.com/robots.txt</A><br><pre><br>Page Not Found<br></pre><br><hr><br><br>Intereresting also is that the Contacts from each site are different.  With a name or two from another group of scam-front sites. :[<br><br>&raquo;<small>https</small>://<A HREF="https://www.prophotosland.com/index.php?action=contact">www.prophotosland.com/index.php?&middot;&middot;&middot;=contact</A><br>Support: Alex McGuire<br>e-mail: support@prophotosland.com<br>tel: (609) 916-0040 <br><br>&raquo;<small>https</small>://<A HREF="https://www.photogeyser.com/index.php?action=contact">www.photogeyser.com/index.php?action=contact</A><br>Support: Eric Robertson<br>e-mail: support@photogeyser.com<br>tel: (301) 979-9960<br> <br>&raquo;<small>https</small>://<A HREF="https://www.polishpicturesonline.com/index.php?action=contact">www.polishpicturesonline.com/ind&middot;&middot;&middot;=contact</A><br>Support: Cristian Darie<br>e-mail: support@polishpicturesonline.com<br>tel: (214) 556-6190 <br><br>Strange...<br><br>Regards,<br><br>Doctor Olds<br><br><small>--<br><A HREF="http://tinyurl.com/ylb8u9">What&#146;s the point of owning a supercar if you can&#146;t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20054795</guid>
<pubDate>Sun, 24 Feb 2008 17:49:05 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20054575</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Another site in this network just popped up... <br><br>&raquo;<A HREF="http://polishpicturesonline.com/" >polishpicturesonline.com/</A><br><br>they use the same exact pictures and text as the other two... watch out for this one... looks like it has been live for a little over a week.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20054575</guid>
<pubDate>Sun, 24 Feb 2008 17:01:11 EDT</pubDate>
</item>

<item>
<title>Re: [Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.phot</title>
<link>http://www.dslreports.com/forum/remark,20053984</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : Sorry - other site name was cut off... it was<br><br>www.photogeyser.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20053984</guid>
<pubDate>Sun, 24 Feb 2008 14:46:12 EDT</pubDate>
</item>

<item>
<title>[Credit Card Fraud] fraud:  www.prophotosland.com &#x26; www.photogey</title>
<link>http://www.dslreports.com/forum/remark,20053977</link>
<description><![CDATA[<A HREF="/useremail/u/1532053"><b>jswanson</b></A> : This is the same small charge $9.87 credit card fraud scheme posted on other threads although I have not yet seen these two sites specifically mentioned.  If you see a small charge from either of these companies please:<br><br>1.  Report the FRAUD to your credit card company, do not just dispute the charge - state that it is FRAUD and insist on a chargeback.  Get a new credit card # and close the old account.<br><br>2. Report the fraud to www.ic3.gov with as much detail as possible<br><br>3.  DO NOT attempt to contact the company as they will reverse the charges but may charge you again next month.  They would rather refund your money then be investigated for fraud.  HOWEVER, if you want to help stop them work through ic3.gov and your credit card FRAUD division.<br><br>4.  Check your credit card statements carefully every month.<br><br>There are many forums out there regarding this topic... all you need to do is search on small charge credit card fraud or even 9.87 charge credit card fraud.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20053977</guid>
<pubDate>Sun, 24 Feb 2008 14:45:05 EDT</pubDate>
</item>

</channel>
</rss>
