ABP Properties Fraud
Report
Active
Domain
Don't Bear Internet Fraud
Home
Bobbear Icon

ABP Properties banner.

ABP Properties is from the same criminal gang as the Silverlens,
Creovision and Neolenses frauds. The scam is identical to the criminal's previous CBA Properties scam. Like those frauds it uses a website stolen from a genuine company in order to try and lend legitimacy to the usual money laundering mule job. It is also hosted on the usual zombie botnet which guarantees its bogus & criminal nature even without the ample other evidence as documented below. A site contact tells me that the work agreement form she received from CBA Properties bore the company name of Silverlens, confirming the link beyond any doubt.

The 
ABP Properties website has been stolen from the genuine property company Property Frontiers who needless to say have nothing to do with this fraud - they are as much a victim as anyone else who falls for this scam.

The ABP Properties spam subjects usually include "Amazing job opportunity. Home-based.", "Real Job Offer with paid trial.", "Customer Service Representative vacancy. High salary!",  "Home-Based Job position. PAID TRIAL!",  but the one thing in common is the offer of a job as a money laundering mule that will lose you lots of money, get your bank account(s) and all your assets frozen and have you facing criminal charges - don't do it!

This fraudster should not be confused with any legitimate company of the same or similar name - the above website screenshot and the included money laundering job clearly identify the fake website and these fraudsters.

Current Zombie Botnet Host

ns1.cochn.com [65.75.190.243] - WEBHOSTPLUS-INC (carohosting.net) - Notified 1st. April 2008

The ethical majority of service providers, (all credit to them), act within 1-24 hours of being informed of the criminal abuse of their system, (the best in less than 1 hour), but there are unfortunately a few that do not, for one reason or another.


Known Website Domains

abpinvest.net
 (Parked)
abpgroup.net (DNS Looped)
abprops.net (Parked)

Nameserver Domains

cochn.com
 (Parked)

Registrar

REGISTER.COM, INC. (19-Mar-2008)
KEY-SYSTEMS GMBH (19-mar-2008)
REGISTER.COM, INC. (19-Mar-2008)



SpiritDomains/IARegistry (13-Mar-2008) 

Note for registrars
The criminal uses a zombie botnet to host all his website domains. That means that he has to register his own zombie botnet nameserver domain as he cannot use a legitimate DNS. It therefore follows that any domain in your database which has the current zombie botnet nameserver, (ns1.cochn.com
) in the whois data IS zombie botnet hosted and IS a domain registered by the same criminal for the same criminal purposes. Would you please search for all the criminals domains, suspend them and delete the DNS data. Thank you.

Zombie Botnet DNS Data (abpinvest.net, abpgroup.net and abprops.net)
How I am searching:

Searching for abpinvest.net A record at d.root-servers.net [128.8.10.90]: Got referral to M.GTLD-SERVERS.net. (zone: net.)
Searching for abpinvest.net A record at M.GTLD-SERVERS.net. [192.55.83.30]: Got referral to ns1.cochn.com. (zone: abpinvest.net.)
Searching for abpinvest.net A record at ns1.cochn.com. [208.116.44.58]: Reports abpinvest.net. Response:
DomainTypeClassTTLAnswer
abpinvest.net.AIN1800121.137.245.192
abpinvest.net.AIN180064.113.81.204
abpinvest.net.AIN180076.111.24.146
abpinvest.net.AIN180085.120.191.96
abpinvest.net.AIN180089.32.94.21
abpinvest.net.NSIN1800ns1.cochn.com.
abpinvest.net.NSIN1800ns2.cochn.com.
ns1.cochn.com.AIN1800208.116.44.58
ns2.cochn.com.AIN180078.80.12.10

Looking up at the 2 abpinvest.net. parent servers:

ServerResponse
ns1.cochn.com [208.116.44.58] 121.137.245.192 64.113.81.204 76.111.24.146 85.120.191.96 89.32.94.21
ns2.cochn.com [78.80.12.10]Timeout

The DNS data shows a standard 5-IP zombie botnet where the nameserver ns1.cochn.com hosted by FortressITX of Clifton NJ on IP 208.116.44.58 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). The nameserver domain, (cochn.com - Spiritdomains/IARegistry) is by definition registered by the criminals as they cannot use a legitimate DNS server to host a zombie botnet.

Evidence of Criminal Fraud:

i) Site theft - the website content is clearly stolen from the genuine company Property Frontiers.

ii) The website is hosted by the usual zombie botnet as demonstrated by the DNS data above - that in itself is ample evidence that the site is not legitimate.

iii) Spam received by site contact - sample below.


iv) Fake Location Details from site 'Contact Us' page:
Phone: + (44) 208 144 4205
Fax: + (44) 207 084 7790

One Britton Street
London EC1M 5NW


The address
One Britton Street is the location of the genuine property agents Hurford Salvi Carr and not these criminals. The telephone and Fax. numbers are for different London exchanges. Several test calls to + (44) 208 144 4205 were all picked up by an answering machine.

v) They claim on their website to be a founder member of the UK Property Professional's Association, the AIPP. In fact they are not listed in the association's database.

vi) Their multiple domains for the same website were all registered in the last week or two.

vii) They claim on their website: "We cover the majority of the worlds’ emerging property markets and are continuously seeking to expand our coverage. Currently we have over 9,000 properties listed over 40 countries", however, this particular bogus company has no internet presence other than as spammers and scammers. They also claim in the spam: "the world's leading integrated real estate services Company with offices in more than 350 markets across 40 countries worldwide" but they don't list any of their 'offices' on their website.

viii) On the Application Form the CV is optional! What sort of company would recruit just anyone without even a CV? - A money mule recruiter, that's who.

ix) The registration whois data is hidden using 'Domain Discreet'. What sort of company does that? You guessed it - a criminal one.

Job (From the website):
 

Vacancy Number: SVC37-322
Opening Date: 24/03/08
Closing Date: Open until filled
Position: Administrative Coordinator
Salary: AUD$66,000 after tax annually
Duty Location: AUSTRALIA

We offer an exciting and rewarding career opportunities for a new Administrative Coordinator to join an Australian team on the work-from-home basis.
Working within a service team of eighteen other personnel, this is a fantastic opportunity to gain permanent employment after a two weeks trial period if you are able to prove your abilities and commitment to the position.

- administration of current real estate database
- updating information on existing properties which are currently for salee
- handling customer enquiries via email
- building strong relationships with property owners and buyers
- plan, prioritise and manage own daily workload

Wages: When benefits and bonuses are added to the base salary, the average total compensation for this position would be AUD$66,000 after tax annually.

Working hours: Monday to Friday, 10am - 5pm (EST Australian Time) with 1 hour for lunch. Part-time positions are also available: Monday to Friday, from 10am to 1pm (EST Australian Time).

Successful candidates will be posses the following:

- Excellent communication and time management skills
- A personal desire to achieve
- Basic computer skills
- The ability to work autonomously
- Superior customer service skills

To the successful applicants we offer a position on a 2 weeks trial basis. During this trial period you will be receiving training and online support while working and being paid.

If you are interested in this vacancy and you feel, that your qualifications correspond to our requirements, please fill in an application form .
It is well disguised, but the actual part-time working from home function of anyone who applies for this position will turn out to be simply "Supporting the Financial Representative when required", (it's exactly the same as the Silverlens, Neolenses & Creovision job), and will consist of receiving stolen/counterfeit checks into your account and transferring them back to this criminal less 10% for yourself - the illegal money mule function.

Feedback, (in confidence), from anyone who has applied for this job would be appreciated.

Spam

HOME-BASED Job Offer            

Hello,

ABP Properties is a leading International property investment company with many thousands of properties in many different geographic locations. Due to the continued growth we have an exciting new opportunity for YOU to join the world's leading integrated real estate services Company with offices in more than 350 markets across 40 countries worldwide.

We are looking for Administrative Coordinator to join our team on the Work-from-Home basis. Offering an attractive salary package with first class paid training.

This role involves:
- administration of current real estate database
- updating information on existing properties which are currently for sale
- handling customer enquiries via email
- building strong relationships with property owners and buyers
- plan, prioritise and manage own daily workload

Wages: AUD$66,000 after tax annually + Super. Sick leave and holidays pay.

Working hours: Monday to Friday only. Full and part time positions are available.

To be considered for the role, you will ideally have:
- Excellent communication and time management skills
- A personal desire to achieve
- The ability to work autonomously
- Superior customer service skills

If you are interested in this vacancy and you feel, that your qualifications correspond to our requirements, please visit www.abpinvest.net to fill in an application form.

Thank you for your interest to this job.
Sincerely,

ABP Properties.


The above evidence clearly demonstrates that the ABP Properties website is a stolen fraudulent website set up with intent to deceive. If you are an abuse team that has received an abuse report regarding these fraudsters, please consider immediate termination of their services in view of the absolutely undeniable evidence of criminal fraud - please don't delay - these criminals will not respond to any communication from you, (all their whois data will be false), but will simply take advantage of any attempt at communication as a delaying tactic to allow them time to carry on their criminal activity and prepare their next network.

Fraud Log

Webpage created 31st. March 2008

***Latest News*** 1st. April 2008
The criminal has moved his zombie botnet onto a SoftwareWorks Group, Inc./WEBHOSTPLUS-INC (carohosting.net) IP (65.75.190.243):
Zombie Botnet DNS Data (Valid for domains abpinvest.net, abpgroup.net and abprops.net)
How I am searching:

Searching for abpgroup.net A record at g.root-servers.net [192.112.36.4]: Got referral to C.GTLD-SERVERS.net. (zone: net.)
Searching for abpgroup.net A record at C.GTLD-SERVERS.net. [192.26.92.30]: Got referral to ns1.cochn.com. (zone: abpgroup.net.)
Searching for abpgroup.net A record at ns1.cochn.com. [65.75.190.243]: Reports abpgroup.net. Response:
DomainTypeClassTTLAnswer
abpgroup.net.AIN180089.32.94.21
abpgroup.net.AIN180071.108.111.48
abpgroup.net.AIN180071.192.111.168
abpgroup.net.AIN180076.111.24.146
abpgroup.net.AIN180085.120.191.96
abpgroup.net.NSIN1800ns1.cochn.com.
abpgroup.net.NSIN1800ns2.cochn.com.
ns1.cochn.com.AIN180065.75.190.243
ns2.cochn.com.AIN180078.80.12.10

Looking up at the 2 abpgroup.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.cochn.com [65.75.190.243] 71.108.111.48 71.192.111.168 76.111.24.146 85.120.191.96 89.32.94.21
ns2.cochn.com [78.80.12.10]Timeout - Fake nameserver, (never resolves).

The DNS data shows a standard 5-IP zombie botnet where the nameserver ns1.cochn.com hosted by SoftwareWorks Group, Inc./WEBHOSTPLUS-INC (carohosting.net) on IP 65.75.190.243 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). The nameserver domain, (cochn.com - Spiritdomains/IARegistry) is by definition registered by the criminals as they cannot use a legitimate DNS server to host a zombie botnet.

October 10th. 2008 - no active domains known - consign to archive. Please notify me of any active domains.