This cluster centers on 2382 connected domains tagged as PureHVNC, elf, sh. 572 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (8772427372, 1319641540, 1319641221) with 557 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2228 complaints with federal agencies. Geog...
(855) 413-5003
Last reported Mar 28, 2026
- 30 community reports from users
Campaign Intelligence
This cluster centers on 2396 connected domains tagged as 156-233-71-230, Quakbot, lnk. 586 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (8772427372, 1319641540, 1319641221) with 565 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2237 complaints with federal agen...
This cluster centers on 1895 connected domains tagged as BeaverTail, RedLineStealer, password: 2026. 113 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 934 phone numbers (8772427372, 1319641540, 1319641221) with 524 FTC complaints; 683 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2093 complaints wit...
This cluster centers on 2416 connected domains tagged as BABADEDA, WallStealer, meterpreter. 607 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 969 phone numbers (5086371451, 9366439335, 1842506726) with 570 FTC complaints; 690 email addresses (kellymoore_64@yahoo.com, schantzsybg7@aol.com, online.motors@consultant.com). Across all linked entities, consumers have filed 2243 complaints with federa...
This cluster centers on 2764 connected domains tagged as BeaverTail, Kaiji, fbf543. 645 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1132 phone numbers (7638857447, 8664372914, 2157987305) with 10266 FTC complaints; 146 companies (JPMORGAN CHASE & CO., Advanced Resolution Services Inc., EVERBANK, NATIONAL ASSOCIATION) with 8616274 CFPB complaints; 298 email addresses (xxxxxxxxxxxxxxxxxxxxxxxx@vm...
This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
This cluster centers on 2874 connected domains tagged as QuasarRAT, StealitStealer, pw-k53mv9bc. 652 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1375 phone numbers (2157987305, 2025069230, 2028641298) with 14635 FTC complaints; 160 companies (JPMORGAN CHASE & CO., Advanced Resolution Services Inc., EVERBANK, NATIONAL ASSOCIATION) with 8680419 CFPB complaints; 299 email addresses (abuse@fb.com, ...
This cluster centers on 1486 connected domains tagged as None, keylogger. 5 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1364 phone numbers (3124141737, 3163966869, 8553892999) with 17909 FTC complaints; 170 companies (EQUIFAX, INC., TRANSUNION INTERMEDIATE HOLDINGS, INC., BANK OF AMERICA, NATIONAL ASSOCIATION) with 8747332 CFPB complaints; 187 email addresses (xxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grup...
Details
Linked Company Activity
Connected Entities
Linked Companies
Related Phone Numbers
Related Domains
Community Reports
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Ran across a popup "Microsoft" remote-access scam today... Here's a screenshot of the website: http://i.imgur.com/9TwTVNw.png Don't load the URL unless you want to try and image what it must feel like to be someone who isn't even remotely savvy with computers and feels they have no choice *but* to call the number. And then you'll have to task manager out of your browser because it locks everything up. I just reloaded it on PaleMoon so I could remember what the robot voice said and noticed a new popup they had on that website: > > A Suspicious Connection Was Trying to Access Your Logins, Banking Details & Tracking Your Internet Activity. > > Security Center & Firewall Services are Disabled, Error code 0x8007042c; . > > Your TCP Connection Was Blocked by Your Firewall. Your Accounts May be Suspended Until You Take an Action. > > Your Personal Information May Have Leaked. IMMEDIATE RESPONSE REQUIRED > > Your Hard Disk May Have Trojan Virus! Please Do Not Try to Fix Manually, It May Crash Your Data. > > Please Visit Your Nearest Service Center OR Call Help Desk+1-855-413-5003 > > ------------------------------------------------------------- > Customer Service: +1-855-413-5003 (TOLL-FREE) > ------------------------------------------------------------- > > PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILIURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE. > > ********** IMMEDIATE RESPONSE REQUIRED ********** > > Your System32 .net frame work file missing due to some harmful virus, Debug malware error 895-system 32.exe failure. > Please contact network administration to rectify the issue. > Please do not open internet browser for your security issue to avoid data corruption on your registery of your system. Please contact network administration department at +1-855-413-5003 (TOLL-FREE) > > Viru
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
NordProtect — Identity theft monitoring and recovery
NordProtect watches for your personal info on the dark web, monitors your credit, and covers up to $1M in identity theft insurance.