Forensic analysis | Scam PVU

FRAUDULENT PERFORMANCE IN PLANTSVSUNDEAD

Analysis of a hacker who has executed a scam against users taking advantage of administrators:

The page is as follows, with an address ending in .com

error


Within an official post we find the following:

error


Where we find “support” announcements, repeated many times:

error

error

error


Marketplace.plantsvsundead.net (.net??) https://marketplace.plantsvsundead.net/claim-your-pvp-seed?ref=os0ef303

error

error


pvu-event.com (totally different from the plantsvsundead server address) https://pvu-event.com/

error

error


error

Marketplace.plantsvsundead.net 172.67.211.239 (use two ip’s, this is one)

error

arnold.ns.cloudflare.com [108.162.193.69] error

daniella.ns.cloudflare.com [108.162.194.228] error


pvu-event.com 42.112.30.39

error

error

ns1.dns-parking.com [162.159.24.201]

ns2.dns-parking.com [162.159.25.42]


Where he falsifies absolutely everything

error

But then at the same time it does not exist

error


I observe the contracts of the transactions

https://bscscan.com/token/0x31471e0791fcdbe82fbf4c44943255e923f1b794?a=0xa03b5c2b861689f10fff97d9a846fc61b0c0db4c

error


It is observed that everything is income except for two, a possible test and another that is a transfer of the total token that has already accumulated to the following address:

0x8094c59bed7044e78394ee50e08a3da342214441

With a value of $ 9,800 already

error

Where everything is token income

New scammer wallet: 0x6a3157f63538C201e6c7da6aA22ba09135Aa07AB

error