Another mining scam made its exit today.
The following is info I was able to collect on their operation, and I hope this information helps anybody who got ripped off by these criminals.
The phone number given by fflak mining is the same as the phone number on this site:
http://www.comptroub.com.hk/The address listed on this site is 2/F, Dah Sing Life Bldg, 99-105 Des Voeux Road Central, Central, Hong Kong
different than given from the fflak mining site: The New World Tower, 16 Queen’s Road, Central, Hong Kong
IP history results for fflakmining.com.
==============
IP Address Location IP Address Owner Last seen on this IP
104.18.37.239 United States Cloudflare, Inc. 2018-01-27
104.18.36.239 United States Cloudflare, Inc. 2018-01-27
167.114.213.199 Montreal - Canada OVH Hosting, Inc. 2017-08-18
164.132.212.72 France OVH Static IP 2017-08-18
107.161.23.204 Atlanta - United States RamNode LLC 2017-08-18
2017
Aug 20
Changes on that date
Removed ns3.dnsowl.com
Removed ns2.dnsowl.com
Removed ns1.dnsowl.com
Added serena.ns.cloudflare.com
Added chuck.ns.cloudflare.com
Old DNS info:
> dig fflakmining ns1.dnsowl.com A +short
198.105.244.64
198.105.254.64
198.251.84.16
173.254.242.221
185.34.216.159
> dig fflakmining.com ns1.dnsowl.com A +short
188.166.204.107 <-- this one looks interesting
http://188.166.204.107185.34.216.159
173.254.242.221
198.251.84.16
> dig fflakmining.com ns2.dnsowl.com A +short
188.166.204.107
168.235.75.52
104.143.9.16
64.32.22.100
>dig fflakmining.com ns3.dnsowl.com A +short
188.166.204.107
70.39.125.242
45.63.5.234
209.141.39.150
Other known domains/sites: fflak.com litemihub.com (all taken down at the same time as fflakmining.com)
The links in their emails lead to
https://u5956394.ct.sendgrid.netHere is some header information from an email reply I got from "Charlie" -
[email protected]:
X-Originating-IP: [135.84.80.217] Authentication-Results: .....yahoo.com from=fflakmining.com; domainkeys=neutral (no sig); from=fflakmining.com; dkim=neutral (no sig) Received: from 127.0.0.1 (EHLO sender-of-o52.zoho.com) (135.84.80.217) by ...yahoo.com with SMTPS; Wed, 20 Dec 2017 16:23:11 +0000 Received: from mail.zoho.com by mx.zohomail.com with SMTP id 1513786989701737.825572623641; Wed, 20 Dec 2017 08:23:09 -0800 (PST) Date: Wed, 20 Dec 2017 14:23:09 -0200 From: Hiring FFLAKMINING
[email protected]And their vimeo account:
https://vimeo.com/user72246105Interesting links:
https://www.linkedin.com/in/fred-fischer-7a44605a/http://business-services.scmp.com/services-directory/office-it-services/computer-troubleshootershttps://hongkong.asiaxpat.com/directory/arts-culture-education/computer-training/1c1ac0f3-6cc7-43c4-a41d-e31912d4dd16/cts-pc-support-centre/http://www.comptroub.com.hk/contacushk.htmAnother match for the phone number in this forum thread:
https://www.kaskus.co.id/thread/000000000000000000873755/all-about-hong-kong-ii/240+&cd=12&hl=en&ct=clnk&gl=usHere is a site mentioned in that thread:
http://www.hkfix.net/en/Further investigation shows us this is a franchise business (look at all the white people in the staff picture, pretty strange for an asian business).
https://www.technology-solved.com/