Guys found today a fake myetherwallet website steal address from phishing
Address of Hacker ethereum:
0xBDfaecb4eE0d1880e8d2Ae693b40EB00104D3077
Address of the fake website
https://xn--myethrwalle-jb9e19a.com/it display DNS name as myetherwallet.com with dots on letter T to trick
Funny thing that it still got a Valid SSL certificate from Bitdefender
https://imgur.com/a/5LSuIhttps://imgur.com/a/UqZQwhttps://imgur.com/a/ofvUs----------------------------------------------------------------------------------------------------------------------------------
Update:
---------
Sorry Guys but no one seemed to got my explanation of the Phishing Attack of MEW, Punycode Phishing Attacks Undecided
this link explain it well, this exactly what happened and website still active today he got more 12000$ of more confiscated wallet Angry
By default, many web browsers use ‘Punycode’ encoding to represent unicode characters in the URL to defend against Homograph phishing attacks. Punycode is a special encoding used by the web browser to convert unicode characters to the limited character set of ASCII (A-Z, 0-9), supported by International Domain Names (IDNs) system.
This loophole allowed the researcher to register a domain name xn--80ak6aa92e.com and bypass protection, which appears as “apple.com” by all vulnerable web browsers, including Chrome, Firefox, and Opera, though Internet Explorer, Microsoft Edge, Apple Safari, Brave, and Vivaldi are not vulnerable.
Here, xn-- prefix is known as an ‘ASCII compatible encoding’ prefix, which indicates web browser that the domain uses ‘punycode’ encoding to represent Unicode characters, and Because Zheng uses the Cyrillic "a" (U+0430) rather than the ASCII "a" (U+0041), the defence approach implemented by web browser fails.
Full Article !!
https://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.htmlPLEASE BE CAREFUL !! MEW link will show correctly in Chrome & also with Valid SSL !!
I will be working on new project to track the Funds on Blockchain ! and Score Wallets and Tag the coins Dispersed ..
i mean why we want blockchain Huh We know the stealer ID, we know his links with Exchanges wallets... we tracked the money stolen and we know exactly where it is !!
if we cannot do something about it or crime report.. is better to be back to FIAT ! :/ anyhow i tracked his wallet to bittrex transfer and other stuff
Anyway we can report this to Bittrex ? legal authority ? at least to lock the fund and not let him cash easily