Crypto "investment" Website

Scammer’s Number: They mostly work on Telegram chats. Currently i’m talking to a couple accounts without tags and one with this username: @Dennisest . I’ve stringed them along for weeks, a couple accounts for months, sometimes with AI generated text and auto-response.
Domains Used: swanfinanceltd.com , www.cityglobalfund.com , veluxcorporationlimited.com , stanbicfinanceltd.com plus a couple i can’t find in my history.
Extra Info: For anyone who’s unfamiliar with the scam: they scout public groups for real looking profiles, contact you and try and befriend you. Then share an “opportunity” for investment on a website just like the ones up there and promise you crazy returns. Obviously those returns are not true and just like that the funds you deposited are gone.

They scam people out of thousands a day (by looking on their wallets’ transactions) with no way of recourse since it’s all crypto and they keep shuffling wallets once they clear out and launder the funds.

Personally I’m trying to get in contact with someone who could help me take them down.
I usually report their live chats to get them banned, crypto price trackers addons, then domain registrar and hosting but i’ve had no luck with the latters. I found however a couple (minor) vulnerabilities in their shitty dashboards and currently looking for a way to exploit them.
I’m almost finished with a bachelor in CS and worked building similar systems so I can maybe of some help. For any further contact message me so we can move to another platform (TG or Discord).

1 Like

SwanFinance Ltd IP:

Date/Time 2021-09-18 13:22:28 UTC
IP Address 197.210.226.71
Country Nigeria, Oye-Ekiti
Orientation portrait-primary
Timezone Africa/Lagos GMT+1
User Time Sat Sep 18 2021 14:22:28 GMT+0100 (West Africa Standard Time)
Language en-GB
Incognito/Private Window No
Ad Blocker No
Screen Size 412 x 915
Local IP 10.189.216.18
GPU Mali-G72
Browser Chrome Mobile (89.0.4389.105)
Operating System Android 10
Device Samsung Galaxy A51
Touch Screen Yes (5 touch points)
User Agent Mozilla/5.0 (Linux; Android 10; SM-A515F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.105 Mobile Safari/537.36
Platform Linux armv8l
Referring URL no referrer
Host Name 197.210.226.71
ISP MTN NIGERIA Communication limited
1 Like

CityGlobalFund IP:

Date/Time 2021-09-18 13:27:43 UTC
IP Address 197.210.55.242
Country Nigeria, Port Harcourt
Orientation portrait-primary
Timezone Africa/Lagos GMT+1
User Time Sat Sep 18 2021 14:27:43 GMT+0100 (West Africa Standard Time)
Language en-GB
Incognito/Private Window No
Ad Blocker No
Screen Size 412 x 915
Local IP 10.189.216.18
GPU Mali-G72
Browser Chrome Mobile (89.0.4389.105)
Operating System Android 10
Device Samsung Galaxy A51
Touch Screen Yes (5 touch points)
User Agent Mozilla/5.0 (Linux; Android 10; SM-A515F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.105 Mobile Safari/537.36
Platform Linux armv8l
Referring URL no referrer
Host Name 197.210.55.242
ISP MTN NIGERIA Communication limited
1 Like

StanbicFinance IP:

Date/Time 2021-09-18 13:31:49 UTC
IP Address 197.211.58.64
Country Nigeria, Lagos
Timezone Africa/Lagos GMT+1
User Time Sat Sep 18 2021 14:31:52 GMT+0100 (WAT)
Language en-gb
Incognito/Private Window No
Ad Blocker No
Screen Size 375 x 667
GPU Apple GPU
Browser Mobile Safari (14.1.2)
Operating System iOS 14.7.1
Device Apple iPhone
Touch Screen Yes (5 touch points)
User Agent Mozilla/5.0 (iPhone; CPU iPhone OS 14_7_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Mobile/15E148 Safari/604.1
Platform iPhone
Referring URL no referrer
Host Name 197.211.58.64
ISP globacom-as
1 Like

Is there anything more we can do than an IP grab? I’m willing to put time and money into taking them down or at least waste their resources/money into making new sites/accounts.

We can take their websites down by contacting the emails down below:
SwanFinanceLTD: [email protected]
CityGlobalFund: [email protected]
VeluxCorporationLTD: [email protected]
StanbicFinanceLTD: [email protected]

1 Like

hmm i get it, i’ll send them an email but i doubt they’ll even respond. all info in the dns query are most likely false so why bother