|
Crawling Across Chaos and Time Without End
|
|
Apr
06
2009
Google Treasure Chest – it’s a scam and a half!Introduction
kevinlifeblog.com
You are then redirected to this page where you have to enter various address details:
I did so using the address of an electricity sub station. (yes, I know). Once all the boxes are ticked and the funny little easily resettable timer is ignored (but noted as a clue to a very good social engineering type scam), you are taken to this website:
In here, the warnings should really be going off in your head by now! They ask for your credit card number, expiry date and CVV number! And all to get $1 from you! securecartcenter.com
Source CodeIn the source code for SecureCartCentre we find that images are served from bsadn.pantherssl.com Click that and you’ll get the folder structure for bloosky.com who serve advertising campaigns. Fish through the folder structure and examine various files. Google Treasure Chest is there. Check out some css files and you’ll find that some are loaded from discovertotal.com , which has a contact of bloosky.com So far so good. If they’d have stuck an htaccess file in there I wouldn’t have seen that, ho hum. Instant Google KitLots of stuff points to this. http://googletreasurechest.com/index.php/home.html It’s the homepage for this ferago. Interestingly, down at the bottom all the links are to this site except for one, the signup link which goes to: http://www.redtomorrowfield.com/z/gtc2/?cy=10&pr=19&af=16&ad=19 redtomorrowfield.comThese are also shrouded from enquiry by DomainsByProxy.com The site actually looks like the treasure chest one – weird. The form at the bottom is similar to the previous address form but the email address is validated by ebizsuite.com, an eCommerce company. So Where’s The Problem?The problem lies in this selection of links below. There are hundreds on the web. No-one has anything good to say. At the bottom of the signup page, is the text:
ConclusionWhen I started this little investigation, I thought it was a straight phishing expedition to get credit card details. Instead, it’s a curious grey fuzz of almost legal chicanery. Watch out! Addendum Posted 7 April 2009The original popup ad was for a ‘person’ called Kevin Hoeffer with his honestly dismal automatic sales pitch. Today I came across another who mysteriously, used to work for a pipe company! This is on this website http://www.joshmadecash.com The actual text goes like this (one paragraph only shown):
Naturally I wondered how many sites there are with this former pipe company (drum roll) bit of spiel going on. Try this Google search on this string “A year ago I was an account manager for a (drum roll) a pipe manufacturing company. Not exactly what I dreamed of when I was growing up.” to see how many. Actually Google says over 100! (202 on 8 May 2009!!)(268 on 29 May 2009!!) Addendum 10 April 2009Useful Links
I’ll continue to post extra info here, instead of in the threads below in order to make it more accessible. I seem to be finding stuff out here on an hourly basis, and most of it is depressing as it reveals the vulnerability of the human condition. So please folks, always remember,
Latest News: 27 April 2009
From this article, we see that the ‘company’ behind Google Money Bollox is “Infusion Media Inc”. Try a Google search on the name here. For a company that’s been behind sooooo many different scammy websites, there are only 173 results. Nearly all relate to their dodgy dealings.
More Related Links
Addendum 2 May 2009
Amazon Related:
Related Posts by TagsImprove the web with Nofollow Reciprocity.
|
© 2007-2010 Strangely Perfect All Rights Reserved
Strangely Perfect is Digg proof thanks to caching by WP Super Cache
Google’s “official blog” has finally commented on the Google Kit scams. http://googleblog.blogspot.com/2009/07/how-to-steer-clear-of-money-scams.html
They also give a few links to where users can report spam or as they describe it “many sites with duplicate content or common templates intended to direct users to the same product or scheme” (eg: the fake blogs and fake news sites)
http://www.google.com/support/webmasters/bin/answer.py?answer=35265
And then a link to another help page which tells you how you can report dodgy adwords ads, plus the advice to report scams to the FTC, IC3, econsumer etc.
http://www.google.com/support/websearch/bin/answer.py?answer=9110
Like or Dislike:
0
0
‘Finally’. You said it mate.
There is a link that I thought would be useful in the third link of yours. It’s URL is https://rn.ftc.gov/pls/dod/wsolcq$.startup?Z_ORG_CODE=PU01 and it’s supposed to go to the FTC complaints dept.
Except it doesn’t.
I think it’s the wizard they want here: https://www.ftccomplaintassistant.gov/FTC_Wizard.aspx?Lang=en
Some of what they said was interesting. A reminder of this came today for me because I’ve noticed a few people having difficulty registering for this website. So I deactivated my SABRE plugin to see if it made it any easier. (Sabre minimises Registration Spam to very small levels). Any way, it was only off for 30mins and I got the first hit from a Russian camouflaged as the Indian TLD. Needless to say, SABRE is now on. When I’ve tested it, it works fine…hmmm.
The point is that the Google article says that comment/registration spammers are trying to hack in to enable spam ops and any other nefarious activity the permissions will let them do.
Registration isn’t really necessary anyway. As you’ll know, I allow people to comment freely and anything with more than a few URLs in it is held for moderation. It works for me and needs minimal maintenance and intervention while keeping the sharks in the bay.
Like or Dislike:
0
0
[...] it! It’s listed as the main contact point for Google Treasure Chest, etc, many times. See here and here for two of my posts. Now check this google search for the phone number 801-578-9020. [...]
Like or Dislike:
0
0
Comments are now closed on this posting as Google Treasure Chest is dead.
However, the problem has not gone away – the menace continues.
Like or Dislike:
0
0
[...] 04/06/2009 (StrangelyPerfect.TV): Google Treasure Chest – it’s a scam and a half! [...]
Like or Dislike:
0
0
[...] 10:34:30 ->/3099/google-treasure-chest-its-a-scam-a(…)com/components/com_frontpage/test.txt?? [...]
Like or Dislike:
0
0