This cluster centers on 2382 connected domains tagged as PureHVNC, elf, sh. 572 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (8772427372, 1319641540, 1319641221) with 557 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2228 complaints with federal agencies. Geog...
lookup.icann.org
First seen Feb 24, 2026
- No SSL certificate
- 2 community reports from users
Campaign Intelligence
This cluster centers on 2396 connected domains tagged as 156-233-71-230, Quakbot, lnk. 586 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (8772427372, 1319641540, 1319641221) with 565 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2237 complaints with federal agen...
This cluster centers on 1895 connected domains tagged as BeaverTail, RedLineStealer, password: 2026. 113 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 934 phone numbers (8772427372, 1319641540, 1319641221) with 524 FTC complaints; 683 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2093 complaints wit...
This cluster centers on 2416 connected domains tagged as BABADEDA, WallStealer, meterpreter. 607 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (5086371451, 9366439335, 1842506726) with 570 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2243 complaints with federa...
This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
Details
Related Domains
No known connections to other entities yet.
Community Reports
I think I just single handedly took down a scam site, and you can too. [prochargebackcommission.com](https://prochargebackcommission.com) is the name of the scam site it was up a week ago. Specifically recovery scam. They also offered device hacking and social media hacking. I looked up the website on [https://lookup.icann.org/en/lookup](https://lookup.icann.org/en/lookup) and contacted their "abuse contact email" ​ **I'll share with you what I wrote.** On Tue, 30 May 2023 at 20:07, James wrote: This domain is being used for crypto scams. [https://prochargebackcommission.com/](https://prochargebackcommission.com/) ​ **Their response was:** On 5/31/2023 1:04 AM wrote: Dear James, Thank you for your email. Upon checking, the reported domain name isn't hosted on any of our servers. As such we do not have control over the files on the website. You can contact the hosting provider to assist in taking down the website. To get more information about the hosting provider https://digital.com/best-web-hosting/who-is/#search=prochargebackcommission.com If there has been a scam, please provide us with proof to investigate the report. Regards, **I was frustrated that they demanded proof. Then I remembered the computer laws regarding hacking being incredibly broad and that its a felony to attempt to hack, manipulate, or attempt any unauthorized use of any computer system and the jurisdiction extends to any American computer system like the social media accounts they offer to hack so I responded:** You are listed as the registrar, the the services they offer are violations of the Computer Fraud and Abuse Act and the Digital Millennium Copyright Act. Just because you are outside our jurisdiction does not mean you can freely attack American computer networks. **I checked back about three days later and the website is gone, at least to me it is. So anytime you come across a scam site try contact their abuse email a
How to tell if a site is a scam Hey I see posts multiple times a day if asking is "[meta-ass.crypto420fun.ml.tk.ru](https://meta-ass.crypto420fun.ml.tk.ru) a safe site to send my six figure cryptocurrency portfolio to? They are promising to double my money weekly?" I'll keep it simple, 4 questions ​ Is it less than 1 year old on [https://lookup.icann.org/en/lookup](https://lookup.icann.org/en/lookup)? Did someone you don't know in real life tell you about it? Are there no reviews of it online? Do they promise a return of greater than 40% annually? ​ If the answer is yes to any two of these questions it is very likely a scam site. ​ I also want to say that keeping your money in a crypto exchange is inherently risky. Major exchanges like Coinbase have failed before by losing all assets in a hack or having a liquidity collapse. I recommend using open source custodial wallets to hold funds and only use exchanges for the duration of the exchange. For bitcoin I use Bitcoin Core. This site can help you find one: [https://bitcoin.org/en/](https://bitcoin.org/en/) ​ If you're looking for an exchange/staking try the ones vetted by Forbes: [https://www.forbes.com/advisor/investing/cryptocurrency/best-crypto-exchanges/](https://www.forbes.com/advisor/investing/cryptocurrency/best-crypto-exchanges/) They even have staking platforms: [https://www.forbes.com/advisor/investing/cryptocurrency/best-crypto-staking-platforms/](https://www.forbes.com/advisor/investing/cryptocurrency/best-crypto-staking-platforms/) I believe this is the safest source possible even so you can still lose your money unless its held in a custodial wallet. Just remember to write down your seed phrase.
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
Proton Pass — Unique passwords for every account
After a breach, reused passwords let attackers into your other accounts. Proton Pass generates and stores a unique password for each one.