Bitcoin Forum
April 26, 2024, 02:35:18 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 »  All
  Print  
Author Topic: Scam Alert : TimeToBit/timetobit.com Scammed 3.38 BTC  (Read 15842 times)
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 02:51:56 PM
 #1

What happened::
I ordered a 'cloud mining contract'  for 1 TH/s for 3.38btc on 15/8/2014 from this site, but they payouts remain as pending and the customer support does not respond to email, and their 'Live Chat' is always offline.

Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=348062

Reference Link: http://www.timetobit.com
Amount Scammed:3.38btc
Payment Method: bitcoin
Proof of Payment: https://blockchain.info/tx/5a7de5462f40e24b9b74b1d07c3427cec89791378392c2b5213d45f1ad018337
Additional Notes: Do not buy cloud mining contracts from timetobit.com
1714142118
Hero Member
*
Offline Offline

Posts: 1714142118

View Profile Personal Message (Offline)

Ignore
1714142118
Reply with quote  #2

1714142118
Report to moderator
Bitcoin addresses contain a checksum, so it is very unlikely that mistyping an address will cause you to lose money.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714142118
Hero Member
*
Offline Offline

Posts: 1714142118

View Profile Personal Message (Offline)

Ignore
1714142118
Reply with quote  #2

1714142118
Report to moderator
1714142118
Hero Member
*
Offline Offline

Posts: 1714142118

View Profile Personal Message (Offline)

Ignore
1714142118
Reply with quote  #2

1714142118
Report to moderator
1714142118
Hero Member
*
Offline Offline

Posts: 1714142118

View Profile Personal Message (Offline)

Ignore
1714142118
Reply with quote  #2

1714142118
Report to moderator
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 03:59:59 PM
 #2

From : https://www.opencompany.co.uk/company/SC480808/timetobit-limited

Company Name:      Timetobit Limited
Company Number:   SC480808
Registered Address:   93-95 Hanover Street, Edinburgh, EH2 1DJ

----------------------------------------------------------------------------

From : Companies House search at http://wck2.companieshouse.gov.uk//wcframe?name=accessCompanyInfo

Current Appointments
Number of current appointments: 1

DIRECTOR:         WELLINGTON, BERNHARD    

Appointed:         25/06/2014   
Date of Birth:      03/05/1979
Nationality:         BRITISH   

No. of Appointments:   1   

Address:         93-95 HANOVER ST., EDINBURGH, UNITED KINGDOM, EH2 1DJ   

Country/State of Residence:   UNITED KINGDOM   

----------------------------------------------------------------------------

From : http://www.avanta.co.uk/UK/offices/business-centres-edinburgh

Business Centre Edinburgh

93-95 Hanover Street, Edinburgh, UK EH2 1DJ

Avanta’s Hanover Street Business Centre is situated in the heart of Edinburgh’s historic New Town, just a few moment’s walk from Princes Street. Behind the elegant Georgian façade you will find a highly equipped, contemporary business centre that provides the ideal office let in Edinburgh.

Telephone: +44 (0)870 875 1921

----------------------------------------------------------------------------

Give them a call perhaps because they do seem to be a legally setup company ?
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 04:42:41 PM
Last edit: August 18, 2014, 05:32:56 PM by mlnoone
 #3

Thanks a lot for finding their information, I too had found their entry on opencompany.com, indicating their legality.

However:
  • they do not mention a phone number on their site
  • the 'Live Chat' always offline,
  • they have disappeared from this forum and twitter.

I actually managed to get an email reply from them, it was sent from a time zone corresponding to Sweden, when I sent them the link of an earlier scam accusation from this very forum (https://bitcointa.lk/threads/timetobit-free-mining-plan-giveaways-round-2.336005/page-6), posing as a new user who is considering buying a contract:

Quote
On Aug 15, 2014, at 8:25 AM, Info | TimeToBit <info@timetobit.com> wrote:
Hello,

I will have one of our PR representatives have a look and try to clear up the situation, generally we are not really active in the forums, it may sound weird for the regular customer, but reason being for that is that there's not much of a customer base present in bitcoin forums at all. After all we are a company relying on sales, if there's no sales to be made in a particular location, you don't bother going there.

Please do not confuse this with customer support, in my personal opinion and I would say also in that of our customers, we provide excellent support via e-mail with exceptional response time.


Kind Regards,

Claire | Sales

--
If you have any further queries, requests or suggestions, we will be pleased to assist you.

Best Regards,

TimeToBit | Instant Bitcoin Cloud Mining

This was the last communication I received from them.  

They never responded when I wrote from the email ID I used to sign up - a few minutes later on the same day that I got this reply.
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 04:48:34 PM
Last edit: August 18, 2014, 04:59:43 PM by odlal
 #4

I actually managed to get an email reply from them, it was sent from a time zone corresponding to Sweden, when I sent them the link of an earlier scam accusation from this very forum (https://bitcointa.lk/threads/timetobit-free-mining-plan-giveaways-round-2.336005/page-6), posing as a new user who is considering buying a contract:

Perhaps you could have a look at the "Headers" of your latest email from "Claire" because it'll contain some IP addresses which can be looked up for a physical location here : http://tejji.com/ip/ip-to-location.aspx?ip=46.228.38.200

EDIT : For example have a look at this message regarding Lunamine and their email headers : https://bitcointalk.org/index.php?topic=675315.msg8354422#msg8354422

EDIT2: If you're able to post here a REDACTED copy of the email header I'm sure there's some Network Techy type people who could look into this a bit further Wink
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 05:14:21 PM
 #5

ping www.timetobit.com

Pinging timetobit.com [192.64.118.152] with 32 bytes of data:
Reply from 192.64.118.152: bytes=32 time=145ms TTL=46
Reply from 192.64.118.152: bytes=32 time=145ms TTL=46
Reply from 192.64.118.152: bytes=32 time=146ms TTL=46
Reply from 192.64.118.152: bytes=32 time=147ms TTL=46

Ping statistics for 192.64.118.152:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 145ms, Maximum = 147ms, Average = 145ms

-------------------------------------------------------------

http://tejji.com/ip/ip-to-location.aspx?ip=192.64.118.152

Geographic Location & Characteristics
IP address :   192.64.118.152

IP number :   3225450136
Country :   United States  flag
Region:   California
City (Estimate) :   Los Angeles
Latitude :   34° 2' North
Longitude :   118° 26' West
Time Zone :   Pacific Daylight Time
GMT Offset :   -07:00:00
Lookup IPs :   192.64.118.*
Lookup IPv6 :   0000:0000:0000:0000:0000:ffff:c040:*
IPv6 (Short) :   ::ffff:c040:7698
IPv6 (Long) :   0000:0000:0000:0000:0000:ffff:c040:7698

-------------------------------------------------------------

http://www.ip-tracker.org/check/internet-speed.php?ip=192.64.118.152

IP Address:      192.64.118.152
Hostname:      anstele.com
ISP:            Namecheap
Organization:   Namecheap
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 05:26:28 PM
 #6

Thanks again, I had tried tracing the email using the header - and it was located as sent from Sweden:

IP address :   
95.143.193.61

IP number :   1603256637
Country :   Sweden  flag
Region:   
City (Estimate) :   
Latitude :   62° 0' North
Longitude :   15° 0' East
Time Zone :   W. Europe Daylight Time
GMT Offset :   02:00:00


I can now see Sweden mentioned in the Lunamine thread also.  Is something going on there!?

These are the headers, if any one would like to examine them further:
Quote
Return-path: <info@timetobit.com>
Envelope-to: xx@xxx.xxx
Delivery-date: Thu, 14 Aug 2014 22:51:17 -0400
Received: from [10.115.3.11] (helo=bosimpinc11)
   by bosmailscan06.eigbox.net with esmtp (Exim)
   id 1XI7bp-000779-Az
   for xx@xxx.xxx; Thu, 14 Aug 2014 22:51:17 -0400
Received: from server1.timetobit.com ([192.64.118.151])
   by bosimpinc11 with bizsmtp
   id eqrF1o01D3G4Pk001qrGvP; Thu, 14 Aug 2014 22:51:17 -0400
X-EN-OrigIP: 192.64.118.151
X-EN-IMPSID: eqrF1o01D3G4Pk001qrGvP
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=timetobit.com; s=default;
   h=Content-Type:In-Reply-To:References:Subject:To:MIME-Version:From:Date:Message-ID; bh=e/4PGOkZ0whJdArR0D4LPv8zJcVO5cEOLPhuH6MXc2M=;
   b=LGT/lbAmHdgVSLy0gt6UAQIKG9AnompH1SDWzwoQpxAyuAsky//jOJ2ydQXlbh8BU19MNYmmJQZt8XqZULdn9/DjIpylMUkop3vbRlIhn7Y+yOY76tQGNLoWSIxArHGwSR2Sw0I/8mBmLO7ONfCoq6xu/ELX3l/y7R5WksgH09Y=;
Received: from [95.143.193.61] (port=56958 helo=Tonys-iMac.local)
   by server1.timetobit.com with esmtpsa (TLSv1:DHE-RSA-AES128-SHA:128)
   (Exim 4.82)
   (envelope-from <info@timetobit.com>)
   id 1XI7bj-0003z9-EN
   for xx@xxx.xxx; Thu, 14 Aug 2014 19:51:13 -0700
Message-ID: <53ED769B.5040709@timetobit.com>
Date: Fri, 15 Aug 2014 09:55:23 +0700
From: Info | TimeToBit <info@timetobit.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Xx Xxxx <xx@xxx.xxx>
Subject: Re: Reviews on homepage showing site is a scam
References: <0f740657-06bd-4e04-b535-18899ffc2875@email.android.com> <53ED6EA5.4070106@timetobit.com> <85073B35-8A1F-420D-86C5-F20E690C6E60@xxx.xxx>
In-Reply-To: <85073B35-8A1F-420D-86C5-F20E690C6E60@xxx.xxx>
Content-Type: multipart/alternative;
 boundary="------------010600000008010400000100"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server1.timetobit.com
X-AntiAbuse: Original Domain - xxx.xxx
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - timetobit.com
X-Get-Message-Sender-Via: server1.timetobit.com: authenticated_id: info@timetobit.com
X-Source:
X-Source-Args:
X-Source-Dir:

Received: from [95.143.193.61] (port=56958 helo=Tonys-iMac.local)

So  'Claire | Sales' was writing from "Tony's iMac", from a Swedish IP, on behalf of TimeToBit - in Scotland?!
dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 05:31:42 PM
 #7

So we have a name

Quote
Tonys-iMac.local

Doh it see its been mentioned already
neil95
Newbie
*
Offline Offline

Activity: 15
Merit: 0


View Profile
August 18, 2014, 05:40:24 PM
 #8

I've got 4 payments still "pending". Wondering if I've been scammed too.
dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 05:43:59 PM
 #9

it seems that the IP in the email is listed as a peer here.

Quote

not sure that that means if anything.


Also

Quote
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 05:48:24 PM
 #10

I don't know if this means anything but I ran a trace on the IP address here : http://network-tools.com/default.asp?prog=trace&host=95.143.193.61

95.143.193.61 is from Sweden(SE) in region Scandinavia

TraceRoute from Network-Tools.com to 95.143.193.61
Hop   (ms)   (ms)   (ms)           IP Address   Host name
1      Timed out      Timed out      Timed out             -  
2      164      162      149         4.69.146.1    vl-3501-ve-115.csw1.dallas1.level3.net  
3      149      149      149         4.69.151.134    ae-63-63.ebr3.dallas1.level3.net  
4      Timed out      Timed out      Timed out             -  
5      149      149      149         4.69.132.86    ae-2-2.ebr1.washington1.level3.net  
6      155      160      157         4.69.134.138    ae-81-81.csw3.washington1.level3.net  
7      150      150      150         4.69.134.153    ae-82-82.ebr2.washington1.level3.net  
8      Timed out      Timed out      Timed out             -  
9      151      150      150         4.69.143.133    ae-45-45.ebr1.frankfurt1.level3.net  
10      Timed out      Timed out      Timed out             -  
11      148      148      148         4.69.163.9    ae-83-83.ebr3.frankfurt1.level3.net  
12      Timed out      Timed out      Timed out             -  
13      Timed out      Timed out      Timed out             -  
14      150      150      150         4.69.202.34    ae-118-3504.edge3.stockholm2.level3.net  
15      150      150      150         212.73.250.138     -  
16      149      157      149         62.109.44.154     -  
17      150      Timed out      150         62.109.44.158    sejar0001-rc5.ip-only.net  
18      156      150      151         213.132.112.82    sesto0001-rc3.ip-only.net  
19      Timed out      Timed out      Timed out             -  
20      149      149      148         95.143.207.230     -  
21      147      148      147         95.143.193.61     -  
Trace complete

--------------------------------------------------------------------------------

And then ran this http://myip.ms/info/whois/95.143.207.230 based upon the address at Hop number 20 above, the penultimate step in the list which gave this :

Whois IP Live Results for 95.143.207.230 -

IP Location:   Sweden,    Gavleborgs Lan,    Hudiksvall
IP Reverse DNS (Host):   95.143.207.230
IP Owner:    Internetport Sweden Ab
Owner IP Range:   95.143.192.0 - 95.143.207.255    (4,096 ip)    
Other Sites on IP »
Owner Address:   Internetport Sweden Ab, Peter Forslund, Sjotullsgatan 16, 824 50, Hudiksvall, Sweden
Owner Country:   Sweden
Owner Phone:   +4665010000
Owner CIDR:   95.143.192.0/20

Huh

--------------------------------------------------------------------------------

95.143.207.230 points to :

https://www.ripe.net/membership/indices/data/se.serverconnect.html

The Réseaux IP Européens Network Coordination Centre (RIPE NCC) is an independent, not-for-profit membership organisation that supports the infrastructure of the Internet through technical coordination in its service region.

The most prominent activity of the RIPE NCC is to act as the Regional Internet Registry (RIR) providing global Internet resources and related services (IPv4, IPv6 and AS Number resources) to members in the RIPE NCC service region.

Internetport Sweden AB
Internetport Sweden AB
Sjotullsgatan 16
824 50 HUDIKSVALL
SWEDEN
phone:   +4665010000
fax:  +46650601024
e-mail:  peter (at) serverconnect (dot) se
Areas serviced:   SE
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 05:56:28 PM
 #11

Yup - that seems to be the guy running this site.

Somewhere in Sweden.

Possible goes by the name 'Tony'

And he's got all our bitcoins!
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 06:03:09 PM
 #12

I've got 4 payments still "pending". Wondering if I've been scammed too.
Quite possibly yes - you too have been scammed. 

Looked pretty legit didn't it?  Same here!
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 06:04:08 PM
 #13

From https://apps.db.ripe.net/search/

I entered 95.143.193.61

And got this :

inetnum:         95.143.193.1 - 95.143.194.224
netname:         serverconnect-dedicateserver-net
descr:           Abuse-mailbox: abuse@serverconnect.se
country:         se
admin-c:         PF776-RIPE
tech-c:          PF776-RIPE
status:          ASSIGNED PA
mnt-by:          MNT-SERVERCONNECT
source:          RIPE # Filtered


person:          PAOLO FANTON
address:         SJOTULLSGATAN 16
address:         Hudiksvall
address:         824 50
address:         SWEDEN
phone:           +46 65010000
fax-no:          +46 650601024
nic-hdl:         PF776-RIPE
source:          RIPE # Filtered
mnt-by:          MNT-SERVERCONNECT


route:           95.143.192.0/20
descr:           INTERNETPORT AB -BL
origin:          AS49770
mnt-by:          MNT-SERVERCONNECT
source:          RIPE # Filtered

Huh

Information also available here : http://www.tcpiputils.com/browse/ip-address/95.143.193.61
mlnoone (OP)
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 18, 2014, 06:13:27 PM
Last edit: August 18, 2014, 06:39:01 PM by mlnoone
 #14

Imagining a Phone Call, to +4665010000

"Hello..?"
...
"Do you run bitcoin scams?"
...
"Do you know who Tony is?"
...
dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 06:16:22 PM
 #15

From https://apps.db.ripe.net/search/

I entered 95.143.193.61

And got this :

inetnum:         95.143.193.1 - 95.143.194.224
netname:         serverconnect-dedicateserver-net
descr:           Abuse-mailbox: abuse@serverconnect.se
country:         se
admin-c:         PF776-RIPE
tech-c:          PF776-RIPE
status:          ASSIGNED PA
mnt-by:          MNT-SERVERCONNECT
source:          RIPE # Filtered


person:          PAOLO FANTON
address:         SJOTULLSGATAN 16
address:         Hudiksvall
address:         824 50
address:         SWEDEN
phone:           +46 65010000
fax-no:          +46 650601024
nic-hdl:         PF776-RIPE
source:          RIPE # Filtered
mnt-by:          MNT-SERVERCONNECT


route:           95.143.192.0/20
descr:           INTERNETPORT AB -BL
origin:          AS49770
mnt-by:          MNT-SERVERCONNECT
source:          RIPE # Filtered

Huh

Information also available here : http://www.tcpiputils.com/browse/ip-address/95.143.193.61

That is the guy who is tech contact for the IP block at the server hosting/colo company. He is not the scammer.



odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 06:17:21 PM
 #16

That is the guy who is tech contact for the IP block at the server hosting/colo company. He is not the scammer.

But could he point to who is ?
dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 06:18:02 PM
 #17

That is the guy who is tech contact for the IP block at the server hosting/colo company. He is not the scammer.

But could he point to who is ?

Try him, probably bit late in the day now.
odlal
Full Member
***
Offline Offline

Activity: 151
Merit: 100


View Profile
August 18, 2014, 06:27:05 PM
 #18

That is the guy who is tech contact for the IP block at the server hosting/colo company. He is not the scammer.

But could he point to who is ?

Try him, probably bit late in the day now.

I've sent an email to RIPE pointing them to this thread and asking if they would share any information they have about IP address 95.143.193.61
dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 06:37:36 PM
 #19

That is the guy who is tech contact for the IP block at the server hosting/colo company. He is not the scammer.

But could he point to who is ?

Try him, probably bit late in the day now.

I've sent an email to RIPE pointing them to this thread and asking if they would share any information they have about IP address 95.143.193.61

RIPE allocated that block to a service provider, they can tell yu anymore than all the public info in the ripe database.

You would need the hosting/colo to spill the beans on that hosted IP.

dekodoge
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 18, 2014, 06:39:16 PM
 #20

I love how the website just keeps counting up/down

Quote
Network Hashrate: 800 TH/s

Also the main image is stolen

used here

http://pmhis.net/dedicated_servers.php

also

http://www.fnbg.co.uk/business-server-hosting-scotland.html
Pages: [1] 2 3 4 5 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!