Pages:
Author

Topic: HKCEx breaks the market. 8.88% bonus on deposit, high rates and more! - page 2. (Read 12510 times)

newbie
Activity: 58
Merit: 0
Thanks for the update!

Looks like the paypal address was a dead end, so the name (lavin lam) is also probably fake.

However it's possible they registered at Taka but with a different company name.
newbie
Activity: 49
Merit: 0
newbie
Activity: 58
Merit: 0
Bitcoinnews.hk just told me they're going to check it out.

I am meeting Detective Mok from Central police station at 5pm (09:00 GMT).  The information I will give him is as follows.  Is there anything I have missed?

Looks accurate from the information we have been able to obtain

Just one thing, MG Foreign Exchange Limited have denied any connection to HKCEx according to technode:

Quote
However, the MSO license number 14-02-01350, which is previously shown in the company’s website, is registered by heavy metal exchange MG Foreign Exchange Limited and a reader who claimed to have visited MG in Hong Kong said the company denied to have any relationship with HKCEx.
newbie
Activity: 12
Merit: 0
Please keep us in touch..
I'm very sorry I've started this topic. I've lost all my BTC as others Sad Sad Sad
sr. member
Activity: 278
Merit: 250
I am meeting Detective Mok from Central police station at 5pm (09:00 GMT).  The information I will give him is as follows.  Is there anything I have missed?



Company name: HKCEx
HKCEx is a registered trademark of MG Foreign Exchange Limited. CR.No 1979508. MSO Licence # 14-02-01350
 
Company address:
HKCEx
Belcher's Street, 56
Sai Wan, Hong Kong
 
MG Foreign Exchange address:
MG Tower on 133 Hoi Bun Rd. Kowloon
 
The web site owner’s details are obscured by privacyprotect.org (Queensland, Australia) I believe this company is being used to cover the fraud.  Privacyprotect is used to stop web site owners receiving junk mail, they say that they take illegal use very seriously, however they have not taken my allegation seriously.  Maybe they will take you more seriously.
 
To avoid hacking, they have hosted the site with cloudflare.com . They set this up after the problems started, adding weight to the case that they were hacked and not stealing money.  Cloudflare should have customer details on record, but again aren’t very willing to share information.
 
People:
Pheng Cheah (CEO)
Peng Tsou (Director)
Mr. Liang
Mr. Gang Fu
Chi Xu (Financial department)
Orlando James (Tech support)
Lavin Lam (Head of Marketing and PR)
 
More info on the people working there can be found at:
http://webcache.googleusercontent.com/search?q=cache:55P-OfxR0F0J:https://www.hkcex.net/about/management-team+&cd=1&hl=en&ct=clnk&gl=us
 
Latest update:
VNET is a company that have set up hosting services with Sunny Vision on behalf of HKCEx.

When I (CaptainClaw) contacted Sunny Vision and informed them of HKCEx's fraud, they took down HKCEx's server.


VNET have provided the following address:
Quote
Room 1408, 15F, SPA Centre, 53-55
Lockhart road
Wanchai
Hong Kong

We cannot verify if this address is accurate as VNET did not verify addresses.

VNET has this address from HKCEX's paypal information, but anyone with a prepaid card can setup a paypal account and enter fake information.

Domain was set up at Sunny Vision data centre in HK using the email address: [email protected]
 
newbie
Activity: 58
Merit: 0
Just sent the address to bitcoinnews.hk (the guys who checked out the original address and confirmed it was fake)
full member
Activity: 125
Merit: 100
Why not contact a hongkong based news station and tell them to  GO FOR IT, SEARCH ..
they would be first with such a ''story'' and maybe it's a win-win situation.

 Shocked
member
Activity: 97
Merit: 10
Man or woman?

The question is if the identity was just stolen or not? I guess it was Wink I mean, people hiding behind multiple VPN providers won't give their name to anyone.

Well, we just need to keep digging...
member
Activity: 97
Merit: 10
We must verify that address, telephone and that ip`is from another VPS service. We must ask too

Very well done, sir! I have a feeling we are getting somewhere in the end...


Following screenshots from Google Streetview








Even though this address is most likely a fake one, maybe they were not chosen randomly. Would be great if someone in HK could go there to have a look.
newbie
Activity: 58
Merit: 0
So in summary:

VNET is a company that have set up hosting services with Sunny Vision on behalf of HKCEx.

When I contacted Sunny Vision and informed them of HKCEx's fraud, they took down HKCEx's server.

Wu Haisheng works for VNET, and forwarded emails to and from [email protected] (address now inactive)

VNET have provided the following address:
Quote
Room 1408, 15F, SPA Centre, 53-55
Lockhart road
Wanchai
Hong Kong

We cannot verify if this address is accurate as VNET did not verify addresses.

VNET has this address from HKCEX's paypal information, but anyone with a prepaid card can setup a paypal account and enter fake information.

Our only lead is the above address, someone in Hong Kong want to go check it out?
member
Activity: 97
Merit: 10
Looking up hkcex.net on domainwhitepages.com we get the following traceroute which might be helpful to those who understand it. I don't Wink

Traceroute

Tracing route to hkcex.net [124.248.221.134]...
hop    rtt    rtt    rtt         ip address    fully qualified domain name
1    0    0    0         208.101.16.73    208.101.16.73-static.reverse.softlayer.com
2    0    0    0         66.228.118.157    ae11.dar02.sr01.dal01.networklayer.com
3    0    0    0         173.192.18.252    ae14.bbr01.eq01.dal03.networklayer.com
4    34    34    34         173.192.18.141    ae0.bbr01.cs01.lax01.networklayer.com
5    30    30    30         173.192.18.167    ae7.bbr02.cs01.lax01.networklayer.com
6    41    41    41         173.192.18.150    ae0.bbr02.eq01.sjc02.networklayer.com
7    132    132    132         50.97.18.161    ae0.bbr01.eq01.tok01.networklayer.com
8    140    140    140         50.97.18.163    ae7.bbr02.eq01.tok01.networklayer.com
9    183    183    183         50.97.18.167    ae0.bbr01.pn01.hkg01.networklayer.com
10    176    176    176         202.40.160.139    sunnyvision3-10g.hkix.net
11    184    184    184         123.242.225.10    te3-3.core3.hk01.hkngn.com
12    *    *    *            
13    *    *    *            
14    *    *    *            
15    *    *    *            

Trace aborted



The bold IP is referring to another domain HKIX.NET


Queried whois.internic.net with "dom hkix.net"...

   Domain Name: HKIX.NET
   Registrar: DOMAIN.COM, LLC
   Whois Server: whois.domain.com
   Referral URL: http://www.domain.com
   Name Server: NS1.CUHK.EDU.HK
   Name Server: NS2.CUHK.EDU.HK
   Name Server: NS3.CUHK.EDU.HK
   Status: ok
   Updated Date: 12-mar-2012
   Creation Date: 23-apr-1995
   Expiration Date: 24-apr-2021

>>> Last update of whois database: Sun, 01 Jun 2014 01:21:32 UTC <<<

Queried whois.domain.com with "hkix.net"...

Domain Name: HKIX.NET
Registry Domain ID:
Registrar WHOIS Server: whois.domain.com
Registrar URL: www.domain.com
Updated Date: 2012-06-26 23:41:31
Creation Date: 1995-04-23 04:00:00
Registrar Registration Expiration Date: 2021-04-24 04:00:00
Registrar: Domain.com, LLC
Registrar IANA ID: 886
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.6027165396
Reseller: MyDomain
Reseller: [email protected]
Reseller: +1.8004057875
Domain Status: ok
Registry Registrant ID:
Registrant Name: Network Administrative Contact
Registrant Organization: The Chinese University of Hong Kong
Registrant Street: Information Technology Services Centre G/F, Pi Chiu Building, CUHK
Registrant City: Shatin
Registrant State/Province: New Territories
Registrant Postal Code: 00000
Registrant Country: HK
Registrant Phone: +852.39438801
Registrant Phone Ext:
Registrant Fax: +852.26035001
Registrant Fax Ext:
Registrant Email: [email protected]


And the bold italic IP belongs to the domain HKNGN.COM


Queried whois.internic.net with "dom hkngn.com"...

   Domain Name: HKNGN.COM
   Registrar: ENOM, INC.
   Whois Server: whois.enom.com
   Referral URL: http://www.enom.com
   Name Server: NS1.HKSEEKER.COM
   Name Server: NS2.HKSEEKER.COM
   Status: ok
   Updated Date: 20-may-2014
   Creation Date: 17-jun-2013
   Expiration Date: 17-jun-2015

>>> Last update of whois database: Sun, 01 Jun 2014 01:27:49 UTC <<<

Queried whois.enom.com with "hkngn.com"...

Domain Name: HKNGN.COM
Registry Domain ID: 1809120000_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2014-05-20 02:37:53Z
Creation Date: 2013-06-18 01:26:15Z
Registrar Registration Expiration Date: 2015-06-18 01:26:00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252744500
Domain Status: ok
Registry Registrant ID:
Registrant Name: DOMAIN ADMINISTRATOR
Registrant Organization: JIAPEI GROUP LIMITED
Registrant Street: ROOM 604, WELLTECH CENTRE, PAT TAT STREET, SAN PO KONG,
Registrant Street: KOWLOON, HONG KONG
Registrant City: HONG KONG


As admitted, I don't know much about that stuff. Maybe you can find a hint...
member
Activity: 97
Merit: 10

However, the name they have replied with is Wu Haisheng


Any update regarding that trace?

I did a quick search on that name and found this guy very capable of setting up such scheme >>> http://www.linkedin.com/in/wuhaisheng

In general, the name is obviously all but common!

 Roll Eyes

Could we think they are changing server again? Or could we think they seal us?

Seems like they wanna be sure that they left no evidence which might identify them before they start moving coins. Once those crooks feel save, our moniez will be insta-gone...
member
Activity: 97
Merit: 10
I want to know Why BTC world like coindesk Cryptonews cointelegraph and others haven't notified anything about that Theme. if a lot of people are losing their savings funds.

The only reason why don't write freakin word can have two major reasons IMFAO.

First, they don't want to admit that they were promoting an obvious scam before. When HKCex allegedly collected $3m it was spread all over the major BTC "news" websites. By the way, it seems pretty obvious that Coindesk (e.g) is getting paid to promote shady companies accepting Bitcoin anyways. Just take a look at those trading platforms they write/wrote about. Usually, they are the worst one can find. And they know! Or don't ever research those companies, doing C/P journalism.

The other reason is quite simple. They are part of that scheme and are getting paid to shut up.

Well, both scenarios are, at least, not very unlikely Wink

Shame on those wannabe-journalists!

hero member
Activity: 672
Merit: 500
The guy we are looking for is mostly likely in china. China Unicom is a mobile netwrok in China, and QQmail he used almost only used in China. I think the IP addresses are a dead end, we should ask for the names of the identification used when registering for hosting from Sunny Vision.
newbie
Activity: 58
Merit: 0
Quote
(encrypted/useless parts removed)
Authentication-Results: hotmail.com; spf=pass (sender IP is 65.55.116.80) [email protected]; dkim=none header.d=live.jp; x-hmca=pass [email protected]
X-SID-PRA: [email protected]
X-AUTH-Result: PASS
X-SID-Result: PASS
X-Message-Status: n:n
Received: from BLU004-OMC3S5.hotmail.com ([65.55.116.80]) by BAY004-MC2F44.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22678);
    Fri, 30 May 2014 20:18:59 -0700
Received: from BLU436-SMTP63 ([65.55.116.72]) by BLU004-OMC3S5.hotmail.com with Microsoft SMTPSVC(7.5.7601.22701);
    Fri, 30 May 2014 20:18:59 -0700
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
Received: from smtpbg308.qq.com ([120.196.211.86]) by BLU436-SMTP63.smtp.hotmail.com over TLS secured channel with Microsoft SMTPSVC(8.0.9200.16384);
    Fri, 30 May 2014 20:18:57 -0700
X-HAS-ATTACH: no
X-QQ-BUSINESS-ORIGIN: 2
X-Originating-IP: 58.253.117.79
X-QQ-STYLE:
X-QQ-mid: webmail767t1401506333t130365
From: <[email protected]>
To: (REMOVED)
Subject: Re:My withdrawal
MIME-Version: 1.0
Content-Type: multipart/alternative;
Content-Transfer-Encoding: 8Bit
Date: Sat, 31 May 2014 11:18:53 +0800
X-Priority: 3
X-QQ-MIME: TCMime 1.0 by Tencent
X-Mailer: QQMail 2.x
X-QQ-Mailer: QQMail 2.x
X-QQ-SENDSIZE: 520
X-OriginalArrivalTime: 31 May 2014 03:18:58.0152 (UTC) FILETIME=[0F9AAE80:01CF7C7F]
newbie
Activity: 58
Merit: 0
Captain
Did they reply of [email protected]

No, I have his personal live.jp address from Sunny Vision.

personal live.jp address ? did you mean this is a hkcex person?
I think it is would be helpful to show this address public to all of us.

I don't know if it's just a throwaway, his actual address or an something else completely but it's the one he signed up to sunny vision with.

[email protected]

Any message I send I recieve this:

THAT twitter Account Bitcoin Ticker had been releasing prices of HKCEX the last time until dead
https://twitter.com/vonSchle
Somebody knows, it says located in San Fracisco and release a web which is not finished. Something BAD Honk hong and san francisco. We can search more.


Nice find, how did you find it?

The twitter page says San Francisco, the whois says it's located in Germany and it's a Hong Kong exchange that may have been based in Singapore...

Very odd that it only ever seemed to report HKCEx prices.

Edit:

Looking at the email headers, it seems [email protected] is a forwarding address to smtpbg308.qq.com

There was also this: X-Originating-IP: 58.253.117.79

From wikipedia:

Quote
The X-Originating-IP (not to be confused with X-Forwarded-For) Email header field is a de facto standard for identifying the originating IP address of a client connecting to a mail service's HTTP frontend. When clients connect directly to a mail server, its address is already known to the server, but web frontends act as a proxy which internally connect to the mail server. This header can therefore serve to identify the original sender address despite the frontend.

Could 58.253.117.79 be the IP of the sender?

Running it through WHOIS we find a Chinese ISP:

http://who.is/whois-ip/ip-address/58.253.117.79
newbie
Activity: 11
Merit: 0
Captain
Did they reply of [email protected]

No, I have his personal live.jp address from Sunny Vision.

personal live.jp address ? did you mean this is a hkcex person?
I think it is would be helpful to show this address public to all of us.
full member
Activity: 378
Merit: 100
hope you get your money back
member
Activity: 97
Merit: 10
wasn't it like sending 10 cents to the adress and add the HATE-NOTE in the field on top?


Yeah, but as correctly mentioned by MrWDunne already, they are probably going to tumble the coins and that is pretty much it.

But with those traces to specific individuals involved, we still have a good chance to get them back before they just disappear. Let's fucking hunt those cunts down! As I said earlier they were complete amateurs not knowing what exactly they are doing! Scam n0000bs so to say.

So, please keep this thread updated and pumping, fellas. We need any support now!


All the best!


member
Activity: 97
Merit: 10

However, the name they have replied with is Wu Haisheng

Interestingly, the name appears as a member of the bitcoin foundation.

Will update if I find anything else.

Are you fucking kidding? WOW, that would be a real blow!!!
Pages:
Jump to: