ss_blog_claim=88d0a386a6277415f42c9ee5561ded98

Latest MSN scam records usernames and passwords for spam



I just received a rather strange message from a friend on my MSN contact list. Naturally I was suspicious about any messages containing a misspelled .info domain and it seems my suspicions were correct about this one.

The site in question is pooop.info. You visit that site and enter your details at your own risk, although I highly advise that you do not enter your MSN account details anywhere except the Windows Live Messenger sign-in window.

The message I received looked something like this:

PARTY PARTY PARTY

http://[your friend's email account (the part before the @)].pics.pooop.info

The message other users are receiving may vary, so be vigilant.

So what’s the premise of this latest scam? A user basically voluntarily enters their MSN account details (email AND password) on the proviso they’re going to see their friend’s photos. The site is employing the tactic of a social networking site - sign-up to see your friend’s photos and it seems to be working. What most users don’t realise is that the fine print is spelled out clearly in their terms and conditions - which are linked in perfect sight above the sign-in box on the pooop.info website. Here’s the interesting part, their Terms & Conditions:

By filling out this form, you authorize TST Management, Inc to spread the word
about this 100% real and upcomming Messenger Community Site.
You will receive your share of the credit in helping us spread the word. This is a harmless
Community site which is offering users a platform to meet each other for free.

We do not share your private information with any third parties.
By using our service/website you hereby fully authorize TST Management, Inc to send messages
of a commercial nature via Instant Messages and E-Mails on behalf of third parties via the information
you provide us. This is not a “phishing” site that attempts to “trick” you into revealing personal
information. Everything we do with your information is disclosed here.
If you are under eighteen (18),
you MUST obtain permission from a parent or guardian before using our website/service.

This page is not affiliated with or operated by Microsoft(tm) or MSN Network(tm).

ANY LIABILITY, INCLUDING WITHOUT LIMITATION ANY LIABILITY FOR DAMAGES CAUSED OR
ALLEGEDLY CAUSED BY ANY FAILURE OF PERFORMANCE, ERROR, OMISSION, INTERRUPTION, DEFECT,
DELAY IN OPERATION OR TRANSMISSION, COMMUNICATIONS LINE FAILURE, SHALL BE STRICTLY LIMITED
TO THE AMOUNT PAID BY OR ON BEHALF OF THE SUBSCRIBER TO THIS SERVICE.

We may temporarily access your MSN account to do a combination
of the following:
1. Send Instant Messages to your friends promoting this site.
2. Introduce new entertaining sites to your friends via Instant Messages.

This is a free service. You will not be asked to pay at any time.
You will not be subscribed to anything asking for payment.
This service is made possible by many hours of human effort.

Messenger Profiles, Inc reserves the right to change the terms of use / privacy policy
at any time without notice. To view the latest version of this privacy policy,
simply bookmark this page for future reference.

You understand that this agreement shall prevail if there is any conflict between this
agreement and the terms of use you accepted when you signed up with MSN. You also
understand that by temporarily accessing your msn account, Messenger Profiles, Inc
is NOT agreeing to MSN’s terms of use and therefore not bound by them.

This agreement shall be construed and governed by the law of the Republic of Panama.
You expressly consent to the exclusive venue and personal
jurisdiction of the courts located in the Republic of Panama
for any actions arising from or relating to this agreement.

Copyright 2008 TST Management, Inc

I bolded the interesting part - your account may be accessed to spread the word - I believe it should say ‘your account WILL be accessed’ because that’s exactly what’s happening. You may also notice that the T&Cs are governed by the laws of Panama. I’m pretty sure I wouldn’t give my MSN login details to anyone, especially a site in Panama. But alas, here’s where it gets even more interesting. A whois of the site
reveals the site is actually owned by a group in Hong Kong called Blue China Group, Ltd.

I wanted to see if the site was actually real in it’s claims, so I signed up for a dummy hotmail account… I entered the account details perfectly and what do you know? ‘Login failed’. Where are the photos I was promised? It seems that they’re just harvesting more and more email accounts that most likely be used for spam. They say they’re not a phishing site, and technically they aren’t because the Terms & Conditions plainly state your account will be accessed by TST management (there’s another discrepancy in the company’s details. What ever happened to Panama and the Blue China Group?) but I wish people would just be more careful about what they do with their information.

So spread the word to your friends not to give out their sign-in information to ANYONE, especially pooop.info. Halt the spread of this site and hopefully stop the potentially tens of thousands spam emails that will result from it.

Update: The obvious solution to this problem seems to be to change your account’s password. It seems this harvesting scam is starting to snowball, so be vigilant. Just to reiterate, don’t EVER give out your MSN account’s password. SEE UPDATE #3 BELOW

Update #2: Thanks to the comment of a reader known as ‘d’, another website, srys.info, has been uncovered which is run by the same group of shameless scammers. A whois of the domain yields the same results as the whois of pooop.info. Thanks d!

Update #3: After reading around on the internet, some say this problem is actually a virus (probably a remade version of the ‘Should I put this picture of us on MySpace?’ and then your friend would send you a .zip file). I don’t think it’s a virus at all but I will try to find out. For now, stay vigilant and remind your friends to read this article if they are affected by the problem.

Update #4 (March 26): This article has gotten quite a bit of attention around the internet, including a news story on mess.be. Just an update on the list of sites that you may be linked to include:

rkntbp.info, vnxpkf.info, yzxvsn.info, jcyhzr.info, vnxpkf.info, xrsnbt.info, dytgms.info, qpcbkt.info, yqbzfj.info, yxwzmq.info, psnkcq.info, sxwmkr.info, tqxycj.info, wcmbsj.info, rhqwcp.info, qmnfct.info, rsbkdg.info, zjdgxq.info, mxbpkr.info, xjctsp.info, rhqwcp.info, mgtwdn.info, kfytsj.info, dsbpzg.info, gmnzby.info, dbnyzc.info, jcyhzr.info, dsbpzg.info, dbnyzc.info, bzjnxd.info, zjdgxq.info, qvsgwy.info, cdystp.info, hmybqw.info, yvmjzc.info, vmytks.info, nhcswv.info, ztmrcj.info, wkfbmt.info, fvkgcz.info, zcxrjb.info, jtyqkv.info, xhzsrg.info, hqnxmv.info, srbgxz.info, pghzvq.info, bgpmwr.info, ndkzcy.info, tpyhzx.info, etc…

It seems that most of the info domains now use skaq.info as the main site and are simply just ‘mirroring’ skaq.info (it is the same site just under a different domain). Continue to be wary of such sites.

Update #5 (April 24): So here I am again updating this article because the face of the threat has changed, yet again, in an attempt to trick more users. It seems they’ve started to use more logical domains (as reported by users in the comments) such as imagehosters.info and friendpixer.com. I believe this will catch more users out, so once again I reiterate DO NOT ENTER YOUR ACCOUNT DETAILS ANYWHERE OTHER THAN YOUR MSN CLIENT. I appreciate your updates in the comments on the different sites, etc. Keep them coming! Note some comments are being pushed into the moderation queue as spam - don’t worry, I check these and get them approved as quickly as possible. There is no need to resubmit your comment.

Help to spread the word by Digging this story.

If you liked this post, buy me a coffee!


139 Responses to “Latest MSN scam records usernames and passwords for spam”


  1. 1 d Mar 16th, 2008 at 11:03 am

    i got a very similar message from a friend of mine, and i’m ever-suspicious of any random website like this that asks that i enter the same username and password that i use for another service. it didn’t direct me to pooop.info, but srys.info instead. same format, with the friend’s username in the url. same page with a login screen and the TST Terms & Conditions.

    my friends are not unintelligent, but they are, perhaps, gullible. apparently that goes for quite few people out there–sad, but true.

  2. 2 Aeriff Mar 16th, 2008 at 11:37 am

    Thanks for the info, d! The post has been updated accordingly.

  3. 3 Ka Mar 16th, 2008 at 1:55 pm

    [quote comment=""][...] see. …The Unavoidable Obsession with Hillary Clinton&39s Dead End BuzzFlashblog.washingtonpost.comLatest MSN scam records usernames and passwords for spam I just received a rather strange message from a friend on my MSN contact list. Naturally I was [...][/quote]
    [quote comment="23324"]i got a very similar message from a friend of mine, and i’m ever-suspicious of any random website like this that asks that i enter the same username and password that i use for another service. it didn’t direct me to pooop.info, but srys.info instead. same format, with the friend’s username in the url. same page with a login screen and the TST Terms & Conditions.

    my friends are not unintelligent, but they are, perhaps, gullible. apparently that goes for quite few people out there–sad, but true.[/quote]
    well, i got that just a day ago and changed my password and everything is fine for now

    i guess the website is down as the message “403 - timeout” is displayed after i click on the link myself

  4. 4 a Mar 16th, 2008 at 10:08 pm

    update on another.
    flst.info that surfaced on my friend’s MSN.
    have searched the domain and is exactly the same as srys.info and pooop.info

  5. 5 a Mar 16th, 2008 at 10:16 pm

    another one.
    flst.info
    domain is same as srys.info and pooop.info
    yeah

  6. 6 F Mar 17th, 2008 at 9:51 am

    http://bulkbul.info/ is another one.

  7. 7 yo Mar 17th, 2008 at 11:01 am

    Same goes here with bulkbul.info.
    Actually this seems to be spreading in Estonia, and is out since St Valentine:

    http://morkiel.wordpress.com/2008/02/14/msn-msn-msn/

    There it was a link to
    http://misiganesnimi.partypicx.info/

    It’s not only “TST Management, Inc” - but also “MessengerProfiles, Inc”.
    The domains are secured with Whoisguard. Check
    http://www.afilias.info/cgi-bin/whois.cgi with bulkbul.info:

    Domain Name: BULKBUL.INFO
    Created On: 27-Mar-2007 11:11:07 UTC
    Last Updated On: 26-May-2007 20:42:28 UTC
    Expiration Date: 27-Mar-2008 11:11:07 UTC
    Sponsoring Registrar: eNom, Inc. (R126-LRMS)
    Status: OK
    Registrant ID: 3B6F183DBD6DB9DD
    Registrant Name: WhoisGuard Protected
    Registrant Organization: WhoisGuard
    Registrant Street1: 8939 S. Sepulveda Blvd. #110 -
    Registrant Street2: 732
    Registrant Street3:
    Registrant City: Westchester
    Registrant State/Province: CA
    Registrant Postal Code: 90045
    Registrant Country: US
    Registrant Phone: 1.6613102107
    Registrant Phone Ext.:
    Registrant FAX:
    Registrant FAX Ext.:
    Registrant Email: 3d77f55b452e4b8d852cf442c7604701.protect@whoisguard.com

    Just change your password in MSN/hotmail and you should be fine. You might also want to warn your contacts.

  8. 8 Joakim Sundén Mar 17th, 2008 at 7:14 pm

    Add http://www.bulkbul.info/ to the list…

    /Joakim

  9. 9 OverSoft Mar 18th, 2008 at 10:29 am

    Seems *.pics.skaq.info has the same site on it.
    Just received a MSN message with a link to this site and thought i’d research the company name on Google and found this site.

  10. 10 jb489 Mar 20th, 2008 at 6:30 pm

    [quote comment=""][...] Seems this particular blog has noticed a similar phishing attempt by the same individual(s) using more than one domain:Forged Euphoria - Latest MSN scam  [...][/quote]

    Same problem here but with a http://username.pics.skaq.info site.

  11. 11 Amro Mar 20th, 2008 at 11:11 pm

    http://www.enstaneette.com/ <— That’s one that is spreading rapidly in Finland. Asks for your messenger credentials and if you input them, you get a virus and it starts linking the site to all your contacts.

  12. 12 Johnny Hagstroem Mar 22nd, 2008 at 8:10 am

    [quote comment=""][...] Seems this particular blog has noticed a similar phishing attempt by the same individual(s) using more than one domain:Forged Euphoria - Latest MSN scam  [...][/quote]

    .pix.skaq.info

    is another site

  13. 13 Jonathan Mar 24th, 2008 at 5:06 am

    I’v got another one…. 03kem.info

  14. 14 dvda Mar 25th, 2008 at 3:55 am

    just got the *.03kem.info link also and the contact doesn’t know how they got her login info.

  15. 15 Legato Mar 26th, 2008 at 1:54 pm

    i got it too from my gf

    except its “images.05b7b.info/”

    i almost entered in my details cause it was from my gf but i was like wtf this doesnt seem right haha so lucky i didnt =]

  16. 16 Sarah Mar 28th, 2008 at 9:07 am

    I never signed up for anything/clicked on anything and I have this problem (my msn sends out the link).

    I don’t know how that happened but it has.

  17. 17 Aeriff Mar 28th, 2008 at 10:55 pm

    [quote comment="23749"]I never signed up for anything/clicked on anything and I have this problem (my msn sends out the link).

    I don’t know how that happened but it has.[/quote]

    There have been reports of this being a physical virus as well as people simply signing into your account. I suggest a full system scan with your antivirus software and changing your account’s password as an extra precaution.

  18. 18 angryman Mar 31st, 2008 at 6:17 am

    I just got a message from a friend pointing to http://his username].profilepics.info
    The address might look more legit than the randomly generated or misspelled ones, but is also owned by TST management, so watch out!

  19. 19 Joe Mar 31st, 2008 at 6:45 pm

    [quote comment=""][...] Seems this particular blog has noticed a similar phishing attempt by the same individual(s) using more than one domain:Forged Euphoria - Latest MSN scam  [...][/quote]

    What if you accidentally enter your information… and then quickly change the password right after it. And then the next day it doesn’t work. How is it possible? and most importantly… is there a way I can get my account back?

  20. 20 Aeriff Mar 31st, 2008 at 7:46 pm

    [quote comment="23830"]What if you accidentally enter your information… and then quickly change the password right after it. And then the next day it doesn’t work. How is it possible? and most importantly… is there a way I can get my account back?[/quote]

    If you changed your password you should be right, but as for getting your account back because you forgot the password - it’s going to be pretty tough.

  21. 21 Cal Apr 1st, 2008 at 12:30 pm

    http://(friends name).friendpics.info/

    I copped this one. Stupidly filled it in. Changed password immediately. Hope thats it.

  22. 22 Saša Apr 3rd, 2008 at 10:10 am

    Hello,

    Just to update the list. Seems like they started registering more logical domains. The new one is picfriender.info.

  23. 23 DoubleYou Apr 4th, 2008 at 2:27 am

    It looks like they moved to Panama now. The whois is giving a Panama location, and the same location is used for the following domains:

    http://www.localpics.info/
    http://maxcomments.com/

    Haven’t found more. The address they use is of a Panama law firm, and in the message they’re also stating something about ‘This agreement shall be construed and governed by the law of the Republic of Panama.’ Maybe they’re trying closer to home now, or they’re getting caught.

  24. 24 partybob Apr 6th, 2008 at 9:54 am

    [quote comment=""][...] #2: It seems that this is not new, Aeriff wrote a blog post on this on March 15th. The only difference is the more logical domain name (picfriend.info vs. [...][/quote]

    0ryh.info came to me today.

  25. 25 Joe Apr 7th, 2008 at 3:41 pm

    nooo there’s no way that I forgot the password that I changed it to. I wouldn’t use a password I’d never used before. It must have been changed while I was changing it also… =’[

  26. 26 JTW Apr 11th, 2008 at 9:46 pm

    Now also using c0olstuff.info

  27. 27 Al Apr 18th, 2008 at 11:46 pm

    [quote comment=""][...] a misspelled .info domain and it seems my suspicions were correct about this one. … http://www.forgedeuphoria.com/blog/2008/03/latest-msn-scam-records-usernames-and-passwords-for-spam/ forgedeuphoria.com [...][/quote]
    mine was 1c3q.info at the end, and of course I did not!

  28. 28 scott Apr 19th, 2008 at 12:21 am

    you can add this link to the list: http://jonigaloni.1fp9.info

  29. 29 nikhita Apr 20th, 2008 at 5:55 am

    http://.1ik5.info also…

    this virus is so widespread now it’s unbelievable!

  30. 30 Thai Apr 20th, 2008 at 9:48 pm

    http://.1ik5.info also…[quote comment="24597"]http://.1ik5.info also…

    this virus is so widespread now it’s unbelievable![/quote]

    I got this from my friend too! Why are MSN users today so easy to believe any lie into giving typing the MSN password now. Got to warn others.

  31. 31 Carl Apr 21st, 2008 at 11:44 pm

    They are linking to ausername.friendpixer.com now.

  32. 32 A friendly person Apr 22nd, 2008 at 5:14 am

    I also got one from http://very.c00l-stuff.com/
    Fairly different from .info ones. Bad sign !
    Thanks for the article.
    I wonder if we should report these sites in the phishing tool in firefox, as I did for the first link I received.

  33. 33 jennb83 Apr 22nd, 2008 at 1:40 pm

    Just recieved an instant message on msn and it is simply a website address. friendpixer.com
    But this has tst management terms and conditions. In the first lines of the terms and conditions it says “This is not a phishing scam.” The site asks for your msn email addy and password.

  34. 34 Kari J Apr 22nd, 2008 at 6:59 pm

    It seems that “they” have made it even more sophisticated - now containing the username of a hotmail account http://hotmail_username.friendpixer.com when sending…

  35. 35 joren Apr 22nd, 2008 at 7:05 pm

    [quote]They are linking to ausername.friendpixer.com now.[/quote]
    also just received one.

  36. 36 another one.... Apr 23rd, 2008 at 9:26 am
  37. 37 roro Apr 23rd, 2008 at 4:17 pm

    [quote comment=""][...] read more | digg story [...][/quote]
    [quote comment="24769"]imagehosters.info[/quote]

    yep, me too

  38. 38 roro Apr 23rd, 2008 at 4:18 pm

    gotta try to catch these clowns

  39. 39 Fredrik Apr 23rd, 2008 at 5:05 pm

    [quote comment=""][...] read more | digg story [...][/quote]
    http://imagehosters.info/ to add to the list

  40. 40 Zub Apr 23rd, 2008 at 5:42 pm

    contact who keeps sending me messages to “sign in here” etc pointing to above sites is now telling me ‘hii.. check out this.. http://real.amazing-stuff.info .. brb !!’

  41. 41 Aeriff Apr 24th, 2008 at 12:54 pm

    Your information is greatly appreciated, everyone. Keep the tips coming.

  42. 42 Ed Apr 25th, 2008 at 9:20 am

    msnname.myfriendz.info is another one….

    Registrant Email: tstmanagement@gmail.com
    Admin ID: a1c2f5cd1d7
    Admin Name: Mark Bradley
    Admin Organization: TST Management, Inc
    Admin Street1: edificio Magna Corp - 5th Floo
    Admin Street2:
    Admin Street3:
    Admin City: PANAMA
    Admin State/Province: PANAMA
    Admin Postal Code: 0000
    Admin Country: PA
    Admin Phone: 507.2021577

  43. 43 sec_e Apr 26th, 2008 at 9:44 am

    Hi,
    One of my friends received a message via MSN messenger telling to visit http://teh_sa.friendpixer.com/. She provided her IM account and its password few days later when she realized what it was. Is it just the IM account and password harvester?
    I am curious, because she sometime notified her account had been signed on when she signed on. She worries her message box is peeped and malicious use of her documents.

  44. 44 another Apr 26th, 2008 at 12:31 pm
  45. 45 Gabe Apr 28th, 2008 at 6:35 am

    A friend of mine also got one “http://xxxxxxxx.real.awesome-stuff.info”
    I told her to change pw and to warn the other contacts..
    Still, I looked around for a solution and found this: http://www.bleepingcomputer.com/forums/topic143796.html but I’m not sure if it’s a solution or if it’s all set up from the same one that spreaded this thing.

  46. 46 Aeriff Apr 28th, 2008 at 8:36 am

    @Gabe: I don’t think that file is a fix at all - no files were installed nor downloaded, only your password shared so it can’t be Malware. I think the process that was outlined on that forum was to get rid of the Malware that has been spreading like wildfire lately where the contact sends a zipped file claiming it to be a picture with a message like: ‘Do you mind if I put this picture of us on Myspace?’

  47. 47 Lazy May 6th, 2008 at 4:14 am

    Just got a message from my girlfriend who was offline.

    The url was next (username).this.are.the.fri3ndp1x.info

    Alarm straight away. As I knew that she is not online. Due to a customer meeting at work.

  48. 48 jojo May 7th, 2008 at 8:57 am

    got this one from a friend .was.found.by.fri3ndp1x.info
    I asumed the problem was in her computer(?) so i advised her to warn her contacts, change password, run antivirus and antispyware. Anything else?

  49. 49 JanR May 8th, 2008 at 12:27 am
  50. 50 Cato May 8th, 2008 at 3:32 pm

    Got a message from a site not mentioned here: http://xxxxxx.haha.they.have.taken.ph0t0s.info/
    It have the same Terms of Use / Privacy Policy from TST Management.

  51. 51 onitake May 13th, 2008 at 11:11 pm

    here’s one more: awes0me.info
    also owned by TST Management Inc.

  52. 52 itso May 16th, 2008 at 8:44 pm

    just got that link on my MSN
    http://ch33se.info/indexxx.php

  53. 53 Shawn Lee May 19th, 2008 at 12:30 pm

    Add http://www.p4rtyp1cs.com to the list…

  54. 54 Jonas Kronborg May 21st, 2008 at 1:59 am

    I got a similar message linking to [name_from_email].b00m.info. Checked the whois for b00m.info, owned by the same “TST Management, Inc”. Thought you might wanna add it to your list.

  55. 55 John May 22nd, 2008 at 12:38 pm

    meetp0int.info is also another mirror now

  56. 56 erlando May 25th, 2008 at 9:56 pm

    You can add checkdiz.info to the list of sites “run” by TST Management and Blue China Group.

  57. 57 Nazmi May 29th, 2008 at 7:35 pm

    my friend got it, it sent me hisUsername.snapsh0t.info

    does any one know how to remove it?

    thanks

  58. 58 ABlogger May 31st, 2008 at 1:31 am

    Hi,

    Nice article. I believe TST Management are registering their domains with Enom. You could use eNoms report abuse form to report them http://www.enom.com/help/abusepolicy.aspx.

    Regards,
    PGJ

  59. 59 Doahd002 Jun 2nd, 2008 at 4:42 pm

    Anothher site is *randomword (for mine it was my friends name)*.ther1ng.info

  60. 60 Luke Jun 3rd, 2008 at 8:36 am

    http://lefety.b0unce.info

    Add it to your list?

  61. 61 Kuroreon07 Jun 3rd, 2008 at 7:47 pm

    Here’s another latest one i hope so … got it from my friend and as i thought same scamming technique like “whoblockyou”

    here’s the address:
    http://(myfriend’saccount).flatl1ne.info/

  62. 62 Lars Sjöström Jun 4th, 2008 at 8:01 am

    There is a scam that has .jumphost.info I guess. It is their way of
    doing these scams.

    Nasty.

    Funmobile is another company to look out for. Nasty too. In short if you enter a pin (after entering your sms number) they charge the cell phone bill 6-7 USD A WEEK!!! So…they will scam you (our children) for 28 USD until the next bill…

  63. 63 n Jun 4th, 2008 at 12:16 pm

    The site is alwayse changing.
    It is now jumphost.info.

  64. 64 Eb' Jun 6th, 2008 at 2:18 am

    New dns: freakpics.info

    Ciao =)

  65. 65 oranges Jun 13th, 2008 at 7:56 am

    [email].h0t-pics.info

    another one! Jesus christ thank god I did a whois on the domain because I got suspecious. 2 google searches and I get here.

    Remember people, don’t click weird links :)

  66. 66 Dreamflux Jun 15th, 2008 at 11:39 am

    http://www.picmarker.info is another one of these “TST sites” …. it got me and my girlfriend… changed all our passwords… hopefully it was fast enough.

  67. 67 caelyn Jun 15th, 2008 at 7:34 pm

    The same here goes for the imgcheck.info domain…

  68. 68 Yaniv Jun 16th, 2008 at 5:10 am

    just got sent a link to loadpics.info
    “tst management” like the others

  69. 69 Danos Jun 17th, 2008 at 5:22 am

    I keep getting a message from a friend of mine when he is offline with the same terms and conditions asking for login details, At first I thought it was a web chat as I thought he may have been having problems with his MSN. Thankfully I took a closer look because I thought it looked so fake and didn’t end up entering any details as I’m usually quite careful when it comes to stuff like this. The URL was imgchecker.info All I can say is be careful people.

    Danos Out….

  70. 70 Zwelgje_NL Jun 17th, 2008 at 6:53 am

    just got sent a link to http://email.y0urpic.info/
    and again “tst management” like the others

  71. 71 Cindy Jun 18th, 2008 at 1:55 pm

    I got one from my boyfriend and I knew right away it was not good..

    it is http://username.image-banana.info

    I just asked him to change his password info … hope that works..

  72. 72 kaiwin Jun 23rd, 2008 at 5:42 am

    Another http://(Any kind of random name here).imagegallerys.info/
    Anyone want to come with me to Panama to destroy their servers?

  73. 73 Chayolle Jun 23rd, 2008 at 11:21 pm

    Great article, but one question remains, how to remove it???

  74. 74 Aeriff Jun 24th, 2008 at 7:59 pm

    @Chayolle: Just change your account’s password. As I said in the article, nothing is installed on your computer.

  75. 75 Neil B Jun 27th, 2008 at 1:54 pm

    Thanks for the post, I got the exactly same kind of link sent to me, only the name is different: this time it is imagecherry.info

  76. 76 Lily Jun 28th, 2008 at 1:21 am

    username.imagequick.info
    was the one I got sent tonight
    Also owned by TST. They’re rife!

  77. 77 James Jun 29th, 2008 at 2:53 pm

    A new one:
    imagekick.info/

    Alas this one got me, but I realized what it was about the time I clicked login *smacks forehead I changed my password instantly and hopefully it didn’t send to all of my contacts U.U

  78. 78 Jez Jul 4th, 2008 at 7:22 am

    Another URL for the list .imageh0sting.info

  79. 79 Rich Jul 4th, 2008 at 10:34 pm

    Another one: imageloco.info

    Whois shows it is owned by TST Management

  80. 80 another phishing website by TST Jul 5th, 2008 at 7:00 pm
  81. 81 gcap Jul 6th, 2008 at 2:36 pm

    i got one from imagepenguin.info

  82. 82 Moby Jul 8th, 2008 at 10:59 pm

    hosthdd.info is also a site you’d want to steer clear of. I mean, a friendwhom I’ve never talked to on MSN sent me this. Go figure.

  83. 83 aka Jul 10th, 2008 at 1:22 am
  84. 84 JaJaWa Jul 10th, 2008 at 8:10 am

    Here’s a log of mine: I edited the names:

    Messenger Plus! Chat Log
    Session Start: 09 July 2008

    * Me (me@domain.com)
    * friend_name@hotmail.com (friend_name@hotmail.com)

    (22:08) friend_name@hotmail.com: http://friend_name.holyimage.info

    http://get-that-stuff.info
    (22:12) friend_name@hotmail.com: http://friend_name.imagefrosty.info

    http://get-that-stuff.info

    I wasn’t gullible enough to fool for it. Found this site on Google so thought I’d post these.

  85. 85 Shadyman Jul 10th, 2008 at 12:42 pm

    I reported four of them to the registrars, MSN and yahoo. (hostapic.info, imagefrosty.info, get-that-stuff.info, and imagegallerys.info)

    The results of my reporting are available here: http://erroraccessdenied.com/node/1635

  86. 86 st1234 Jul 17th, 2008 at 11:58 pm

    just got one of thes thru my girlfriendsw contact know shes at work so ive signed in on an old messenger account and blocked all the old contact list, then entered my password and old email when i sign bk into messenger will the contacts be unblocked? i take it this is done by a software program and not manually? my contacts were still blocked hence they cant send an im!

  87. 87 not important Jul 18th, 2008 at 4:36 am

    add disco-fevers.com to the list.

  88. 88 Fuzzball Jul 18th, 2008 at 7:14 am

    .disco-fevers.com is another one of these websites incase it has not been mentioned.

    The website is owned by the TST group (apparently).
    This is a clever website as the domain (with the recipitents email) is only made at the time the message is sent via an instant message. Therefore putting random crap in this section will register as a site error.

    eg of situation

    Victem@domain.com “sends” the message to Bogus@domain.com

    in this case the link sent will be bogus.disco-fevers.com

    Could be worth adding as this is clearly going around.

  89. 89 wishmaster Jul 19th, 2008 at 3:21 am

    Another one:
    username.findthatt.com

  90. 90 Olesquire Jul 19th, 2008 at 7:12 am

    The latest scam site is http://www.imgers.com/

    I reported this to US-CERT.

    Please submit reports about phishing sites to phishing-report@us-cert.gov

  91. 91 ghetto_reality_coin Jul 20th, 2008 at 4:35 pm

    One of my friend keep sending me a link while she is offline. (computer off, perhaps)

    http://xxxx(my ID).disco-fevers.com/

    I was really annoyed by that, and then I went to Mozilla.org to report the site as forgery website.
    After that, I thought I might be able to do more about it, so, I went to FBI website and reported this website, and gave them the information I’ve collected about the site. (whois)
    As I checked today, when I use firefox (mozilla product), the site was marked as forgery. Then, I use IE to check this site, and the screen show the site is no longer exist.

    I think everyone should do whatever possible to eliminate those rats.

    (ps. that website is hosted by a U.S. company)

  92. 92 Nomen Nescio Jul 22nd, 2008 at 1:18 am

    Another one: catchedyou.com

  93. 93 Paul S Jul 22nd, 2008 at 3:25 am

    Another domain
    username.youphotoz.com

  94. 94 sea town Jul 23rd, 2008 at 3:38 am

    .torrocheck.com, same TST Mgmt company in whois

  95. 95 Serina Jul 23rd, 2008 at 6:51 am

    Well they just hit our messengers at work and the most recent site is below:

    Most recent site is http://wwww.imgchecka.com

    Sadly, it uses your first and last name (on mine) so it looks legitimate until I googled it.

    Thanks for the heads up.

  96. 96 Milzyman Jul 23rd, 2008 at 8:56 am

    all you need to do is change your password and your all sorted again!!!

  97. 97 trippelA Jul 23rd, 2008 at 7:48 pm

    I got it today
    Maybe it’s enough to change password, but it also insert a Trojan to the system.
    TROJ_SHUTDOWN.BG

    The Trojan close down your MSN connection, and you get a message that you are logged one at an other machine.

  98. 98 joe Jul 25th, 2008 at 5:06 am

    hey thx 4 the heads up
    I use msn mobile and i was logged on with my girlfriend
    Next to me.suddenly i got a instant message from her
    and she was next to me. Same thing as before…

    It was http://*my user name es. John*.torrocheck.com/
    Lets beat those wankas!

  99. 99 Mike Jul 28th, 2008 at 5:17 am

    Mine was .sh0tz.com

    if you also go to http://www.sh0tz.com it take you to the same page…

  100. 100 n0b Aug 1st, 2008 at 12:19 am

    I just got one for http://friendlypixx.com/ today.

  101. 101 L Aug 1st, 2008 at 4:51 am

    another domain: username.whosthatt.com

  102. 102 chanx Aug 2nd, 2008 at 2:43 am

    I got one for http://www.CrazyThingx.com. I did not do a whois, but I bet it’s the same guys.

  103. 103 june Aug 4th, 2008 at 4:54 pm

    i have got one from my fiend,http://june.11.thatzyou.com/
    just like a foolish man, now i have changed my passwords. i don’t know what will happend.

  104. 104 Karl Aug 5th, 2008 at 2:52 am

    Ive had several of these today.

    Thought i had better share the last two

    http://is-dat-u.com/
    http://is-thatt-you.com/

    It came to me on MSN Messenger with e.g karl.is-dat-u.com, karl.is-thatt-you.com

    Both the same as mentioned above.

    Same company!

    Cheers

  105. 105 Jean Reis Aug 5th, 2008 at 4:05 am

    Hi,

    I was googling around for more info about that obvious scam (I like the Terms and Conditions though, pretty honest), and found your blog. Add this one to the list:

    .is-thatt-you.com/

    This one was sent by a friend of mine, with *my* username in the address, I don’t know if it’s always like that?

  106. 106 coinz87 Aug 5th, 2008 at 6:40 pm

    ok have also recived a message but only it is coming from my mom lol yea i kno but still we both use the same computer but it only happens from her acc. and the message reads as this ((coinz87.myfriendsz.com/))) so what it is doing this time is taking who’s ever e-mail and using it right in the message just thought i would let ppl kno and hey thanks for the website

  107. 107 Michael Laddie Aug 7th, 2008 at 9:30 pm

    Hi.

    Found this artlice after receiving a strange link from a friend.

    The link was http://msn-name.picfriendz.com:81

    Just thought id let you know.

    Michael.

  108. 108 Andreas Aug 8th, 2008 at 7:57 am

    I got this from a friend: xyz.imgfriendz.com where xyz is my msn-username, also by TST Management.

  109. 109 E Aug 9th, 2008 at 12:46 am

    Our company got hit with this today. What a mess! Pay attention to any message boxes from Messenger telling you that you are signed in to another computer. Change your MSN password ASAP!

  110. 110 Peter Sørensen Aug 10th, 2008 at 9:24 am

    Just receved a message from a offline contact: peter.imguser.com.

    I clicked the link, and created a new msn called AntiMsnHacker@live.dk

    I tried to log in with my new email and password but it failed. Or did it.

    I didn’t log of MSN that day and nect morning i was offline…

    I did a whois on imguser.com and the owner of it is also TST Management.

    Later same day i wrote an email to tstmanagement@ymail.com and support@NameCheap.com

    Not because i think it would help, im just so tired of receving those messages form my stupid friends HEHE..

  111. 111 bunny Aug 13th, 2008 at 10:37 am

    summarypic.com

    tst management, as usual
    someone needs to stamp that guy out. and perhaps MSN live can block his IPs, he has to be
    signing in to hundreds of gullible accounts to send this dreck.

  112. 112 Michael Aug 15th, 2008 at 2:19 am

    Just reported another one of their sites to Microsoft’s piracy address (ok, so it’s not really piracy, but I couldn’t find an address for reporting phishing): yourpiczz.com

    I fell for it the first time, stupidly, then quickly changed my password so they couldn’t spam my contacts.

  113. 113 Rezzy Aug 15th, 2008 at 9:19 am

    There’s a new domain picslists.com Usually sent as: http://receivernickname.piclists.com

  114. 114 sexymonkey Aug 16th, 2008 at 2:27 am

    http:(usernamepicthanks.com or something similar - keeps coming from a couple friends of mine with my username in it!

    Ever since the msg, my antivirus has detected a trojan and my ebay account was hijacked! BEWARE!! I HAD TO PROVE MYSELF TO EBAY to get my account back and have now changed every single password for every site I may have accessed since getting the message.

    p.s. I have NEVER in over 15years of internet and downloading had a virus, worm or otherwise.

    PLEASE BE VERY AWARE AND CHANGE PASSWORDS, CHECK ACCOUNTS ETC AND RUN ALL VALID AND LEGIT ANTI SPYWARE/ ANTI VIRUS AND SO ON

    I got some trojan/ agent found on my lappie :-(

    Hope no one else has had this problem!

  115. 115 sexymonkey Aug 16th, 2008 at 2:30 am

    btw, if u do find any trojans or such like, there is great help on the majorgeeks.com website

    right, off to kill off this trojan! wish me luck

  116. 116 juls Aug 16th, 2008 at 12:52 pm

    just got a msn from someone from Wayn.com he just left a link never said anything else and when u click on, it say login with r msn email and password.. i read the terms inconditions and got a chill up my spin…. so i just googled tst management and got this site…. thankgod.

  117. 117