Today I have received an email in my primary inbox (not in spam). Where I see the name of the sender is Bittrex news, curiously try to Open the email for more reading. And found they are promoting fake steller airdrop and malware. So I decided to warn the newbies here. because the newbies has more chance to get trapped in this type of airdrops. Let's start...
The email comes from:
They sent he email to not only me but also hundreds of email account at the same time
They provide this documents link in the description
https://docs.google.com/forms/d/e/1FAIpQLScHApfQJWOK-ys_zGd0hoMdkuaTvpqDvp_TpdH0ZzyXHwDyLw/viewform
archiveIn this google documents, they provide how to claim the airdrop, Also provided the fake site link.
https://stellar-company.com/
archiveI have laughed a little bit when I see that they also ask the bitcointalk username for submitting
Site domain information:
Registrar Info
NameHosting Concepts B.V. d/b/a Openprovider
Whois Serverwhois.registrar.eu
Referral URLhttp://www.registrar.eu
StatusclientTransferProhibited https://icann.org/epp#clientTransferProhibited
ok https://icann.org/epp#ok
Important Dates
Expires On2021-04-06
Registered On2020-04-06
Updated On2020-05-02
Name Servers
ns1.md-86.webhostbox.net162.215.252.35
ns2.md-86.webhostbox.net162.215.252.35
Now as I said previously people need to download a wallet to claim this airdrop. The link of the wallet file
After checking the file link in virus total I found that the file contains malware.
source:
https://www.virustotal.com/gui/url/3c7f1a9199c4a673dbea01a259b5f8a9edfdd04be6074e0b7c5733e3b6e881e9/detectionSo they have arranged this method step to step for spreading their fake wallet and malware on the internet. I don't know how much people have already get trapped here. But basically newbies in online earning people are trying these airdrop to earn a few bucks without thinking or investigating anything.
And my main motive was to warn newbies who are not much aware about these things. Be aware, investigate, save your computer, and virtual money from malware. Thanks for reading.