Bitcoin Forum

Other => Beginners & Help => Topic started by: Chikito on November 05, 2019, 08:05:30 AM



Title: [Warning] Phishing Blockchain.info
Post by: Chikito on November 05, 2019, 08:05:30 AM
Found another fake blockchain.info
Code:
//biockcheln.info/
https://i.ibb.co/yp7DsWC/blockchain.png

https://www.virustotal.com/gui/url/0aee55b5441490294adc6b6195e76f8b2e0f1a34d8b3339d30dd8adf407dfab0/detection

Code:
Domain Name: BIOCKCHELN.INFO
Registry Domain ID: D503300001181905266-LRMS
Registrar WHOIS Server: whois.reg.com
Registrar URL: http://www.reg.com
Updated Date: 2019-10-05T21:58:27Z
Creation Date: 2019-10-05T21:58:24Z
Registry Expiry Date: 2020-10-05T21:58:24Z
Registrar Registration Expiration Date:
Registrar: Limited Liability Company "Registrar of domain names REG.RU"
Registrar IANA ID: 1606
Registrar Abuse Contact Email: abuse@reg.ru
Registrar Abuse Contact Phone: +7.4955801111
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Registrant Organization: Privacy Protection
Registrant State/Province:
Registrant Country: RU
Name Server: NS1.REG.RU
Name Server: NS2.REG.RU
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form is https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2019-11-05T07:44:10Z <<<

Be careful, do not insert your private information and always double-check site.

Let's report it here: https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en


Title: Re: [Warning] Phishing Blockchain.info
Post by: JeromeTash on November 05, 2019, 08:37:14 AM
More information about the IP address used by scammer. There are 9 malicious/phishing URLs under the same IP address

WARNING

DO NOT VISIT THE LINKS

Code:
http://iocaibitcoins.com/
https://iocaibitcoins.com/
https://lolibitcoins.net/
http://privatemgrgg.pw/vcruntime140.dll
https://localbicolns.org/
http://localbicolns.org/
http://mgsocl.su/api/check.get
http://mgsocl.su/api/gate.get
http://dress-x.ru/freebl3.dll


Title: Re: [Warning] Phishing Blockchain.info
Post by: Kakmakr on November 05, 2019, 08:51:14 AM
You have to be blind not to spot those phishing sites, because they are very different than the original sites. The problem is that people are so busy, they will not even look at those addresses and simply follow Url links provided in emails to visit those sites.

The best practice to prevent Phishing links like this, is to type those url yourself and not to click on any url's. People are lazy, so they will just "one click" on Url's provided for them. Any reputable site will implement 2FA to make sure that the login information alone, will not give access to your account, so make sure to enable 2FA, if it is provided.  :P


Title: Re: [Warning] Phishing Blockchain.info
Post by: pgbit on November 05, 2019, 09:10:57 AM
The best way to avoid the issue of phishing is to bookmark your most visited or sensitive websites (sites where you have to input your private information especially those financially related like your private keys), take your security very seriously, it's a sad fact that many people still fall for phishing schemes in this day and age but we are all humans and we make mistakes.

Quote
The best practice to prevent Phishing links like this, is to type those url yourself and not to click on any url's.
This is one of the reasons why people fall for phishing sites, most of their domain names are made to look almost like the real thing so while typing, you might make a mistake and get the spelling wrong and it takes you straight to a phishing site and because you typed it yourself, you likely won't even double-check, we have to make allowances for human errors.


Title: Re: [Warning] Phishing Blockchain.info
Post by: Chikito on November 05, 2019, 11:40:09 AM
~snip..
Yes, we can look the related ip address : https://www.virustotal.com/gui/ip-address/185.212.130.9/relations

~ snip...
When people in a hurry to pay something, sometimes they don't have the chance to check the website address.

~snip..
Maybe better to add some extension like Suspicious Site Reporter (https://chrome.google.com/webstore/detail/suspicious-site-reporter/jknemblkbdhdcpllfgbfekkdciegfboi?hl=en-US) for chrome browser or Netcraft Anti-Phishing Extension (https://addons.mozilla.org/id/firefox/addon/netcraft-toolbar/) for firefox to avoid phishing


Title: Re: [Warning] Phishing Blockchain.info
Post by: lobat999 on November 05, 2019, 12:20:11 PM
Found another fake blockchain.info
Code:
//biockcheln.info/
https://i.ibb.co/yp7DsWC/blockchain.png

https://www.virustotal.com/gui/url/0aee55b5441490294adc6b6195e76f8b2e0f1a34d8b3339d30dd8adf407dfab0/detection

Code:
Domain Name: BIOCKCHELN.INFO
Registry Domain ID: D503300001181905266-LRMS
Registrar WHOIS Server: whois.reg.com
Registrar URL: http://www.reg.com
Updated Date: 2019-10-05T21:58:27Z
Creation Date: 2019-10-05T21:58:24Z
Registry Expiry Date: 2020-10-05T21:58:24Z
Registrar Registration Expiration Date:
Registrar: Limited Liability Company "Registrar of domain names REG.RU"
Registrar IANA ID: 1606
Registrar Abuse Contact Email: abuse@reg.ru
Registrar Abuse Contact Phone: +7.4955801111
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Registrant Organization: Privacy Protection
Registrant State/Province:
Registrant Country: RU
Name Server: NS1.REG.RU
Name Server: NS2.REG.RU
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form is https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2019-11-05T07:44:10Z <<<

Be careful, do not insert your private information and always double-check site.

Let's report it here: https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en


@OP you can also submit the phishing link to this thread -  Host-file to deal with phishing sites (https://bitcointalk.org/index.php?topic=5178198.msg52241579#msg52241579) and update your host file accordingly. Thanks for keeping the community aware about this. :)


Title: Re: [Warning] Phishing Blockchain.info
Post by: virasog on November 05, 2019, 03:27:33 PM
The name of this Phishing site is easy to figure out if anyone just double check the site address. That's why it is recommended to focus on the name of the site so you are not scammed or bookmarking important sites is also one solution to avoid these scam attempts.


Title: Re: [Warning] Phishing Blockchain.info
Post by: bob123 on November 05, 2019, 05:10:08 PM
The name of this Phishing site is easy to figure out if anyone just double check the site address. That's why it is recommended to focus on the name of the site so you are not scammed or bookmarking important sites is also one solution to avoid these scam attempts.

Just checking the URL you are visiting does not guarantee that you are on the legitimate site you intended to visit.
There are multiple approaches to trick people into visiting a fake site.

Currently the most common is to use punycode. The URL will look almost exactly as the original one except for some subtle changes (e.g. a small dot below a character).
Another (more complicated) way to trick you into visiting a fake website would be DNS spoofing / cache poisoning. You'll see the original URL in the address bar, but will connect to a malicious server. Bookmarking the site won't help you there.
While a lot of these more sophisticated attacks are uncommon, relying on a website to open up a wallet (i.e. using a web wallet) is always a bad idea, security-wise.


Title: Re: [Warning] Phishing Blockchain.info
Post by: Juggy777 on November 05, 2019, 05:24:57 PM
The problem is that people are so busy, they will not even look at those addresses and simply follow Url links provided in emails to visit those sites.


I have often seen newbies fall for such phishing sites as they rarely suspect the sites they’re visiting, and hopefully after seeing op they’ll make it a habit to spend few extra seconds and verify if the site is legit or not. It’s also pertinent to note that a person with good knowledge of seo can rank these sites in the first position in google, though it’ll be taken down later but the damage is usually done by that time.


Title: Re: [Warning] Phishing Blockchain.info
Post by: target on November 05, 2019, 05:34:04 PM

The problem is that people are so busy, they will not even look at those addresses and simply follow Url links provided in emails to visit those sites.


I have often seen newbies fall for such phishing sites as they rarely suspect the sites they’re visiting, and hopefully after seeing op they’ll make it a habit to spend few extra seconds and verify if the site is legit or not. It’s also pertinent to note that a person with good knowledge of seo can rank these sites in the first position in google, though it’ll be taken down later but the damage is usually done by that time.

An SEO guy would have to build backlinks and post articles somewhere and I guess he'd be tracked if he does that. he' got much success if he targets newbies email like the list of bounty hunters who usually register to the documents they fill on campaigns. Some of the spreadsheets actually are open for the public which their email can be seen by anyone.  So its advised that they don't click links in the emails. If they normally visit a website, its best if they just bookmark it or manually type the url every time they go.


Title: Re: [Warning] Phishing Blockchain.info
Post by: panganib999 on November 05, 2019, 05:35:30 PM
Blockchain's popularity is growing especially now that China announced that they agree that bkockchain is a helpful and great technology and that they might use it according to their President Xi Jin Ping, he also said that using blockchain related applications is also great because it was supported by blockchain technology. That announcement influenced the masses and scammers and those who are behind phishing and cybercrimes has possibly saw it as opportunity and something to be taken advantage of. Make sure, people, that younare verifying  that the sites you are using are legitimate before entering your details.


Title: Re: [Warning] Phishing Blockchain.info
Post by: stompix on November 05, 2019, 06:51:13 PM
That's why it is recommended to focus on the name of the site so you are not scammed or bookmarking important sites is also one solution to avoid these scam attempts.

Just checking the URL you are visiting does not guarantee that you are on the legitimate site you intended to visit.
There are multiple approaches to trick people into visiting a fake site.

Currently the most common is to use punycode. The URL will look almost exactly as the original one except for some subtle changes (e.g. a small dot below a character).
~

Yeah, the above user will focus on the name and ....then we will have a new open topic in scam accusation.
There are some really nasty letters, forget dots, they look almost the same, xn--gogl-1nd42e . com is the nastiest thing I ever saw alongside with xn--mcrosoft-tkb . com

Far better is not to click on any damn link than checking character by character, type it yourself.


relying on a website to open up a wallet (i.e. using a web wallet) is always a bad idea, security-wise.

Not your keys...sooner or later not your money.  8)


Title: Re: [Warning] Phishing Blockchain.info
Post by: bob123 on November 05, 2019, 07:47:20 PM
relying on a website to open up a wallet (i.e. using a web wallet) is always a bad idea, security-wise.

Not your keys...sooner or later not your money.  8)

True, and even if you are the only one in possession of your keys.. if you need to rely on a website to access them (e.g. like with myetherwallet where the keys are loaded from a file on your PC), you are also at risk.
The best option simply is to use a desktop-/mobile wallet or go for cold storage / a hardware wallet.


Title: Re: [Warning] Phishing Blockchain.info
Post by: Chikito on November 09, 2019, 03:25:06 AM
I am Investigated and found connecting IP related to Phishing website.
https://www.virustotal.com/gui/url/0aee55b5441490294adc6b6195e76f8b2e0f1a34d8b3339d30dd8adf407dfab0/details

https://i.ibb.co/jRpmTFt/185-212-130-9.png

https://www.virustotal.com/gui/domain/iocaibitcoins.com/relations

https://i.ibb.co/5T17hDH/1.png

IP ; 185.212.130.65
https://www.virustotal.com/gui/ip-address/185.212.130.65/relations

https://i.ibb.co/5BMWxnk/2.png

IP ; 194.58.112.174
https://www.virustotal.com/gui/ip-address/194.58.112.174/relations

https://i.ibb.co/L5YbTNB/3.png

IP ; 95.183.14.71
https://www.virustotal.com/gui/ip-address/95.183.14.71/relations

https://i.ibb.co/Vg4hC26/4.png

Be careful always double-check when you visiting website



Title: Re: [Warning] Phishing Blockchain.info
Post by: hugeblack on November 09, 2019, 01:41:18 PM
I am Investigated and found connecting IP related to Phishing website.

This scammer owns a lot of sites, it is better to report the IP to one of these sites ---> https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en.
The problems of such sites are that they appear in one of the Google ads, the first page during the search, be inside a game and other things that we use it daily. For example, if this link is one of the games and suddenly appeared then ignored, after a time I will open the browser and will use that site.

It is best to have a dedicated device for sensitive sites and use only to browse those sites.




Title: Re: [Warning] Phishing Blockchain.info
Post by: Chikito on November 09, 2019, 10:55:20 PM
This scammer owns a lot of sites, it is better to report the IP to one of these sites ---> https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en.
reported those websites and IP.
When I look those IP many people did the report.
https://www.abuseipdb.com/check/185.212.130.9 - reported 10 times
https://www.abuseipdb.com/check/185.212.130.65 - reported 3 times
https://www.abuseipdb.com/check/194.58.112.174 -reported 7 times
https://www.abuseipdb.com/check/95.183.14.71 - reported 1 time

https://i.ibb.co/BqCRQk5/123.png

We can look up this IP 194.58.112.174 begun Scamming people since 2018 Using Ethereum phishing site.

The scammer did steal money a lot of people.  We should together to report it






Title: Re: [Warning] Phishing Blockchain.info
Post by: nakamura12 on November 10, 2019, 08:27:20 PM
The spelling of the link is obvious if you always double check the link in the address bar all the time. This is another site to be added in the blocked phishing site. I think there are more fake blockchain.info site that are waiting to be discovered any where at any time. Let's be safe.


Title: Re: [Warning] Phishing Blockchain.info
Post by: spike420211 on November 10, 2019, 11:50:51 PM
Thank you ha warning! I’ll ask you about only one thing.
Once you publish this in the English thread and not in the local, then use the section language - English. This is a topic for beginners, which means that everything should be as detailed and clear as possible.


Title: Re: [Warning] Phishing Blockchain.info
Post by: mk4 on November 11, 2019, 03:30:35 AM
Are we going to create separate topics for every phishing site we find now? Not saying that what you did(OP) by posting this thread was wrong, but it's getting pretty redundant. It's pretty much the same phishing scam as what the scammers have been doing since forever anyway. I think an admin should just sticky a thread about phishing links here in the Beginners & Help section so posts like this will be unnecessary as I'm sure we're going to see a lot more of this simply due to the fact that phishing sites aren't going anywhere soon.

Anyway, thumbs up for informing the noobies.


Title: Re: [Warning] Phishing Blockchain.info
Post by: JohnBitCo on November 11, 2019, 04:03:54 AM
Are we going to create separate topics for every phishing site we find now? Not saying that what you did(OP) by posting this thread was wrong, but it's getting pretty redundant. It's pretty much the same phishing scam as what the scammers have been doing since forever anyway. I think an admin should just sticky a thread about phishing links here in the Beginners & Help section so posts like this will be unnecessary as I'm sure we're going to see a lot more of this simply due to the fact that phishing sites aren't going anywhere soon.

Anyway, thumbs up for informing the noobies.

That's pretty much what is required, A dedicated thread which lists all the phishing sites and we have discussion about them in a single place. Creating a new thread for every phishing sites get the Beginners & Help section crowded . The person starting this thread will need to update the OP periodically.


Title: Re: [Warning] Phishing Blockchain.info
Post by: mk4 on November 11, 2019, 06:57:00 AM
That's pretty much what is required, A dedicated thread which lists all the phishing sites and we have discussion about them in a single place. Creating a new thread for every phishing sites get the Beginners & Help section crowded . The person starting this thread will need to update the OP periodically.

Rather than a list, it should be basic information concerning phishing and scams in general, to teach the less educated how to detect scams for themselves rather than relying on a huge phishing site list that could end up being thousands and thousands in the long run, knowing that the list is simply going to be endless.


Title: Re: [Warning] Phishing Blockchain.info
Post by: Chikito on November 11, 2019, 11:46:31 AM
I locked this thread and moved to  [Warning] Phishing Cryptocurrency Website (https://bitcointalk.org/index.php?topic=5197078.0)