GlobalData Investments & CNServers, CHINESE CRYPTOMINERS IMPERSONATING THE US GOV. W/ THE TALIBAN

Popup (down) - https://us.post-abnormal.life

Registered via NameSilo on October 19, 2023 - Whois post-abnormal.life

image

The website linked was a commonly-used USPS phishing link that has since been taken offline. While most of these sites are registered via Alibaba Singapore on a Tencent-or-Alibaba-owned US IP address, this one uses 49.51.182.41, an American IP operated by CloudRadium, LLC, a California-based DDoS protection service with a disconnected phone number whose IP addresses were used to host WannaMine, an Internet worm based off of WannaCry used to mine the cryptocurrency Monero from victims’ computers.

CloudRadium is a brand of GlobalData Investments, Inc. alongside CeRaNetworks.com, which hosts servers in Los Angeles, Hong Kong and mainland China whilst accepting payment via credit cards and Bitcoin. Their US office, according to Google Maps, is located at 1200 W. 7th Street, Suite L1-150, Los Angeles, California, 90017.

The company, as CeRaNetworks, is listed on TrustPilot as “A Hong Kong datacenter infrastructure service provider is committed to providing high-quality infrastructure services for SMEs.”

The company also appears to be linked to CNServers, LLC, a subsidiary/business name of CyberNet Servers Limited in Hong Kong that is also believed to be hosting these USPS phishing domains.

Associated Telegram Server - Telegram: Contact @daobaniu

Associated Phone Number - (702) 224-2888 (VoIP, ONVOY)

Associated Email Address - [email protected]

4 Likes

UPDATE: The scammers are now spoofing British phone lines to pose as the IRS regarding a “$573 tax refund.”

NEW POPUP: https://irs.gov.secure-fundhub.com/

Registered via Alibaba Singapore on November 3, 2023 - Whois secure-fundhub.com

image

On the website, users are asked to provide their

  • Full name
  • SOCIAL SECURITY NUMBER
  • Birthday
  • Mailing Address
  • Phone number
  • Bank Account number

Associated IP Address - 49.51.194.58 :us:

The IP address also hosts

2 Likes

NEW POPUP - usps-www.top

Registered in He Nan, China via Chengdu West Dimension Digital on August 3, 2023 - Whois usps-www.top

image

(This was a group text labelled “USPS” with myself and another victim, the scammer swiftly dipped).

IP: 47.253.93.99 :us: (Alibaba, also hosts usps-www.site)

2 Likes

WEIRD UPDATE: It appears the scammers are now making cold calls from spoofed foreign numbers, as I just received a call from a random Iranian number. It was a prerecorded message in Chinese, save for what I thought was a brief reference to the United States Postal Service.

For legal purposes, I will not be posting the number as it may have been spoofed and I have no way to verify the number in question.

1 Like

2 hours ago, I also got a call from spoofed Iranian number +98…

Were they speaking Chinese as well?

1 Like

Yes…Some Chinese dialect

If their number wasn’t spoofed and I was able to call them back, I should pull a “-999,999,999 social credit” on them for shits and giggles.

1 Like

Looks like my mother just received the same call, this time from a spoofed JPMorgan/Chase number.