Tracking bank/crypto phishing gang(s) using Google Sites, Tawk.to, MS Azure sites, Wordpress, etc

Another:

https://sites.google.com/codeacti.com/amazoncomcode/

links to

https://am.bloklognn.gb.net/log/ fake login

https://am.bloklognn.gb.net/err/ fake error

Again, a tawk.to web chat widget.

1 Like

Another call today from “Stefan” from PayPal. His favorite color is magenta.

1 Like

Callback “Jake from Bittrex” 754-227-8736.

When I asked for his favorite color, he asked me to wait one moment, and hung up! How rude.

2 Likes

Found another one!

Google Sites page: https://sites.google.com/coinlogs.us/cryptocomloginissues/home

Azure hosting/phishing page https://cryptoedv.azurewebsites.net/

2 Likes

Another callback number from this group: Earlier today I was pinging the web chat widgets on a bunch of their phishing sites (many are still active), and just got a call from “Josh from Swissborg.” His TextNow number is 972-833-1205. He won’t tell me his favorite color.

He texted me: "This side Josh from SwissBorg. We have found suspicious activity in your wallet. Kindly call us back.

Team SwissBorg"

2 Likes

Another callback number: “Josh from Bitstamp” – 423-218-9543

1 Like

More website(s) active with tawk.to chat widgets, reported them to tawk.to with their form.

https://sites.google.com/coinlogs.us/cryptocomloginissues/home

links to

https://cryptomnes.azurewebsites.net/

with the fake error page

https://cryptomnes.azurewebsites.net/error.html

Tawk.to client id: 659c3f7b8d261e1b5f50daed .

Edit: another new one:

https://metamavesk.azurewebsites.net/

2 Likes

LOL Paul (Senior!) is working late … perfect time for a late night chat, join in at

https://tawk.to/chat/653f9c79f2439e1631e9e1ab/1he07mfc1?pop=1

1 Like

Another one of Scammer Paul’s live chat URLs:

https://tawk.to/chat/653f9a86a84dd54dc486adfe/1he077833?pop=1

He’s working late, check in and ask about your bitcoins.

New subdomain: https://cryptro.azurewebsites.net/

1 Like

New subdomain: https://metamaskds.azurewebsites.net/

New Tawk.to web chat account: Jack is available now to consult about your failed login!

https://tawk.to/chat/65b7804f8d261e1b5f591333/1hlacqeoe?pop=1

from

https://capitttll.online/err/

Update: “Mark” from Capital One can be reached at 707-327-2882.

Another list of phishing domains on the same IP address:

1 Like

Paul wants to chat with you about your account – any account! (New Tawk.to id)

https://tawk.to/chat/65c0c3248d261e1b5f5c7aa1/1hlsfkici?pop=1

1 Like

https://tawk.to/chat/65b7804f8d261e1b5f591333/1hlacqeoe

He has no info about me but still will stop any new purchases
Jack

21:24

my card lost

Agent profile image

Do not worry. We are forwarding your request to concerned dept.

They will get back to you over phone call in the morning after 6-8 hrs

May be after 9 in morning .is that okay ?

yes. can you block now any new purchases?

Agent profile image

Okay.it will be done.

Anything else may I help you ?

many thanks

Agent profile image

Please also check your email after some time regarding this .

Good night.

Another Tawk.to chat link from https://piopp.ink/ers/ (fake PayPal)

https://tawk.to/chat/65c49e8f0ff6374032caadfa/1hm40motc

And another one from https://cprosis.shop/err/ (fake Crypto dot com)

https://tawk.to/chat/65c0ba9c0ff6374032c973d3/1hlsdhtqg

1 Like

https://capitttll.online/logg/ is still live, after pinging the site and providing a phone number I got a call from “Chris from Capital One” at 330-294-6857. He wouldn’t tell me his favorite color.

1 Like

Another one:

Ledger Live Not Working : Most Secure Crypto Wallet App and
Ledger Wallet Extension : Most Secure Crypto Wallet extension

link to

https://bildherrywation.com/026988c7-502a-41e5-8a5b-e79d04c51f3d

which redirects to

https://ladegerwalle.azurewebsites.net/

fake error page:

https://ladegerwalle.azurewebsites.net/process/error.html

Tawk.to chat: https://tawk.to/chat/65ca442c8d261e1b5f5f16ff/1hmf1kk06

Update: Another feeder website: https://liveledgerweb3.com/

A Twitter spambot account promoting these scams – note that this amazingly prolific gang does German-language scams, too: x.com

Update 2: and French! https://sites.google.com/cryptowalletc.com/ledgerlive-wallet/home , associated Twitter bot x.com

1 Like

Another possible lead to follow up on with this group:

A tweet by the spambot that promotes the Crypto phishing scams

https://twitter.com/shirajoy5/status/1727548684391624755

Links to a Google sites page for Indian cricket betting (probably impersonating something else, I don’t know.)

This site leads victims to chat via Whatsapp with

+91 92563 99231 (Indian prefix)

1 Like