Bitcoin Forum
April 26, 2024, 01:31:45 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: [Warning] Fake Brave Bounty Program Giving 1,500 BAT Tokens to each participant!  (Read 427 times)
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
October 22, 2019, 02:09:05 PM
Last edit: October 29, 2019, 11:59:38 AM by lobat999
Merited by suchmoon (4), xandry (2), Halab (2), Quickseller (1), DdmrDdmr (1), 1miau (1)
 #1

Just recently, I have received an email purportedly coming from the Brave browser team with the subject "Update your Brave browser. Get 1,500 BAT tokens" after which I became suspicious since 1.5k BAT bounty to be given individually sounds too good to be true and I see many red flags on the email (as illustrated below) and suspicious links which I find very obvious to be forms of scam tactics!

Please disregard this email and don't visit those sites listed on the form or give any personal information whatsoever. This is obviously a scam bounty program and the link to the download page is a phishing site - identical to the official Brave website! Also, we may run the risk of downloading a trojan or any other malware that could be embedded if we proceed to download that  installer without hesitation.



Follow up email with same phishing link








Comparisons

Brave Browser Official Main Page



Phishing site main page


                         Legit download message box                        Fake download message box  
       



Legit downloaded file
                     
 

Fake downloaded file


Note: Notice the distinctive differences on attributes on both pages, download message boxes and the downloaded files enclosed with red markers.


Code:
Phishing Site: https://bounty-brave.info/ 

Note: Some information on the email were omitted for privacy purposes.
1714095105
Hero Member
*
Offline Offline

Posts: 1714095105

View Profile Personal Message (Offline)

Ignore
1714095105
Reply with quote  #2

1714095105
Report to moderator
1714095105
Hero Member
*
Offline Offline

Posts: 1714095105

View Profile Personal Message (Offline)

Ignore
1714095105
Reply with quote  #2

1714095105
Report to moderator
1714095105
Hero Member
*
Offline Offline

Posts: 1714095105

View Profile Personal Message (Offline)

Ignore
1714095105
Reply with quote  #2

1714095105
Report to moderator
"The nature of Bitcoin is such that once version 0.1 was released, the core design was set in stone for the rest of its lifetime." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714095105
Hero Member
*
Offline Offline

Posts: 1714095105

View Profile Personal Message (Offline)

Ignore
1714095105
Reply with quote  #2

1714095105
Report to moderator
1714095105
Hero Member
*
Offline Offline

Posts: 1714095105

View Profile Personal Message (Offline)

Ignore
1714095105
Reply with quote  #2

1714095105
Report to moderator
Bttzed03
Legendary
*
Offline Offline

Activity: 2114
Merit: 1149


https://bitcoincleanup.com/


View Profile
October 22, 2019, 02:27:50 PM
 #2

Another phishing site, report it to https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en to be taken down asap.

Edit:

You can also post the phishing site in this format if you want more people to report it:
Code:
Phishing site: https:xxxx
LbtalkL
Full Member
***
Offline Offline

Activity: 1176
Merit: 162


View Profile
October 22, 2019, 02:35:27 PM
 #3

Thanks for posting it here, This is obviously a fake/phishing website but some newbies might be fool by them.  BAT using yahoo email is very suspicious in the first place. The only legit BAT airdrop is from brave browser and coinbase.

lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
October 22, 2019, 02:36:56 PM
 #4

Another phishing site, report it to https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en to be taken down asap.

Edit:

You can also post the phishing site in this format if you want more people to report it:
Code:
Phishing site: https:xxxx


Done. Thank you for the info. Smiley


Thanks for posting it here, This is obviously a fake/phishing website but some newbies might be fool by them.  BAT using yahoo email is very suspicious in the first place. The only legit BAT airdrop is from brave browser and coinbase.

Yeah. Its very obvious and the fact that users needs to download a Brave browser installer again doesn't feel right when they can do it via updates, assuming the bounty was legitimate.
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2296
Merit: 10731


There are lies, damned lies and statistics. MTwain


View Profile WWW
October 22, 2019, 03:13:51 PM
 #5

The brave site is pretty well cloned, although it is relatively simple, and most of the menu items just points to the original site’s content .. except for the download file itself which is different.

Virustotal displays the file as Malware (Avira does that so far): https://www.virustotal.com/gui/url/12322e193dda741bf0e7d6e5944b2d736c7f5fee9a625f5e3a2efa81823c4c2e/detection

Remember that the site itself does not necessarily encounter an entry using Virustotal (the close site does not: https://www.virustotal.com/gui/url/56a6e6a37b2c3fec6201ca9bd2839e50ab6c1f6b6bd1545e836a71b9a1530f99/detection), but rather the url that points to the download file. That is the one that needs to be examined with extra care.

In addition, ScamAdviser raises a bunch of warning signs that need to be looked at: https://www.scamadviser.com/check-website/bounty-brave.info.

The general problem is that, if you are not suspicious from the beginning, one normally does not go into the trouble of doing the above, thus potentially falling for the trap. Which goes to show that you are the first firewall against this from happening.
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
October 22, 2019, 09:49:18 PM
Last edit: October 23, 2019, 04:23:44 AM by lobat999
 #6

The brave site is pretty well cloned, although it is relatively simple, and most of the menu items just points to the original site’s content .. except for the download file itself which is different.

Virustotal displays the file as Malware (Avira does that so far): https://www.virustotal.com/gui/url/12322e193dda741bf0e7d6e5944b2d736c7f5fee9a625f5e3a2efa81823c4c2e/detection

Yeah, they cloned the site almost exactly as the original and official Brave site except for the "Google form" button beside the download button but if we hover our mouse to the download button, then we could easily distinguish the fake one which doesn't use the brave.com domain. I'm pretty sure there will be more detection once AV companies get to analyze the file thoroughly - I suspect its loaded with a trojan considering the fake installer file size is 9.2 MB whereas the genuine Brave installer is only at 1.2 MB!

The general problem is that, if you are not suspicious from the beginning, one normally does not go into the trouble of doing the above, thus potentially falling for the trap. Which goes to show that you are the first firewall against this from happening.

Absolutely! This is the first step of defense we all should practice! If we can just all become more vigilant and investigate a little on this type of fraudulent activities, then we can inform and sound an alarm immediately to the community so that in our own little way we could help in stopping this malwares to propagate further more. Smiley
Buttlebit
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
October 23, 2019, 07:27:42 AM
 #7

I'm so happy i didn't fall for this, as the clone was well planned and executed, i will share this information with others so they don't fall for it as well. Thank you very much for this information it is very helpful.
bassbity
Sr. Member
****
Offline Offline

Activity: 1092
Merit: 284


View Profile
October 23, 2019, 08:36:05 AM
 #8

I also receive emails like that even though I've never joined other BAT campaigns, but I often receive phishing emails.
Is there another way to stop this email, it is very annoying for me and this is afraid of being used by someone else.
Lucius
Legendary
*
Offline Offline

Activity: 3220
Merit: 5628


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
October 23, 2019, 02:21:49 PM
 #9

I also receive emails like that even though I've never joined other BAT campaigns, but I often receive phishing emails.
Is there another way to stop this email, it is very annoying for me and this is afraid of being used by someone else.

You receive such e-mails for the reason that your e-mail address posted publicly somewhere, and is probably part of some spam e-mail base that resales in the black market. The simplest solution is to create a new email, and if that is not an option to simply ignore such messages. Way to stop this e-mail is to report it as spam in settings of your e-mail provider, so after a certain number of reports, such e-mail will directly go in the spam folder.

For those who use Brave it is a known fact that users get only 5 BAT tokens at the start, and I think some $5 worth of tokens for the month of surfing. The very fact that someone is giving 1500 BATs is already enough warning that this is a fraud.


.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
October 23, 2019, 03:11:17 PM
Merited by Quickseller (1)
 #10

I also receive emails like that even though I've never joined other BAT campaigns, but I often receive phishing emails.
Is there another way to stop this email, it is very annoying for me and this is afraid of being used by someone else.

Since you often received phishing emails, I would assume your email address had fallen into the wrong hands which is very unfortunate but this scenario are very common nowadays considering that there are black markets where these kinds of data are being bought or sold for illicit purposes.

Now, its technically possible to block certain email addresses from sending us unsolicited emails but this is just a tentative solution since these perpetrators could easily circumvent this method just by using a new email address for sending spam phishing emails. Another one is to filter your emails and redirect it to a certain folder if your email platform provides that feature.

If you would like to received less spam and other malicious emails, I suggest you try to use disposable emails instead of your personal email and this could be used for one time purposes such as registrations to less important sites, etc., which could be later discarded at a predefined time.

Finally, I believe all of these techniques doesn't guarantee  a hassle free email experience, so that I think the best way to stop these kinds of email is to be more vigilant and suspicious and create a mass awareness or inform the community at once if we encounter it so that other people may know and could possibly avoid being victimized!

I guess time will come that these kinds of emails will be easily distinguished and avoided  that I think it will discourage its perpetrators from doing the same technique again if it becomes ineffective and could stop its operations thus could significantly reduce the amount of spam and malicious emails we received regularly!

"Awareness is key to prevention!"
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
October 29, 2019, 12:04:46 PM
 #11



Just updated the OP with an image of the scammers follow up email with the same phishing link that was sent to another email address of mine. It seems these bad actors are getting more brazen and more persistent with their phishing activities. Angry
cvasy
Sr. Member
****
Offline Offline

Activity: 520
Merit: 250


KUWA.ai


View Profile
November 03, 2019, 09:38:21 AM
 #12

Thank you for providing information that is handy for us, I also have received an incoming message from someone who did send airdrop brave link, but there are some of my friends who are trapped because they are tempted by the gifts given so that they follow all what is ordered by the fraudster including fill out the form and click on the download link, what do they need to do now to get rid of the phishing trap? Whether the download link will also work on Android because as far as I know the link is only for PCs, but my friend tried to download it via a mobile device but in the end the link did not work, did the phishing trap also affect the Android device?

|
|

█████████████████████████
██ ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ██
██ █████████████▀█████ ██
██ ███ ▀█████▀      ▀█ ██
██ ███     ▀▀      ▐██ ██
██ ███▌            ███ ██
██ ████▌          ▄███ ██
██ ██████       ▄█████ ██
██ ████▄▄▄▄▄▄▄████████ ██
██ ███████████████████ ██
██▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄██
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

█████████████████████████
██ ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ██
██ ████████████▀▀▀████ ██
██ ████████▀▀     ████ ██
██ █████▀    ▄▀  ▐████ ██
██ ██▀     ▄▀    ▐████ ██
██ ████▄▄ █▀     █████ ██
██ ██████ ▄▄█   ▐█████ ██
██ ████████████ ██████ ██
██ ███████████████████ ██
██▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄██
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
sheenshane
Legendary
*
Offline Offline

Activity: 2394
Merit: 1215


Cashback 15%


View Profile WWW
November 03, 2019, 10:06:56 AM
Merited by xandry (1)
 #13

Thank you for the awareness and the heads up as well, I also received email from them and now I'm curious where did they get my email address. I almost clicking the link they are given when I opened my Gmail account. Good thing I remember this thread of yours.



I almost fall into this trap because it was sent through my mail inbox, not in a spam message. But luckily I'm a Chrome user.


.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Strongkored
Legendary
*
Offline Offline

Activity: 2758
Merit: 1112


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
November 03, 2019, 12:12:44 PM
 #14

I got it yesterday, as it went to the inbox instead of to spam, I thought this was true, much less when I saw the sender using a old coin name Siacoin, I thought they were collaborating on a new project after re-cheking the domain they mentioned is different with real brave browser domain, so I immediately
deleted that email. Looks like they're sending gradually so there's still email about this bounty being sent over to look for another victim.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
desticy
Sr. Member
****
Offline Offline

Activity: 1512
Merit: 292


www.cd3d.app


View Profile
November 03, 2019, 12:18:19 PM
 #15

Thanks for the warning.
It seems that with the revival of the crypto market, its ancient inhabitants of scammers and scammers also came to life. In my opinion this is a good sign.

For me, this is the first sign that the Bat market and project in particular have good potential for the very near future. So soon we will see interesting movements in the market.
Be vigilant Now there are more and more cases of phishing attacks, follow the recommendations given by verified forum users.

panganib999
Hero Member
*****
Offline Offline

Activity: 1736
Merit: 589


View Profile WWW
November 03, 2019, 04:23:37 PM
 #16

Just recently, I have received an email purportedly coming from the Brave browser team with the subject "Update your Brave browser. Get 1,500 BAT tokens" after which I became suspicious since 1.5k BAT bounty to be given individually sounds too good to be true and I see many red flags on the email (as illustrated below) and suspicious links which I find very obvious to be forms of scam tactics!

Please disregard this email and don't visit those sites listed on the form or give any personal information whatsoever. This is obviously a scam bounty program and the link to the download page is a phishing site - identical to the official Brave website! Also, we may run the risk of downloading a trojan or any other malware that could be embedded if we proceed to download that  installer without hesitation.

There are modus and schemes floating around the forum that there are fake websites made for phishing and I've read some of those. they seemed legitimate and would really gibe you a hard time to identify whether its fake or not, but this one here, is obviouslyba click bait and would really give you doubts about opening it. Just looking at the user interface and the offer, those are the epitome of scams and click baits so. everyone, of you see one, best believe me all you have to do is to ignore it and don't give a shit about it. Never click links once you saw early signs of scams.
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
November 04, 2019, 05:22:10 AM
 #17

Thank you for the awareness and the heads up as well, I also received email from them and now I'm curious where did they get my email address. I almost clicking the link they are given when I opened my Gmail account. Good thing I remember this thread of yours.



I almost fall into this trap because it was sent through my mail inbox, not in a spam message. But luckily I'm a Chrome user.

You're welcome!  Being a part of this community, I guess its our duty to inform others on these pitfalls so that we may never become victims of it!

Now I understand that the email sent to you was sent by a different email address and I suppose these scammers are very aggressive on their phishing campaign and will do different tricks to become successful that I feel it is rather important to keep the community regularly informed about this until these threats have subsided, hopefully in the near future.

So I guess we should continue on keeping everybody aware about this as much as possible. Smiley
masulum
Legendary
*
Offline Offline

Activity: 2212
Merit: 1592


hmph..


View Profile WWW
November 04, 2019, 01:07:26 PM
Merited by xandry (1), Husna QA (1), lobat999 (1)
 #18

Another email I received today with same strategy using another name airdrop portal, ask to fill spreadsheet very same with @OP stories. Here is the proof from email I received.





Code:
https://brave-drop.info

.freebitcoin.       ▄▄▄█▀▀██▄▄▄
   ▄▄██████▄▄█  █▀▀█▄▄
  ███  █▀▀███████▄▄██▀
   ▀▀▀██▄▄█  ████▀▀  ▄██
▄███▄▄  ▀▀▀▀▀▀▀  ▄▄██████
██▀▀█████▄     ▄██▀█ ▀▀██
██▄▄███▀▀██   ███▀ ▄▄  ▀█
███████▄▄███ ███▄▄ ▀▀▄  █
██▀▀████████ █████  █▀▄██
 █▄▄████████ █████   ███
  ▀████  ███ ████▄▄███▀
     ▀▀████   ████▀▀
BITCOIN
DICE
EVENT
BETTING
WIN A LAMBO !

.
            ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
▄▄▄▄▄██████████████████████████████████▄▄▄▄
▀██████████████████████████████████████████████▄▄▄
▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
  ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
       ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.PLAY NOW.
lobat999 (OP)
Sr. Member
****
Offline Offline

Activity: 1078
Merit: 310



View Profile
November 07, 2019, 06:35:57 AM
 #19

~snip~

Thanks for this information. I will post the above phishing link for update and you can also visit this relevant thread Host-file to deal with phishing sites if you have not done so and you can update your hostfile accordingly for added security.
JeotQ
Member
**
Offline Offline

Activity: 406
Merit: 14


View Profile
November 07, 2019, 05:03:39 PM
 #20

A round of applause for detecting this out, wow i am impressed, God knows how many people would have fell for this trick, this is why its not always good to reply mails or try to claim coins through mails

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!