Bitcoin Forum

Other => Beginners & Help => Topic started by: Yaunfitda on April 22, 2020, 12:31:51 PM



Title: Fake Trustwallet website
Post by: Yaunfitda on April 22, 2020, 12:31:51 PM
There is a fake trust wallet website out there, please be careful not to fall for this. Don't download any of those supposedly apps as it might contain malware to steal your cryptos.

Code:
hxxps://xn--trstwallet-odb[dot]com/

https://i.imgur.com/p5v1z78.png

Code:

Registrant Protection of Private Person
Registrant Country ru
Registrar Registrar of domain names REG.RU LLC REGISTRAR OF DOMAIN NAMES REG.RU LLC
IANA ID: 1606
URL: https://www.reg.com,https://www.reg.ru,http://www.reg.ru
Whois Server: whois.reg.com

(p)
Registrar Status clientTransferProhibited
Dates 5 days old
Created on 2020-04-17
Expires on 2021-04-17
Updated on 2020-04-17  
Name Servers ALBERTO.NS.CLOUDFLARE.COM (has 22,031,748 domains)
MIRA.NS.CLOUDFLARE.COM (has 22,031,748 domains)

http://whois.domaintools.com/xn--trstwallet-odb.com

Real trusted website: https://trustwallet.com/


Title: Re: Fake Trustwallet website
Post by: Plaguedeath on April 22, 2020, 12:46:51 PM
Thank you for inform this

Have your reported the websites? I have report it in this link https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en
After make post don't forget to report the websites, you can help both side of this. In 1 side you help member to avoid this sites, and other side you can help other people who don't in this forum


Title: Re: Fake Trustwallet website
Post by: hugeblack on April 22, 2020, 02:25:56 PM
Do you think this site is a scam? I visited the site and clicked on the links, all leading to the original site.
When I click on download, it will lead me to this link ---> https://trustwallet.com/dl/apk

£edit: When I click on Web wallet, it redirects me to the scam site.
It seems that the scammer has copied the entire site to gain trust and modified the web wallet to steal the money.


Title: Re: Fake Trustwallet website
Post by: jackg on April 22, 2020, 05:58:33 PM
Code:
hxxps://xn--trstwallet-odb[dot]com/

Any idea what this is without the unicode additions? Someone brought it up to me on here a while ago and that looks like a similar format to how a certain unicode character can be added.




edit: ahh it has an accented U

When I click on download, it will lead me to this link ---> https://trustwallet.com/dl/apk

Does the 'u' look different or the same? I think it's big enough to be noticeable...
It's possible that they link to the original site just to make themselves look more legitimate or to try to get more hits before they scam.


Title: Re: Fake Trustwallet website
Post by: Baofeng on April 22, 2020, 11:51:28 PM
Code:
hxxps://xn--trstwallet-odb[dot]com/

Any idea what this is without the unicode additions? Someone brought it up to me on here a while ago and that looks like a similar format to how a certain unicode character can be added.




edit: ahh it has an accented U

When I click on download, it will lead me to this link ---> https://trustwallet.com/dl/apk

Does the 'u' look different or the same? I think it's big enough to be noticeable...
It's possible that they link to the original site just to make themselves look more legitimate or to try to get more hits before they scam.

Yes, it's what we call IDN homograph attack (https://en.wikipedia.org/wiki/IDN_homograph_attack).

Look closely at the 'u'.

https://i.ibb.co/HKGFHbR/Screen-Shot-2020-04-23-at-7-34-21-AM.png (https://imgbb.com/)

I found a new one:

Code:
 PHISHING SITE: trüstwallet.com (xn--trstwallet-beb.com)

https://i.ibb.co/pWwSKGx/Screen-Shot-2020-04-23-at-7-38-23-AM.png (https://ibb.co/tZK92k4)


Title: Re: Fake Trustwallet website
Post by: joniboini on April 23, 2020, 06:50:10 AM
Same technique to attacks, probably registered by the same user or group.

Don't forget to turn on punycode to protect yourself from clicking similar websites. Or use https://www.punycoder.com/ to check whether a website contains that or not.


Title: Re: Fake Trustwallet website
Post by: patrick_kim on April 23, 2020, 07:01:23 AM
There is a fake trust wallet website out there, please be careful not to fall for this. Don't download any of those supposedly apps as it might contain malware to steal your cryptos.

Code:
hxxps://xn--trstwallet-odb[dot]com/

https://i.imgur.com/p5v1z78.png

Code:

Registrant Protection of Private Person
Registrant Country ru
Registrar Registrar of domain names REG.RU LLC REGISTRAR OF DOMAIN NAMES REG.RU LLC
IANA ID: 1606
URL: https://www.reg.com,https://www.reg.ru,http://www.reg.ru
Whois Server: whois.reg.com

(p)
Registrar Status clientTransferProhibited
Dates 5 days old
Created on 2020-04-17
Expires on 2021-04-17
Updated on 2020-04-17  
Name Servers ALBERTO.NS.CLOUDFLARE.COM (has 22,031,748 domains)
MIRA.NS.CLOUDFLARE.COM (has 22,031,748 domains)

http://whois.domaintools.com/xn--trstwallet-odb.com

Real trusted website: https://trustwallet.com/

If you download their mobile app, you won't have to worry about phishing attacks if you have the app downloaded from an official store. It's a good rule of thumb for beginners to only use mobile wallet apps who won't be using the advanced feature settings you can have with desktop/web-based apps anyways.


Title: Re: Fake Trustwallet website
Post by: Annisa_crypto on April 23, 2020, 08:01:47 AM
But someone who doesn't know the coding like me how we will be aware the site is real or fake. Please suggest