Bitcoin Forum

Other => Meta => Topic started by: acs267 on September 13, 2014, 09:46:14 PM



Title: New Phishing Link Going Around
Post by: acs267 on September 13, 2014, 09:46:14 PM
I'm a hundred percent sure this is a new phishing link going around. I just got it a few seconds ago, and, I'll just drop it here so that people will be warned.

Hi bro! I have bad news for you! You can see about in there
http://bilc​ointalk​.o​rg/index.php?topic=654845.msg7515541#msg751554 <--phishing link don't click

As you can see, Bitcointalk is clearly spelled wrong. And, I've never ran into this guy before.




Title: Re: New Phishing Link Going Around
Post by: jackjack on September 13, 2014, 09:52:04 PM
I received the same thing from the user vovka777
Report it!


Title: Re: New Phishing Link Going Around
Post by: Penner on September 13, 2014, 09:52:43 PM
Thanks for this warning user such you are rare :-)


Title: Re: New Phishing Link Going Around
Post by: Penner on September 13, 2014, 09:54:11 PM
wow the best is you can enter any fake user or fake pass it will redirect you here



Title: Re: New Phishing Link Going Around
Post by: lemfuture on September 13, 2014, 09:54:59 PM
thanks for warning users


Title: Re: New Phishing Link Going Around
Post by: Muhammed Zakir on September 13, 2014, 09:55:08 PM
I and other few persons got it too. Don't enter your username and password in it. I have put a -ve trust (https://bitcointalk.org/index.php?action=trust;u=349554) but mine will do nothing! ::) Please PM to any person who are in DefaultTrust list, so that everybody can see.

The message I got :
Hi bro! I have bad news for you! You can see about in there http://bilcointalk.org/index.php?topic=654845.msg7515541#msg751554


  ~~MZ~~


Title: Re: New Phishing Link Going Around
Post by: jackjack on September 13, 2014, 10:00:12 PM
I am in default trust, tell me which accounts sent that


Title: Re: New Phishing Link Going Around
Post by: grue on September 13, 2014, 10:01:14 PM
Thank you for all the reports. If you see any more phishing PMs, be sure to report them as well.

So far, 7 users have been banned for posting this particular phishing site. :o The first 3 accounts that I banned were most likely hacked accounts (members or above), but all the newer ones are coming from 0 post accounts. I'm IP banning them, but whoever is behind it probably has access to vpns/proxies/dynamic ip.

edit: 4 more users have been banned for sending phishing links


Title: Re: New Phishing Link Going Around
Post by: Kprawn on September 13, 2014, 10:03:13 PM
I got the same - It's a phishing attempt.

Newbies will fall for that one.

Check and double check your links send to you. ALWAYS.


Title: Re: New Phishing Link Going Around
Post by: Muhammed Zakir on September 13, 2014, 10:07:16 PM
I am in default trust, tell me which accounts sent that

Link to the profile of the user LOL909 : https://bitcointalk.org/index.php?action=profile;u=349554 .

I think it isn't needed anymore, he might has banned. Anyway, just put it for the safety of others. :)

Thank you for all the reports. If you see any more phishing PMs, be sure to report them as well.

So far, 7 users have been banned for posting this particular phishing site. :o The first 3 accounts that I banned were most likely hacked accounts (members or above), but all the newer ones are coming from 0 post accounts. I'm IP banning them, but whoever is behind it probably has access to vpns/proxies/dynamic ip.

  ~~MZ~~


Title: Re: New Phishing Link Going Around
Post by: dankkk on September 13, 2014, 10:17:39 PM
I'm a hundred percent sure this is a new phishing link going around. I just got it a few seconds ago, and, I'll just drop it here so that people will be warned.

Hi bro! I have bad news for you! You can see about in there
http://bilcointalk.org/index.php?topic=654845.msg7515541#msg751554

As you can see, Bitcointalk is clearly spelled wrong. And, I've never ran into this guy before.
I both got this, reported the PM and posted a scam accusation about it.

It was more then obvious as to what was happening because I was already logged in and it was asking me to log in again


Title: Re: New Phishing Link Going Around
Post by: twister on September 14, 2014, 03:52:35 AM
I'm a hundred percent sure this is a new phishing link going around. I just got it a few seconds ago, and, I'll just drop it here so that people will be warned.

Hi bro! I have bad news for you! You can see about in there
http://bilcointalk.org/index.php?topic=654845.msg7515541#msg751554

As you can see, Bitcointalk is clearly spelled wrong. And, I've never ran into this guy before.

They can hide it behind bitcointalk too. so always look at the bottom of the screen before clicking on any link.


Title: Re: New Phishing Link Going Around
Post by: williamj2543 on September 14, 2014, 03:56:15 AM
Thanks for this! Remember to always check the URL, and if you have never seen the message before, its probably a phishing scam.


Title: Re: New Phishing Link Going Around
Post by: marcotheminer on September 14, 2014, 09:25:07 AM
OP: remove the hyperlink in the top post.. I was about to click it..


Title: Re: New Phishing Link Going Around
Post by: Muhammed Zakir on September 14, 2014, 11:18:19 AM
OP: remove the hyperlink in the top post.. I was about to click it..

I think it's better not to. So other can know the link and how it looks. Clicking the link is okay, entering username and password is dangerous. ::)

  ~~MZ~~


Title: Re: New Phishing Link Going Around
Post by: jackjack on September 14, 2014, 12:03:43 PM
Maybe remove the link itself, not the address


Title: Re: New Phishing Link Going Around
Post by: marcotheminer on September 14, 2014, 12:24:41 PM
Maybe remove the link itself, not the address

What I said.  ::)


Title: Re: New Phishing Link Going Around
Post by: EvilDave on September 14, 2014, 01:22:29 PM
Just posted this in Alts:

Guys/girls/things:

Just had this in my PMs.....

Hi dear,  Very important news about NEM Open Alpha.
NOThttp://bilcointalk.org/index.php?topic=654845.msg7515541#msg7515541
the NOT is from me, do not use the above link!

As you can see, the link leads to Bilcointalk.org......very frigging dodgy.
The senders name resembles that of a real NEM member: p3tmaster.

So, can we mega-ban p3tnnaster, please?
And for the URL, just add NOT....u can still see the URL as an example, but its no longer clickable.


Title: Re: New Phishing Link Going Around
Post by: Bitcoins101 on September 14, 2014, 01:27:14 PM
Phisher is probably thinking he caught a big one...
https://i.imgur.com/6NLdSZC.png


Title: Re: New Phishing Link Going Around
Post by: Muhammed Zakir on September 14, 2014, 01:30:46 PM
Phisher is probably thinking he caught a big one..
https://i.imgur.com/6NLdSZC.png

 :D . What you got after logging in? Redirecting to BT?

  ~~MZ~~


Title: Re: New Phishing Link Going Around
Post by: Bitcoins101 on September 14, 2014, 01:35:29 PM
Phisher is probably thinking he caught a big one..
https://i.imgur.com/6NLdSZC.png

 :D . What you got after logging in? Redirecting to BT?

  ~~MZ~~

Yep, redirects right back to the real site under the link that is in the OP. 


Title: Re: New Phishing Link Going Around
Post by: acs267 on September 14, 2014, 02:22:33 PM
OP: remove the hyperlink in the top post.. I was about to click it..

It's a phishing link. You'll be fine as long as you don't enter your username or password. But you can basically enter in a random or fake one. I didn't remove all of the link, because, I'm pretty sure they all have the same topic start number. 654845.

Anyway, you could basically click away, and even sit on the link and nothing will happen but a discouraged person, looking at the hundreds accounts with 'theymos' or 'satoshi' as their username.


Title: Re: New Phishing Link Going Around
Post by: Nullu on September 14, 2014, 02:40:21 PM
Bombard the site with fake username and passwords.


Title: Re: New Phishing Link Going Around
Post by: Bitcoins101 on September 14, 2014, 03:21:41 PM
Bombard the site with fake username and passwords.
Someone could set up a script to do it.  :D


Title: Re: New Phishing Link Going Around
Post by: NoirSuccubus on September 14, 2014, 03:52:07 PM
I got one from p3tmacter

This guy is registering hordes of new accounts for the purpose of phishing peoples accounts. Look at the new members list and you'll find a bunch. I just went through the first 2 pages of the bitcointalk member list, these are only a few hours old.

NEMmaster
NEMxtester
EspoNem
nemeconomy
utopian-nem
nem-team
nemutopian
p3tnaster
nemxt
nem-xterster


You can see the members list here listed from new to old.
https://bitcointalk.org/index.php?action=mlist;sort=registered;start=0;desc
There's probably much more.


Title: Re: New Phishing Link Going Around
Post by: acs267 on September 14, 2014, 03:57:38 PM
I got one from p3tmacter

This guy is registering hordes of new accounts for the purpose of phishing peoples accounts. Look at the new members list and you'll find a bunch. I just went through the first 2 pages of the bitcointalk member list, these are only a few hours old.

NEMmaster
NEMxtester
EspoNem
nemeconomy
utopian-nem
nem-team
nemutopian
p3tnaster
nemxt
nem-xterster


You can see the members list here listed from new to old.
https://bitcointalk.org/index.php?action=mlist;sort=registered;start=0;desc
There's probably much more.

I don't get it - why are they doing it? Is it to give NEM a bad name, or to show ill fitted strength? It's bizarre to me. Not to mention, they bragged about the thought of them going to hack acounts. 


Title: Re: New Phishing Link Going Around
Post by: theymos on September 14, 2014, 06:19:48 PM
I deleted the spam PMs and banned all of the users and IPs sending them.


Title: Re: New Phishing Link Going Around
Post by: EvilDave on September 14, 2014, 09:31:27 PM
Good work, mate. +1


Title: Re: New Phishing Link Going Around
Post by: ForgottenPassword on September 14, 2014, 09:56:40 PM
I deleted the spam PMs and banned all of the users and IPs sending them.

The source on the phishing website contains the following:
Code:
<title>Login</title><!--368ef74f52681c46ec130f3d13d9f239ea78ffb6c1718a5e8bda35ea3af8626a1c46ec130f3d13d9f239ea78ffb6c171138a3f3d4e7f8f4069051c46ec130f3d13d9f239ea78ffb6c171faa6-->

Is that last piece a session ID?

Maybe you could take a look at the logs and find out what IP was using that session ID.

It also looks like the phishing site is including style sheets from bitcointalk.org. You could set up the server to send a modified stylesheet that has a warning message added when it is requested by the phishing domain in order to warn people it is a phishing website.


Title: Re: New Phishing Link Going Around
Post by: jackjack on September 14, 2014, 10:16:18 PM
I deleted the spam PMs and banned all of the users and IPs sending them.

The source on the phishing website contains the following:
Code:
<title>Login</title><!--368ef74f52681c46ec130f3d13d9f239ea78ffb6c1718a5e8bda35ea3af8626a1c46ec130f3d13d9f239ea78ffb6c171138a3f3d4e7f8f4069051c46ec130f3d13d9f239ea78ffb6c171faa6-->

Is that last piece a session ID?

Maybe you could take a look at the logs and find out what IP was using that session ID.

It also looks like the phishing site is including style sheets from bitcointalk.org. You could set up the server to send a modified stylesheet that has a warning message added when it is requested by the phishing domain in order to warn people it is a phishing website.

Good ideas


Title: Re: New Phishing Link Going Around
Post by: mik3 on September 15, 2014, 04:05:41 AM
GUYS report them to their registrar so they remove the site ASAP.

Send an email to  abuse@internet.bs  with a link to this thread and an explanation.