Australian webcams hacked to make secret recordings, posted to YouTube, in online scam - ABC News
Their website www.macpatchers.com.au is down, but they have a new website:
https://www.macgeeks.com.au with phone numbers:
(Aussie Phone) +61 1800-225-863
(USA Phone) +1 844-856-1333
A search online shows that the owner of this website is:
Registrant TRUE BLUE SOFTWARE SUPPORT PTY. LTD.
Registrant ID ABN 80616784868
and the owner of this ABN is:
CALVIN HUNTER (Director)
Director since 12-01-2017 (1 year and 4 months)
Date of Birth: 15-12-1966
Age: 51 Years old
Place of Birth: KURRI KURRI, NSW
Address:
54 ST CLAIR STREET
BONNELLS BAY NSW 2264 Australia
Home landline gathered from whitepages: +61 (02) 49733292 or +61 (2) 49733292
I also suspect https://pcpatchers.net is one of their sites:
(Aussie Phone) +61 1800830823
More of their scam sites:
https://hotmail.supportau.com.au Ph: +61 1-800-817-695 (Currently blocking silent numbers)
https://yahoo.supportau.com.au Ph: +61 1-800-958-231 (Currently blocking silent numbers)
https://gmail.supportau.com.au Ph: +61 1-800-431-287 (Currently NOT blocking silent numbers)
More details:
macgeeks.com.au which has some of the same details as macpatchers.
MACPATCHERS.COM +61 280730175
macpatchers.co.nz
ravi singh +64-099509148 New Zealand
QUICKBOOKSUPPORTADVISOR.COM
pcpatcherstechnology.com
pcpatchers.com
SUPPORTAUSTRALIANUMBER.COM
Registrant Name: Ravi Shekhar Singh
Domain Name: MACPATCHERS.COM
Registrar: Shinjiru MSC Sdn Bhd
Registrant Name: Ravi Shekhar Singh
Registrant Street: Shalimar Garden Shahibabad
Registrant City: Ghaziabad
Registrant State/Province: Uttar Pradesh(INDIA)
Registrant Postal Code: 201005
Registrant Phone: +91.8527027799
Registrant Email: [email protected]
RAVI SINGH PCPATCHERS LTD at Website Informer
they are back again
working
Today I was having trouble with my gmail account. I got a security alert email from google stating my account had been accessed ‘Near Dilshad Garden, Dehli India’. I followed advice and changed my pw. However my Gmail account, operating with Outlook 2010, persisted in asking for my password. I could not get the pop-up box to disappear. I eventually google searched ‘gmail help australia’ and called a number 1800958218. https://customer-help-number.com.au/gmail-support-australia.html. I told the guy ‘Mark’ my issues and he told me he could help, and asked to access my pc. I allowed this. Mark showed me a dos window apparently showing my IP address and beside this numerous overseas address which are accessing my address. Mark told me he could fix my problems by installing ‘Microsoft Office Professional 2016 plus’, and do a ‘clean up’ and uninstall unwanted software. In signing agreement to do this, the quote was for $589. The company was MacGeeks of Suite Morriset Square 35 Yambo Street Morriset 2264 ABN 91 619 160 119. The Office software appears to have installed correctly. I don’t know what clean-up was performed. Have I been scammed?
@Mickh#52584 Yes you were scammed. Contact your bank and request your money back.
The owner got arrested last week. RAVI SHEKHAR SINGH
Address: F-3, Mrignayani Chawk, Block F, Dilshad Garden, Delhi, 110095
PCPATCHERS TECHNOLOGY PRIVATE LIMITED
RAVI SHEKHAR SINGH, SIMPAL PARIHAR directors
MACPATCHERS TECHNOLOGY PRIVATE LIMITED
connected to;
HV WEB SOLUTIONS PRIVATE LIMITED
News: https://www.ndtv.com/delhi-news/24-arrested-for-targetting-microsoft-customers-from-fake-call-centres-1927655
@Mickh#52584 Unfortunately, this is scam. The owner got arrested last week in Delhi, India
News: 24 Arrested For Duping Microsoft Customers From Fake Call Centres: Police
Is it dangerous to call? Like could they get your info via voice? Or something along the lines to that.
Here Is Some Info For All u HaXors Out There
Found That This Site https://www.macgeeks.com.au > Is Connected To This Free Panel Service Here ( https://demo.opencart.com/ ) There Hosting Service Is This )(https://www.a2hosting.com/opencart-hosting)
The Box DNS Server is Hosted by AWS Cloudfrunt,
(server-99-84-101-16.iad79.r.cloudfront.net)
Learn more About hijacking Here (https://disloops.com/cloudfront-hijacking/)
Also Tool ( https://github.com/MindPointGroup/cloudfrunt)
For Misconfiged domains To Hijack
Some Info Collected By Nikto Scanner
{
Server: Apache
+ Cookie PHPSESSID created without the secure flag
+ Cookie default created without the secure flag
+ Cookie language created without the secure flag
+ Cookie language created without the httponly flag
+ Cookie currency created without the secure flag
+ Cookie currency created without the httponly flag
+ Retrieved via header: 1.1 5c872a96e880c64a2293daae45f1f6ae.cloudfront.net (CloudFront)
+ Server banner has changed from 'Apache' to 'CloudFront' which may suggest a WAF, load balancer or proxy is in place
}
Good Luck HaXors,