Bitcoin Forum
November 04, 2024, 08:14:41 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Chainlink phishing SCAM - chianlink.io 🔺  (Read 197 times)
dkbit98 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 7548



View Profile WWW
October 23, 2019, 11:12:41 PM
Last edit: October 25, 2019, 09:55:23 AM by dkbit98
Merited by Rikafip (1)
 #1

What happened: fake Chainlink phishing website - chianlink.io



Website: https://chianlink.io/
Archived:
https://web.archive.org/web/20191023225418/https://chianlink.io/staking/

Quote
Domain Name: CHIANLINK.IO
Registry Domain ID: D503300001182008932-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2019-10-16T11:27:15Z
Creation Date: 2019-10-16T11:27:04Z
Registry Expiry Date: 2020-10-16T11:27:04Z

Fake blog: https://blog.chianlink.io

Fake wallet: https://wallet.chianlink.io/
archived: https://web.archive.org/web/20191023230624/https://wallet.chianlink.io/

They are asking for your Ethereum private keys. Pure phishing SCAM.

 



█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
dkbit98 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 7548



View Profile WWW
October 25, 2019, 08:15:19 PM
 #2

Update:

Reported to google, symantec and metamask

And metamask blacklisted this phishing scam website


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Chikito
Legendary
*
Offline Offline

Activity: 2562
Merit: 2076


View Profile WWW
October 26, 2019, 12:49:23 AM
 #3

Update:
Reported to google, Symantec and metamask
I see the site doesn't appear and suspended



We have to careful IP address: 198.54.115.191
they always change their domain to open scamming people again
https://www.virustotal.com/gui/ip-address/198.54.115.191/relations

Quote
2019-10-26-tshukwasolar.com
2019-10-26-30daysofgratitude.live
2019-10-25-remodelingkirklandwa.com
2019-10-25-jordanyep.com
2019-10-25-www.jordanyep.com
2019-10-25-buyredbull.ca
2019-10-25-www.buyredbull.ca
2019-10-25-huntinghoop.com
2019-10-25-gacimonline.com
2019-10-25-www.impact2050.com

and make another the virus

https://www.virustotal.com/gui/url/13f373f670b993809d305494cb3c55a4cba246e02d00b2bf09ed601fc5d23812/detection




sikke
Sr. Member
****
Offline Offline

Activity: 504
Merit: 250


View Profile
October 26, 2019, 06:54:36 AM
 #4

Good job, OP. Probably directly contributed to them getting banned from their web host.

Anyhow, this is a very obvious example of a phishing scam. There are much more sophisticated ones which take advantage of certain non-ASCII codes that appear on browsers as ASCII text to exactly reproduce what a site looks like (there are probably hundreds of them for exchanges alone).

Just don't click on any google ads that pop up on search results, nor blindly trust on any clickable link that claim to be the official one.
dkbit98 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 7548



View Profile WWW
October 26, 2019, 08:23:35 AM
 #5

We have to careful IP address: 198.54.115.191
they always change their domain to open scamming people again
https://www.virustotal.com/gui/ip-address/198.54.115.191/relations

Thanks for adding this information.

Good job, OP. Probably directly contributed to them getting banned from their web host.

Yes, I was fast to report them everywhere I could to ban them as fast as possible.
I am happy with results  Grin

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!