Bitcoin Forum
November 16, 2024, 01:38:12 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: PSA: New electrum.org phishing attempt  (Read 253 times)
Wind_FURY (OP)
Legendary
*
Offline Offline

Activity: 3108
Merit: 1938



View Profile
June 29, 2019, 07:55:23 AM
Merited by bones261 (2), OmegaStarScream (1), Pmalek (1)
 #1

Be careful electrum users/newbies. Scammers, hackers, and thieves are becoming more active because of the new Bitcoin rally.

You are all targets, especially newbies.

https://twitter.com/electrumwallet/status/1144678604523147265?s=21

Quote

Do you see that little fleck of dust under the domain name in the left screenshot? Actually not dust. Enable show_punycode in Firefox in order to avoid phishing URLs.



██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
dnpotter
Jr. Member
*
Offline Offline

Activity: 37
Merit: 4


View Profile WWW
June 29, 2019, 09:01:38 AM
 #2

Thanks for the heads up.
hatshepsut93
Legendary
*
Offline Offline

Activity: 3038
Merit: 2161


View Profile
June 29, 2019, 11:00:17 AM
 #3

Nice catch, and nice tip about Firefox!

Also, people really shouldn't be googling or clicking on some links to websites after their first visit - important sites should always be bookmarked and accessed with bookmark. Same goes for typing - autocomplete can lead to a fake site, or you can make a typo and get to hacker's site. And before visiting the site for the first time, always google search what the official site is, and check people's discussions first - never simply click on one of the results.
jossiel
Hero Member
*****
Offline Offline

Activity: 3178
Merit: 636


DGbet.fun - Crypto Sportsbook


View Profile
June 29, 2019, 10:02:11 PM
 #4

I remember that there's also same character of that letter 'L' that has been used as Binance phishing site before. Thanks for the warning.

I see that there's also a post like this on Beginners and Help.

Warning: Another Electrum phishing site

jerry0
Full Member
***
Offline Offline

Activity: 1792
Merit: 186


View Profile
July 11, 2019, 12:38:25 AM
 #5

How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself


www.electrum.org


You should be fine right?
nc50lc
Legendary
*
Offline Offline

Activity: 2604
Merit: 6416


Self-proclaimed Genius


View Profile
July 11, 2019, 03:27:52 AM
Merited by Pmalek (1)
 #6

How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself
www.electrum.org
You should be fine right?
Yes.

FYI, the "eļectrum.org" is the ASCII version of punycode: "xn--eectrum-9hb.org" <--- Warning: phishing site.
It will be displayed as the latter if you're using Firefox with show_punycode enabled.

Try to type the original url on the right box here: https://www.punycoder.com/ then press "<<Convert to text" and it will be displayed as eļectrum.org.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Artemis3
Legendary
*
Offline Offline

Activity: 2030
Merit: 1573


CLEAN non GPL infringing code made in Rust lang


View Profile WWW
July 30, 2019, 02:46:57 AM
 #7

How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself

www.electrum.org

You should be fine right?

This is fine but its not the end of the story. There is another possible attack vector by malware messing your dns or hosts file, so it might resolve electrum.org to a rogue phishing site. So no, not even that is safe enough (and actually searching it might give you the real IP address instead).

I think the only way to be sure is doing the gpg signature check:


██████
███████
███████
████████
BRAIINS OS+|AUTOTUNING
MINING FIRMWARE
|
Increase hashrate on your Bitcoin ASICs,
improve efficiency as much as 25%, and
get 0% pool fees on Braiins Pool
joniboini
Legendary
*
Offline Offline

Activity: 2380
Merit: 1807



View Profile WWW
July 30, 2019, 03:11:28 AM
 #8

There is another possible attack vector by malware messing your dns or hosts file, so it might resolve electrum.org to a rogue phishing site. So no, not even that is safe enough (and actually searching it might give you the real IP address instead).

Another way to solve this is to use a live OS to access the website, download the files and verify it.

Installing anti-phishing malware might also help to prevent you accidentally access a punycode website, but of course, that won't work if your DNS was hijacked.

▄▄███████████████████▄▄
▄███████████████████████▄
████████▀░░░░░░░▀████████
███████░░░░░░░░░░░███████
███████░░░░░░░░░░░███████
██████▀░░░░░░░░░░░▀██████
██████▄░░░░░▄███▄░▄██████
██████████▀▀█████████████
████▀▄██▀░░░░▀▀▀░▀██▄▀███
███░░▀░░░░░░░░░░░░░▀░░███
████▄▄░░░░▄███▄░░░░▄▄████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 CHIPS.GG 
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
███▀░▄░▀▀▀▀▀░▄░▀███
▄███
░▄▀░░░░░░░░░▀▄░███▄
▄███░▄░░░▄█████▄░░░▄░███▄
███░▄▀░░░███████░░░▀▄░███
███░█░░░▀▀▀▀▀░░░▀░░░█░███
███░▀▄░▄▀░▄██▄▄░▀▄░▄▀░██
▀███
░▀░▀▄██▀░▀██▄▀░▀░██▀
▀███
░▀▄░░░░░░░░░▄▀░██▀
▀███▄
░▀░▄▄▄▄▄░▀░▄███▀
▀█
███▄▄▄▄▄▄▄████▀
█████████████████████████
▄▄███████▄▄
███
████████████▄
▄█▀▀▀▄
█████████▄▀▀▀█▄
▄██████▀▄▄▄▄▄▀██████▄
▄█████████████▄████████▄
████████▄███████▄████████
█████▄█████████▄██████
██▄▄▀▀▀▀█████▀▀▀▀▄▄██
▀█████████▀▀███████████▀
▀███████████████████▀
██████████████████
▀████▄███▄▄
████▀
████████████████████████
3000+
UNIQUE
GAMES
|
12+
CURRENCIES
ACCEPTED
|
VIP
REWARD
PROGRAM
 
 
  Play Now  
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!