This cluster centers on 2451 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include cdn.discordapp.com, 91.92.241.152, 91.92.240.222, 158.94.208.174, 178.16.52.44, 158.94.211.102, 158.94.210.93, 158.94.208.52, i.postimg.cc, s3.us-east-2.amazonaws.com, storage.googleapis.com, 178.16.52.18, 158.94.211.101, 158.94.211.100, local-host.life, dropmefiles.com, limewire.com, 62.60.226.159, id8965.com, valfanto.com and 2431 more. 633 of these domains have been flagged by threat int...
782-590-2117
Last reported Mar 20, 2026
- 2 community reports from users
Campaign Intelligence
This cluster centers on 1486 connected domains tagged as AgentTesla, None, js. The domains include i.postimg.cc, cdn.discordapp.com, s3.us-east-2.amazonaws.com, pastes.io, dl.dropboxusercontent.com, ltcexchange.bitparking.com, bitcoin.sipa.be, litecoinpool.org, cryptocoincharts.com, sigaintevyh2rzvw.onion, toremail.net, lelantos.org, www.sigaint.org, epjhlyfgxenf2q4o.onion~~, inocncymyac2mufx.onion, torbox3uiot6wchz.onion, 344c6kbnjnljjzlz.onion, mailtor.net, bscscan.com, securitized.io and 1466...
This cluster centers on 2957 connected domains tagged as GuLoader, NorthKorea, censys. The domains include salelegalsteroids.com, 192.210.186.208, gharnt.com, cloflart.com, id3702579photo-image-docs.com, www.almacensantangel.com, 64.95.12.162, blue-oceans.net, sixmexicos.com, baritonclick.online, 185.252.24.15, un1rw11q4u.com, ameyiando.com, niril.sbs, bursaelektriktamir.com, blankeyeo.com, umxtxhub.za.com, sunchernical.com, 18.194.67.137, servecdn.my and 2937 more. 606 of these domains have bee...
This cluster centers on 2559 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 83.224.148.34, 14.236.247.68, 120.157.72.59, 95.127.248.192, 116.110.179.199, 116.101.73.68, 95.127.250.241, 152.173.199.182, 91.80.129.100, 59.88.45.188, 117.216.5.20, 182.60.11.164, 41.146.14.165, 120.157.46.38, 59.182.90.199, 113.168.249.76, 78.132.114.25, 171.241.208.124, 120.157.229.220, 14.236.84.25 and 2539 more. 640 of these domains have been flagged by threat intelligence feeds inc...
**Powerball Lottery Winner Scam Campaign Exploits Social Media and Payday Loan Company** A coordinated scam campaign has emerged involving three phone numbers operating under a false lottery winner scheme, with connections to The Money Company payday loan business and fraudulent YouTube video content. The core phone numbers in this operation are 2817076426, 7825902117, and 2133170966, all of which show same-campaign relationships with confidence levels of 0.70. Despite the coordinated nature of...
**Debt Collection and Payday Loan Scam Campaign Report** This cybersecurity investigation has identified a coordinated scam campaign operating through a network of 6 connected phone numbers and 2 companies involved in high-risk financial services. The campaign centers around Credit Corp Solutions Inc., a debt collection company with 2,734 CFPB complaints, and The Money Company, a payday loan operation with 2 CFPB complaints. The phone numbers involved are 323-237-8012, 855-776-2375, 888-707-054...
Details
Linked Company Activity
Connected Entities
Linked Companies
PENTAGON FEDERAL CREDIT UNION
campaign co-membercompanyFIFTH THIRD FINANCIAL CORPORATION
campaign co-membercompanyCredit Services Corporation, LLC
campaign co-membercompanyIntegrity Group Inc
campaign co-membercompanyDirect, Inc
campaign co-membercompanyThe Bureaus, Inc.
campaign co-membercompanyEVERBANK, NATIONAL ASSOCIATION
campaign co-membercompanyTime Investment Corporation
campaign co-membercompanyCheckr, Inc
campaign co-membercompanyMOUNTAIN AMERICA FEDERAL CREDIT UNION
campaign co-membercompanyFuture Financial Inc.
campaign co-membercompanyReady Capital Corporation
campaign co-memberRelated Phone Numbers
8553572202
campaign co-memberphone3186669555
campaign co-memberphone8667715844
campaign co-memberphone8339086865
campaign co-memberphone8009220204
campaign co-memberphone4097617631
campaign co-memberphone6789998212
campaign co-memberphone6512042449
campaign co-memberphone5187704680
campaign co-memberphone8887291403
campaign co-memberphone8889194623
campaign co-memberphone9805107108
campaign co-memberphone7712473445
campaign co-memberphone5858247925
campaign co-memberphone8009993355
campaign co-memberphone8007715361
campaign co-memberphone8009033637
campaign co-memberphone8884260179
campaign co-memberphone2025582508
campaign co-memberphone9297499563
campaign co-memberphone3025417253
campaign co-memberphone8887910954
campaign co-memberphone8334471291
campaign co-memberphone7656119812
campaign co-memberRelated Domains
130.12.180.43
campaign co-memberdomainimplementing-theft-metal-justin.trycloudflare.com
campaign co-memberdomainstaying-heavily-meaning-blowing.trycloudflare.com
campaign co-memberdomaincreations-venture-traditional-stainless.trycloudflare.com
campaign co-memberdomain103.125.219.204
campaign co-memberdomain206.123.145.26
campaign co-memberdomainarilprivate.storexyz.web.id
campaign co-memberdomain14.236.182.73
campaign co-memberdomain83.224.162.132
campaign co-memberdomain123.31.81.229
campaign co-memberdomain120.157.56.105
campaign co-memberdomain113.176.132.141
campaign co-memberRelated Emails
diana@ierek.com
campaign co-memberemailcfjtfl@verxl.com
campaign co-memberemailcbx-df@ceszx.com
campaign co-memberemailj.thompson8822@ymail.com
campaign co-memberemailbb.adige@libero.it
campaign co-memberemailhr@teknfix.com
campaign co-memberemailpangmyiuhk@yahoo.co.jp
campaign co-memberemailmarydavis09@zoho.com
campaign co-memberemailidentity@varomoney.com
campaign co-memberemailservicename@nickname.tld
campaign co-memberemailxxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grupoaldama.com.mx
campaign co-memberemaila4084163@trbvm.com
campaign co-memberCommunity Reports
We were looking for an American bully to join out family when we found a dog that was beautiful and very decently priced ($900). We checked out the website they had and it all seemed legit. We reached out with an inquiry on the dog and received a text within a day. He went by the name of Rico when he texted me saying the adoption fee was $900 + $200-$300 delivery depending on the state. He asked how familiar we were with American bullies and our experience which we thought was good because it seemed like they were really looking for a good fit. We asked for pics and videos and received a few of each whenever requested. He answered all of our questions and said that once we paid half of the money we would be able to get the process started for the delivery of the pup. Once we received the tracking information then we would have to pay the other half which we thought was weird but went with it. The process for paying was weird as we were given several different cash apps to sent the money to stating that some had reached the daily limit for cash and it needed to be sent to a different one. We received screenshots of the ticket from company that was being used to transport the pup - Global Safeway Pet Movers - were given the tracking number, departure and arrival time and dates, and we were told to pay the remaining amount. Again we were given different cash apps to pay. The day before delivery we received a text (782-590-2117) and an email ( [email protected] ) supposedly from the Global Pet Movers but they identified as "MYPL Logistics" within the email. They stated that they had updated their policy and would need to send in the pup in an air regulated crate. They had two options one to purchase for $4900 or one to rent for $2000 which [BBB Scam Type: Online Purchase] [Business: Rick Monster Bullies / Monica Rick Bullies / Global Safeway Pet Movers / MYPL Logistics Online Puppy Retail and Pet Transportation Scam] [Location: FL, USA- 32810]
We were looking for an American bully to join out family when we found a dog that was beautiful and very decently priced ($900). We checked out the website they had and it all seemed legit. We reached out with an inquiry on the dog and received a text within a day. He went by the name of Rico when he texted me details and answered all my questions and said that once we paid half of the money we would be able to get the process started for the delivery of the pup. Once we received the tracking information then we would have to pay the other half We received screenshots of the ticket from company that was being used to transport the pup - Global Safeway Pet Movers - were given the tracking number, departure and arrival time and dates, and we were told to pay the remaining amount. The day before delivery we received a text (782-590-2117) and an email ( [email protected] ) supposedly from the Global Pet Movers but they identified as "MYPL Logistics" within the email. They stated that they had updated their policy and would need to send in the pup in an air regulated crate. They had two options one to purchase for $4900 or one to rent for $2000 which would be fully refundable once the pup was delivered. I reached out to Rico to confirm and he said that he was told the day prior about the change but did not think that it would apply to us. We were messaging back and forth within text and we were told that we would be fully refunded once the pup was delivered. I asked several times for the policy to be sent to me which eventually it was - however probably was being made at the point of me requesting it. We were given many different cash apps to send the money to and to break up the amounts which we thought was really weird. They were taking fo [BBB Scam Type: Online Purchase] [Business: Global Safeway Pet Movers Date Repor] [Location: FL, USA- 32810]
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.