This cluster centers on 2451 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include cdn.discordapp.com, 91.92.241.152, 91.92.240.222, 158.94.208.174, 178.16.52.44, 158.94.211.102, 158.94.210.93, 158.94.208.52, i.postimg.cc, s3.us-east-2.amazonaws.com, storage.googleapis.com, 178.16.52.18, 158.94.211.101, 158.94.211.100, local-host.life, dropmefiles.com, limewire.com, 62.60.226.159, id8965.com, valfanto.com and 2431 more. 633 of these domains have been flagged by threat int...
480-624-2599
Last reported Apr 18, 2026
- 5 community reports from users
Campaign Intelligence
Based on consumer protection data, we have identified a multi-faceted scam campaign operating through a network of three interconnected phone numbers: 3026184094, 8772313109, and 4806242599. These numbers are connected through same-campaign relationships with 0.70 confidence scores, indicating coordinated fraudulent activity. The campaign also involves the domain cartpanda.com.de and has been reported together with ACCOUNT SERVICES INC., a debt collection company that has received 8 CFPB complai...
This cluster centers on 1486 connected domains tagged as AgentTesla, None, js. The domains include i.postimg.cc, cdn.discordapp.com, s3.us-east-2.amazonaws.com, pastes.io, dl.dropboxusercontent.com, ltcexchange.bitparking.com, bitcoin.sipa.be, litecoinpool.org, cryptocoincharts.com, sigaintevyh2rzvw.onion, toremail.net, lelantos.org, www.sigaint.org, epjhlyfgxenf2q4o.onion~~, inocncymyac2mufx.onion, torbox3uiot6wchz.onion, 344c6kbnjnljjzlz.onion, mailtor.net, bscscan.com, securitized.io and 1466...
This cluster centers on 2559 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 83.224.148.34, 14.236.247.68, 120.157.72.59, 95.127.248.192, 116.110.179.199, 116.101.73.68, 95.127.250.241, 152.173.199.182, 91.80.129.100, 59.88.45.188, 117.216.5.20, 182.60.11.164, 41.146.14.165, 120.157.46.38, 59.182.90.199, 113.168.249.76, 78.132.114.25, 171.241.208.124, 120.157.229.220, 14.236.84.25 and 2539 more. 640 of these domains have been flagged by threat intelligence feeds inc...
This cybersecurity analysis reveals a coordinated debt collection scam campaign operating through a network of five interconnected phone numbers: 4806242599, 3072268326, 2133170966, 8776840410, and 8883809079. Despite none of these numbers having recorded FTC complaints, they are connected through shared campaign infrastructure with a confidence level of 0.70. The operation appears to leverage legitimate debt collection companies as cover, with ACCOUNT SERVICES INC. (8 CFPB complaints) being rep...
This cybersecurity analysis examines a coordinated debt collection campaign involving multiple phone numbers and domains connected to Account Services Inc., which has generated 8 CFPB complaints. The campaign utilizes three phone numbers operating in coordination: 844-908-0235, 315-307-7951, and 480-624-2599, all linked through same-campaign relationships with 0.70 confidence levels. These numbers work in conjunction with two domains, pay-hh.com and hhcollect.co, which show a strong reported-tog...
Details
Linked Company Activity
Connected Entities
Linked Companies
PENTAGON FEDERAL CREDIT UNION
campaign co-membercompanyFIFTH THIRD FINANCIAL CORPORATION
campaign co-membercompanyCredit Services Corporation, LLC
campaign co-membercompanyIntegrity Group Inc
campaign co-membercompanyDirect, Inc
campaign co-membercompanyThe Bureaus, Inc.
campaign co-membercompanyEVERBANK, NATIONAL ASSOCIATION
campaign co-membercompanyTime Investment Corporation
campaign co-membercompanyCheckr, Inc
campaign co-membercompanyMOUNTAIN AMERICA FEDERAL CREDIT UNION
campaign co-membercompanyFuture Financial Inc.
campaign co-membercompanyReady Capital Corporation
campaign co-memberRelated Phone Numbers
8553572202
campaign co-memberphone8667715844
campaign co-memberphone8339086865
campaign co-memberphone8009220204
campaign co-memberphone4097617631
campaign co-memberphone6789998212
campaign co-memberphone6512042449
campaign co-memberphone5187704680
campaign co-memberphone8887291403
campaign co-memberphone8889194623
campaign co-memberphone9805107108
campaign co-memberphone7712473445
campaign co-memberphone5858247925
campaign co-memberphone8009993355
campaign co-memberphone8007715361
campaign co-memberphone8009033637
campaign co-memberphone2025582508
campaign co-memberphone9297499563
campaign co-memberphone8887910954
campaign co-memberphone8334471291
campaign co-memberphone7656119812
campaign co-memberphone8669591188
campaign co-memberphone8442446363
campaign co-memberphone3473635189
campaign co-memberRelated Domains
130.12.180.43
campaign co-memberdomainimplementing-theft-metal-justin.trycloudflare.com
campaign co-memberdomainstaying-heavily-meaning-blowing.trycloudflare.com
campaign co-memberdomaincreations-venture-traditional-stainless.trycloudflare.com
campaign co-memberdomain103.125.219.204
campaign co-memberdomain206.123.145.26
campaign co-memberdomainarilprivate.storexyz.web.id
campaign co-memberdomain14.236.182.73
campaign co-memberdomain83.224.162.132
campaign co-memberdomain123.31.81.229
campaign co-memberdomain120.157.56.105
campaign co-memberdomain113.176.132.141
campaign co-memberRelated Emails
cfjtfl@verxl.com
campaign co-memberemaildiana@ierek.com
campaign co-memberemailhr@teknfix.com
campaign co-memberemailcbx-df@ceszx.com
campaign co-memberemailj.thompson8822@ymail.com
campaign co-memberemailbb.adige@libero.it
campaign co-memberemailpangmyiuhk@yahoo.co.jp
campaign co-memberemailmarydavis09@zoho.com
campaign co-memberemailxxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grupoaldama.com.mx
campaign co-memberemaila4084163@trbvm.com
campaign co-memberemaillegalnotice@facebookmail.com
campaign co-memberemailleads@myhome.ie
campaign co-memberCommunity Reports
I ordered an iron supplement from a company called Nivara. The order was delayed several weeks despite the website saying orders are typically processed within a few business days in the U.S.. I requested my order to be cancelled after two weeks but was assured the product was on the way - that it was "held up in the factory due to a routine inspection." I informed my credit card company (AMEX) that I had not received the order and they credited my account. When I finally received my order several weeks later, I noticed the supplemental facts label advertised on the website is inaccurate and does not depict the actual supplemental label on the physical boxes. I requested to return the product and the company gave me a physical address which appears to be a residential home: Gabbieh Medrano 748 Hilton Ave, El Paso TX 79907 United States. AMEX informed me they have charged my account again after reconciliation with the company. I have an email out to Nivara now to confirm this address including questioning why it appears to be a residential home. I also Googled their website address location and was given the information of it being located in Arizona with a telephone number of 4806242599. This telephone number appears in searched and has numerous complaints about varying types of businesses. [BBB Scam Type: Online Purchase] [Business: Nivara] [Location: AR, USA - 72223]
I ordered a supposed well documented dental dog treat. Real science backed it up as I researched the product ingredients. I signed up for a subscription. The key ingredient is listed last out of 23. There is no company name or contact on the product bag. Internet research does not recognize this url. Whois shows this domain site and phone number to be a site of frequent scams since 1999. The name listed for this site is “Domains by Proxy”. Whois Information: Name Registration Private Organization Domains By Proxy, LLC Phone tel:+1.4806242599 Fax ? Email https://www.godaddy.com/whois/results.aspx?domain=mydoggies.com&action=contactDomainOwner Mailing Address DomainsByProxy.com 100 S. Mill Ave, Suite 1600, Tempe, Arizona, 85281 [BBB Scam Type: Online Purchase] [Business: My Doggies] [Location: CA, USA - 92054]
No contact was directly by the scammer, instead, an unknown charge appeared on a credit card statement. Research shows the GoDaddy account was established during October 2025, but that the telephone number, (480) 624-2599, has been used repeatedly since 1999 for various scammer accounts. GoDaddy Whois information states the business location to be listed as DomainsByProxy.com 100 S. Mill Ave, Suite 1600, Tempe, Arizona, 85281. Other detailed information about the website by GoDaddy at https://www.godaddy.com/whois/results.aspx?itc=dlp_domain_whois&domain=recovercharge.com [BBB Scam Type: Credit Cards] [Business: Recover Charges] [Location: AL, USA- 35806]
Unsolicited mail arrived at my rental house in my name. Strange as I have never lived at that address. There was visible in the clear window, a fake check made out in my name. My house is not for sale and public data was scraped to associate the house in my name. The address showed Southern Home Buyers, 340 B Monroe Ave, Memphis, TN 38105 with a Presorted Standard US Postage Paid Sacramento, CA Permit 1935. An internet search revealed the scam. southernusahomebuyers.com Technical Analysis Key Facts Domain age 5 months Company Data Organization Domains By Proxy, LLC Owner Registration Private Address DomainsByProxy.com, 100 S. Mill Ave, Suite 1600 State Arizona Country US E-mail https://www.godaddy.com/whois/results.aspx?domain=southernusahomebuyers.com&action=contactDomainOwner Telephone +1.4806242599 Website Data Website southernusahomebuyers.com SSL certificate valid 2025-08-20 SSL issuer GoDaddy.com, Inc. WHOIS registration date 2025-01-21 WHOIS last update date 2025-01-21 WHOIS renew date 2026-01-21 Owner Name Registration Private Organization Domains By Proxy, LLC Street DomainsByProxy.com, 100 S. Mill Ave, Suite 1600 State Arizona Country US Telephone +1.4806242599 [BBB Scam Type: Other] [Business: Southern USA Home Buyers 340 B Monroe Ave Memphis TN 38112] [Location: MS, USA- 38680]
An unsolicited postal mail arrived to my rental house in my name. I have never lived there. Public records associated me with that property address. A fake check made out in my name was visible in a clear window on the mail The Return address on the mail was Southern USA Home Buyers 340 B Monroe Ave Memphis TN 38105, An internet search revealed these facts of the scam running for 5 months registered in Arizona. southernusahomebuyers.com Technical Analysis Key Facts Domain age 5 months Company Data Organization Domains By Proxy, LLC Owner Registration Private Address DomainsByProxy.com, 100 S. Mill Ave, Suite 1600 State Arizona Country US E-mail https://www.godaddy.com/whois/results.aspx?domain=southernusahomebuyers.com&action=contactDomainOwner Telephone +1.4806242599 Website Data Website southernusahomebuyers.com SSL certificate valid 2025-08-20 SSL issuer GoDaddy.com, Inc. WHOIS registration date 2025-01-21 WHOIS last update date 2025-01-21 WHOIS renew date 2026-01-21 Owner Name Registration Private Organization Domains By Proxy, LLC Street DomainsByProxy.com, 100 S. Mill Ave, Suite 1600 State Arizona Country US Telephone +1.4806242599 [BBB Scam Type: Other] [Business: Southern USA Home Buyers] [Location: MS, USA- 38680]
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.