by armstoj
Tue Jul 22, 2014 9:17 am
http://www.greatfactory.co/
http://www.gogreatmall.net/
http://www.greatproduct.net/
http://shoppingmall1.com/ (he took this one down after i found it)
http://www.somall9.com (he took this one down after i found it)
Sounded legit, knew all the keywords, after investigating, I found all these sites. I asked him, he said he only had one website lol, I said really? and linked to other sites, and He took them down lol. His original response via sk y pe was "our technician said "Looks our servers have vulnerabilities being exploited by hackers" lol
Here is the email header for one of our communications
From Daniel Hall Fri Jul 18 06:56:59 2014
X-Apparently-To: Deleted
Return-Path: <[email protected]>
Received-SPF: pass (domain of gmail.com designates 209.85.192.171 as permitted sender)
b0dyZWF0TWFsbC4gWW91IGNhbiBub3cgdGFrZSBwYXJ0IGluIHRoZSB2YXJp
b3VzIHNlcnZpY2VzIHdlIGhhdmUgdG8gb2ZmZXIgeW91LiBTb21lIG9mIHRo
ZXNlIHNlcnZpY2VzIGluY2x1ZGU6IFNob3BwaW5nIENhcnQgLS0tIEFueSBw
cm9kdWN0cyBhZGRlZCB0byB5b3VyIG9ubGluZSBjYXJ0IHJlbWFpbiB0aGVy
ZSB1bnRpbCB5b3UgcmVtb3ZlIHRoZW0sIG9yIGNoZWNrIHRoZQEwAQEBAQ--
X-YMailISG: GX1qfFcWLDv9.mr4Wu9A8Wy.9gve2D4z46tCiYfVWO1_np5y
tGjv3jsRewvXykaHsuQSIrE.bDCR.IA9n0PtJLupM7ch7KcbUwuLz4LmO0Hi
3Ov3I1E7wMT5JX2z9UJfZK4ddJ_.nf5iT9f4NlwGh2IDwQ.6y2b0Y1t_Nct.
oL.79L39HTEUHzVsUY3MurtKnKptMrTDp9GTXY2s6kTklcLJ93DavEEC7wpV
VK5FkNsw7YNjYiRE3xngPAYA49.69urrfV.BqsnhvIs97udkTFoF4Yb034.s
RA9McpyfxZW5uqOxqjUADdCW8OjQi0z7uOJXcuqNyWwhtjonhUfN8yp9JeeQ
978vLCnMLNFqYUEybpMEno3d5LNpjVMWH2yvBmbInBfMGdIV_YSOSCjZy1Bz
DorMID_kNH7jENqXVywvcV04wTP0y5Lp2vFatHmkcTx9Ouzqn1.UGqSemBbU
cYe0gSh0tn4QRZdBngN4nm4FpvFYsvITYFKWMwqtpqV2G5ngfalcP7fdvAE.
mPRKkOSAQFTLS71xvQtcRC6HzLCj2JdtJ1D3FrkG1UOqVbDiarPTgEqjdVMa
lgEI7.dYu2g7eEEqhZ5LG4kTgYWbHN6VpTVln9VfSYfVpcdLZ2a8tAEcGqS4
N6F67g4Bd21LMGyXi30sB9IgxBOGEmfKlbmfNNUmRlb1VFilxS.5Q9nvdMw7
.oRlY.P6E265fU1.BSrJZQt6vI.3GdjgDX93WnEhbfW3ucwGEDB2.IQ6Qh7B
XodjXGeHERP8vzlMqzXrJf2edls1pykh4EdPl68EU1BPNimS7yF1l_IJDEHI
vw6DbjLqFukuyz9h0sgWQqOdkU1ytXbNAcBluIKvbINF9qSh9IqisBmWx34A
hUM5eWe5Zcx3dAYpD2FramxQHXf35dAxfLuQ5QfvpZ0viM4GZrTiYyD9BEei
l81T1K4bsOEQt7qgoFte5SQ69iEsjF6x3HoJegbaWe8Ly0Ddhw49ruw1Szqt
yQn7u8OJRWBB8xWQJvbNZZvydVs55woXCYRvt2zjEvqWRNwxYfg_P130Abdi
5G9ud0sKH_kDbAOIGCm7h67VytB0nosViUX1wqd2Pr1DtYUKHrJBHZ4EIfph
I6G2Xjs_ZOtL7C24vhmzmD7QAFYTBA6Qti1pis2o1fqgGF_NS68uJ1AqvFHu
NqNkCoAuSfY6nbobSnblH.I6JeFAnsZvyRjTAQDcy0QnrPa2zdhEw.5BHEcg
MVC3lvqQtXABXnAT.aI_ir21HyOQuCGujO9gPlKvnkqmhgTSQtqyotzEj2_U
M0T9blNo3lVvBwi93ozm.3MQ7bA.BJ8TPK2Gtk13vDYmVp1x7a9N90Omd3dg
nbzx9n2yKW0SF2UIMmWNh01.EdC19nLl6iysOTgxefV5UO3Ufi0ubvvHBf00
RteGq25qNMck94frWxYa3u4RWbx67qHylPWLvcOwBn_8Qg--
X-Originating-IP: [209.85.192.171]
Authentication-Results: mta1136.mail.gq1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO mail-pd0-f171.google.com) (209.85.192.171)
by mta1136.mail.gq1.yahoo.com with SMTPS; Fri, 18 Jul 2014 13:57:00 +0000
Received: by mail-pd0-f171.google.com with SMTP id z10so5088799pdj.30
for <[email protected]>; Fri, 18 Jul 2014 06:57:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20120113;
h=message-id:date:mime-version:from:to:subject:content-type
:content-transfer-encoding;
bh=rkXAljHpDJWDtLtOwxNOeiIBq3xi8CPiFsXhX0WWIC4=;
b=XN28J1/UlFF1XmXWQp4Wdo4+RwcX6NPv9VrAjYAO68WHZAlL285eDgg5bZmpLgg8vl
IIf99nwTaQ/vbYF9dYGn/5asPKJgGJah+E1n9fu4Oom/n2Kf3vikWDyVoDng2wb1UPCP
4Fez2Fbv0O5apGJY/yGFXU0nH6x0zP8wJyPzSo6kRAeHP76I4kIxUBH2jR1AX6SFjEWC
GWXE7nQSVo9A5I0QwN4ttI1yYX9gTZA8zSNRgxYJDJBsF79s2WpRLIPdjPlLlbm5orL6
h3fEJi9Ih6dRcn96y5lfPOIwFpT87LXjQV4bpinGXUt0QNihzxioSNUI2VZm5HqtoUin
huGw==
X-Received: by 10.66.66.133 with SMTP id f5mr5195832pat.81.1405691820023;
Fri, 18 Jul 2014 06:57:00 -0700 (PDT)
Return-Path: <[email protected]>
Received: from XS318170952198 ([122.10.117.198])
by mx.google.com with ESMTPSA id tl3sm23303107pac.41.2014.07.18.06.56.57
for deleted
(version=TLSv1 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
Fri, 18 Jul 2014 06:56:59 -0700 (PDT)
Message-ID: <[email protected]>
Date: Fri, 18 Jul 2014 06:56:59 -0700 (PDT)
X-Google-Original-Date: 18 Jul 2014 21:57:32 +0800
MIME-Version: 1.0
From: "Daniel Hall" <[email protected]>
To: Deleted
Subject: Welcome to GoGreatMall
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Content-Length: 927
Would love to take this guy down, I may try to stalk him for a long time as I was scammed for 200 dollars....
Just so you all know
http://www.gogreatmall.net/
http://www.greatproduct.net/
http://shoppingmall1.com/ (he took this one down after i found it)
http://www.somall9.com (he took this one down after i found it)
Sounded legit, knew all the keywords, after investigating, I found all these sites. I asked him, he said he only had one website lol, I said really? and linked to other sites, and He took them down lol. His original response via sk y pe was "our technician said "Looks our servers have vulnerabilities being exploited by hackers" lol
Here is the email header for one of our communications
From Daniel Hall Fri Jul 18 06:56:59 2014
X-Apparently-To: Deleted
Return-Path: <[email protected]>
Received-SPF: pass (domain of gmail.com designates 209.85.192.171 as permitted sender)
b0dyZWF0TWFsbC4gWW91IGNhbiBub3cgdGFrZSBwYXJ0IGluIHRoZSB2YXJp
b3VzIHNlcnZpY2VzIHdlIGhhdmUgdG8gb2ZmZXIgeW91LiBTb21lIG9mIHRo
ZXNlIHNlcnZpY2VzIGluY2x1ZGU6IFNob3BwaW5nIENhcnQgLS0tIEFueSBw
cm9kdWN0cyBhZGRlZCB0byB5b3VyIG9ubGluZSBjYXJ0IHJlbWFpbiB0aGVy
ZSB1bnRpbCB5b3UgcmVtb3ZlIHRoZW0sIG9yIGNoZWNrIHRoZQEwAQEBAQ--
X-YMailISG: GX1qfFcWLDv9.mr4Wu9A8Wy.9gve2D4z46tCiYfVWO1_np5y
tGjv3jsRewvXykaHsuQSIrE.bDCR.IA9n0PtJLupM7ch7KcbUwuLz4LmO0Hi
3Ov3I1E7wMT5JX2z9UJfZK4ddJ_.nf5iT9f4NlwGh2IDwQ.6y2b0Y1t_Nct.
oL.79L39HTEUHzVsUY3MurtKnKptMrTDp9GTXY2s6kTklcLJ93DavEEC7wpV
VK5FkNsw7YNjYiRE3xngPAYA49.69urrfV.BqsnhvIs97udkTFoF4Yb034.s
RA9McpyfxZW5uqOxqjUADdCW8OjQi0z7uOJXcuqNyWwhtjonhUfN8yp9JeeQ
978vLCnMLNFqYUEybpMEno3d5LNpjVMWH2yvBmbInBfMGdIV_YSOSCjZy1Bz
DorMID_kNH7jENqXVywvcV04wTP0y5Lp2vFatHmkcTx9Ouzqn1.UGqSemBbU
cYe0gSh0tn4QRZdBngN4nm4FpvFYsvITYFKWMwqtpqV2G5ngfalcP7fdvAE.
mPRKkOSAQFTLS71xvQtcRC6HzLCj2JdtJ1D3FrkG1UOqVbDiarPTgEqjdVMa
lgEI7.dYu2g7eEEqhZ5LG4kTgYWbHN6VpTVln9VfSYfVpcdLZ2a8tAEcGqS4
N6F67g4Bd21LMGyXi30sB9IgxBOGEmfKlbmfNNUmRlb1VFilxS.5Q9nvdMw7
.oRlY.P6E265fU1.BSrJZQt6vI.3GdjgDX93WnEhbfW3ucwGEDB2.IQ6Qh7B
XodjXGeHERP8vzlMqzXrJf2edls1pykh4EdPl68EU1BPNimS7yF1l_IJDEHI
vw6DbjLqFukuyz9h0sgWQqOdkU1ytXbNAcBluIKvbINF9qSh9IqisBmWx34A
hUM5eWe5Zcx3dAYpD2FramxQHXf35dAxfLuQ5QfvpZ0viM4GZrTiYyD9BEei
l81T1K4bsOEQt7qgoFte5SQ69iEsjF6x3HoJegbaWe8Ly0Ddhw49ruw1Szqt
yQn7u8OJRWBB8xWQJvbNZZvydVs55woXCYRvt2zjEvqWRNwxYfg_P130Abdi
5G9ud0sKH_kDbAOIGCm7h67VytB0nosViUX1wqd2Pr1DtYUKHrJBHZ4EIfph
I6G2Xjs_ZOtL7C24vhmzmD7QAFYTBA6Qti1pis2o1fqgGF_NS68uJ1AqvFHu
NqNkCoAuSfY6nbobSnblH.I6JeFAnsZvyRjTAQDcy0QnrPa2zdhEw.5BHEcg
MVC3lvqQtXABXnAT.aI_ir21HyOQuCGujO9gPlKvnkqmhgTSQtqyotzEj2_U
M0T9blNo3lVvBwi93ozm.3MQ7bA.BJ8TPK2Gtk13vDYmVp1x7a9N90Omd3dg
nbzx9n2yKW0SF2UIMmWNh01.EdC19nLl6iysOTgxefV5UO3Ufi0ubvvHBf00
RteGq25qNMck94frWxYa3u4RWbx67qHylPWLvcOwBn_8Qg--
X-Originating-IP: [209.85.192.171]
Authentication-Results: mta1136.mail.gq1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO mail-pd0-f171.google.com) (209.85.192.171)
by mta1136.mail.gq1.yahoo.com with SMTPS; Fri, 18 Jul 2014 13:57:00 +0000
Received: by mail-pd0-f171.google.com with SMTP id z10so5088799pdj.30
for <[email protected]>; Fri, 18 Jul 2014 06:57:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20120113;
h=message-id:date:mime-version:from:to:subject:content-type
:content-transfer-encoding;
bh=rkXAljHpDJWDtLtOwxNOeiIBq3xi8CPiFsXhX0WWIC4=;
b=XN28J1/UlFF1XmXWQp4Wdo4+RwcX6NPv9VrAjYAO68WHZAlL285eDgg5bZmpLgg8vl
IIf99nwTaQ/vbYF9dYGn/5asPKJgGJah+E1n9fu4Oom/n2Kf3vikWDyVoDng2wb1UPCP
4Fez2Fbv0O5apGJY/yGFXU0nH6x0zP8wJyPzSo6kRAeHP76I4kIxUBH2jR1AX6SFjEWC
GWXE7nQSVo9A5I0QwN4ttI1yYX9gTZA8zSNRgxYJDJBsF79s2WpRLIPdjPlLlbm5orL6
h3fEJi9Ih6dRcn96y5lfPOIwFpT87LXjQV4bpinGXUt0QNihzxioSNUI2VZm5HqtoUin
huGw==
X-Received: by 10.66.66.133 with SMTP id f5mr5195832pat.81.1405691820023;
Fri, 18 Jul 2014 06:57:00 -0700 (PDT)
Return-Path: <[email protected]>
Received: from XS318170952198 ([122.10.117.198])
by mx.google.com with ESMTPSA id tl3sm23303107pac.41.2014.07.18.06.56.57
for deleted
(version=TLSv1 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
Fri, 18 Jul 2014 06:56:59 -0700 (PDT)
Message-ID: <[email protected]>
Date: Fri, 18 Jul 2014 06:56:59 -0700 (PDT)
X-Google-Original-Date: 18 Jul 2014 21:57:32 +0800
MIME-Version: 1.0
From: "Daniel Hall" <[email protected]>
To: Deleted
Subject: Welcome to GoGreatMall
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Content-Length: 927
Would love to take this guy down, I may try to stalk him for a long time as I was scammed for 200 dollars....
Just so you all know