Anti Virus scam (760) 493-7049

Scammer’s Number: (760) 493-7049
Domains Used: Contact Us – Digital Web Secure
Extra Info: fake AV support

2 Likes

They aren’t very friendly…:joy:

1 Like

I tried doing a who-is lookup on them and I couldn’t get any intel. I could only get a privacy block.

1 Like

They didn’t want to play, so I’m call-flooding them with 6 numbers. I’m going to add Google voice and TextNow and see if that makes them happy.

2 Likes

That’ll show them who the master really is

2 Likes

(760) 493-7049
Carrier: Onvoy LLC
They’re just letting it ring now. Maybe they parked the number.

2 Likes

We should still push it on them. We shouldn’t let their anger heal.

3 Likes

I got a human Nov. 23 around 12 p.m. EST.

1 Like

484-233-6312 their new number

2 Likes

What does it mean when scammers park numbers?

1 Like

Both numbers still working and the first number needs to get flooded. Definitely angry now, after I’ve rung them more than 50 times. LOL

2 Likes

Phone number 7604937049 definitely still working. Flooding these dumb ducks with calls now.

3 Likes

For anyone that knows how to do it, as I am still relatively new at this, this website needs to get reported and flagged.
https://secure.logmeinrescue.com/Customer/Code.aspx
SB

1 Like

When they get flooded, they set their number to idle, kind of like do not disturb mode. It’s funny, they keep picking up and hanging up, but my dialer is pretty fast and calls them right back. They started transferring my calls to another call-center. :joy::joy: Then they gave up and shut the number down.

3 Likes

Great😃! Let’s keep calling them until they give up more. We need them to get angrier and angrier to the point when they physically destroy their keyboards, headphones, and computers. We must keep pushing. We’re doing a great job! Let’s push for their reactions some more🤣

2 Likes

LogMeIn Rescue is a legit business. Is there a support key you would like to post? We can report that to LogMeIn. Let’s have hope that they take action.

:rofl: :rofl: :rofl: :ok_hand:

3 Likes

They uh, are going to have quite a few emails, I did this on the previous thread I was on,

Oh, also, their wp login:

https://digitalwebsecure.com/wp-login.php

username: digitalwebsecure

and password is supposed to be: OGP3E9L496 - but doesn’t work.

WordPress Version: 5.5.7

and uh,

RUH ROH WRAGGY, WoNdEr WhO DiD ThAt

xD, fucking retards.

Anyway -

Plugin Update Status About
contact-form-7 5.2.2 Warning latest release (5.5.3)
https://contactform7.com/
revslider Unknown
woocommerce 4.5.3 Warning latest release (5.9.0)


/wp-content/uploads/ disabled
/wp-content/plugins/ disabled

: ) - anyway, if it ever comes back up, I can do a few more things, and I’ll update ya’ll here, but uh yeah <3

Some interesting stuff:

=====
-Domain: digitalwebsecure.com
-Registrant : GoDaddy.com, LLC
-Creation date: 2020-09-03 07:18:13
-Expiration : 2022-09-03 07:18:13
-Last update : 2021-09-04 05:57:23

single visit broadband test (using GET)…

-Bytes in : 65.01 KB
-Load time: 1.06 seconds

-Last Reports:

    + CVE-2021-3912 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3912

    + CVE-2021-3911 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3911

    + CVE-2021-3910 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3910

    + CVE-2021-3909 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3909

    + CVE-2021-3908 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3908

    + CVE-2021-3907 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3907

    + CVE-2021-3761 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3761

    + CVE-2020-35152 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35152

    + CVE-2020-24356 -> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24356

some vulns <3

======================
Not shown: 996 filtered tcp ports (no-response)

PORT STATE SERVICE VERSION

80/tcp open http Cloudflare http proxy

|_http-title: Did not follow redirect to https://digitalwebsecure.com/

| http-methods:

|_ Supported Methods: GET HEAD POST OPTIONS

|_http-server-header: cloudflare

| http-robots.txt: 1 disallowed entry

|_/wp-admin/

|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E

443/tcp open ssl/http Cloudflare http proxy

| http-robots.txt: 1 disallowed entry

|_/wp-admin/

|_http-trane-info: Problem with XML parsing of /evox/about

|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E

|_http-generator: WordPress 5.5.7

|_http-server-header: cloudflare

| ssl-cert: Subject: commonName=*.digitalwebsecure.com

| Subject Alternative Name: DNS:*.digitalwebsecure.com, DNS:digitalwebsecure.com

| Issuer: commonName=R3/organizationName=Let’s Encrypt/countryName=US

| Public Key type: rsa

| Public Key bits: 2048

| Signature Algorithm: sha256WithRSAEncryption

| Not valid before: 2021-11-02T04:15:47

| Not valid after: 2022-01-31T04:15:46

| MD5: 15ee b7e4 f1d3 da71 622d 6951 df96 bdc3

|_SHA-1: 4885 cfaf ab99 d2c6 12d8 90d0 776f 9c4b 88ad f8d9

|_http-title: Digital Web Secure

| http-methods:

|_ Supported Methods: GET HEAD POST OPTIONS

8080/tcp open http Cloudflare http proxy

|_http-server-header: cloudflare

8443/tcp open ssl/http Cloudflare http proxy

|_http-title: Site doesn’t have a title.

|_http-server-header: cloudflare

| ssl-cert: Subject: commonName=*.digitalwebsecure.com

| Subject Alternative Name: DNS:*.digitalwebsecure.com, DNS:digitalwebsecure.com

| Issuer: commonName=R3/organizationName=Let’s Encrypt/countryName=US

| Public Key type: rsa

| Public Key bits: 2048

| Signature Algorithm: sha256WithRSAEncryption

| Not valid before: 2021-11-02T04:15:47

| Not valid after: 2022-01-31T04:15:46

| MD5: 15ee b7e4 f1d3 da71 622d 6951 df96 bdc3

|_SHA-1: 4885 cfaf ab99 d2c6 12d8 90d0 776f 9c4b 88ad f8d9

==========

some more funsies ; )

==========
INFO: Checking digitalwebsecure.com

  • 104.21.87.43 [CLOUDFLARENET]
  • 172.67.141.80 [CLOUDFLARENET]
    INFO: Subdomain enumeration progress [20/67]
    INFO: Subdomain enumeration progress [40/67]
    INFO: Subdomain enumeration progress [60/67]
    INFO: NS History by CompleteDNS.com
  • Empty
    INFO: IP History by ViewDNS.info
  • 2011-08-11 | 173.213.88.243 | Eonix Corporation(Charlotte - United States)
  • 2012-01-11 | 208.91.197.101 | Confluence Networks Inc(British Virgin Islands)
  • 2016-11-11 | 184.168.221.61 | GoDaddy.com(Scottsdale - United States)
  • 2021-09-03 | 107.180.27.233 | GoDaddy.com(Scottsdale - United States)
  • 2021-11-28 | 104.21.87.43 | Cloudflare, Inc.(United States)
  • 2021-11-28 | 172.67.141.80 | Cloudflare, Inc.(United States)

anywho, <3

lmao

have a nice day :+1:

1 Like

I don’t know who did this …

:wink:

but uh,

before their Cloudflare got yeeted from being used,

I wanted to share some fun screenshots from the past 24+ hours :slight_smile:




image

(SSL certificate went bye bye)


(that’s what the error is saying → when you went to the website, it was no longer HTTPS :slight_smile: )
proof:
image


xD → unfortunately, it’s back though : /



oh, another funny error

Their uh, back end is uh, exposed now :slight_smile:

IP address: 85.187.128.35
Hosting: A2 Hosting, Inc.

And, if you go to
https://digitalwebsecure.com/ right now,

image

: )



Anyway, kinda sucks nobody was able to be scammed for however long their site has been uh, magically “handled”

<3

I don’t condone anything malicious, but I will say → magic is not illegal, and it’s fun to cast spells :wink:

especially with these poor people, they use Cloudflare and then they’re exposed to me, and then, well,

image

Ruh Roh, and the state it’s in right now : )




ANYWAY, kinda funny, #hack_the_planet(hypothetically)

have a nice day amigos <3

Creo que es muy divertido :wink:

1 Like