Bitcoin Forum
May 08, 2024, 06:20:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: FAKE - TRON AIRDROP - 18,000 TRX  (Read 196 times)
$crypto$ (OP)
Legendary
*
Offline Offline

Activity: 2366
Merit: 1041


Smart is not enough, there must be skills


View Profile WWW
July 07, 2020, 12:18:18 PM
Merited by The Cryptovator (1), notblox1 (1)
 #1

What happened; FAKE - TRON AIRDROP - 18,000 TRX

Website: https://tron-project.com/
Archived; http://archive.is/xhe8s

Code:
https://docs.google.com/forms/d/e/1FAIpQLSfnu7UOyKlP3794udoK5Xu2WIlAedYzyAqDvhlRpnRcGF-NRQ/viewform

Code:
Registrar	Hosting Concepts B.V. d/b/a Openprovider
IANA ID: 1647
URL: http://www.registrar.eu,http://www.openprovider.com
Whois Server: whois.registrar.eu

(p)
Dates Created on 2020-07-07
Expires on 2021-07-07
Updated on 2020-07-07
https://whois.domaintools.com/tron-project.com



I received this notification from an email



When you click on the wallet it will automatically download the malware wallet


R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
1715149201
Hero Member
*
Offline Offline

Posts: 1715149201

View Profile Personal Message (Offline)

Ignore
1715149201
Reply with quote  #2

1715149201
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, which will follow the rules of the network no matter what miners do. Even if every miner decided to create 1000 bitcoins per block, full nodes would stick to the rules and reject those blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
actmyname
Copper Member
Legendary
*
Offline Offline

Activity: 2562
Merit: 2504


Spear the bees


View Profile WWW
July 07, 2020, 01:12:01 PM
 #2

It's actually fortunate that the scammers were stupid enough to forget about the use of BCC. Reply to all in that email and make sure none of the potential victims go through with the link. After all, if they didn't realize that the "Bittrex Team" email came from yahoo of all places, they would probably be the exact audience that would be prone to this kind of scam.

TalkStar
Copper Member
Hero Member
*****
Offline Offline

Activity: 1204
Merit: 737


✅ Need Campaign Manager? TG > @TalkStar675


View Profile WWW
July 07, 2020, 02:38:57 PM
 #3

When you click on the wallet it will automatically download the malware wallet
Its too much risky for them who have limited amount of knowledge about wallet hackers. Its called force download by which they push their web vistors to download that malware wallet file. All their intention is to plant that malware file on visitors device which will play the key role for wallet hacking.

Note: I will suggest our community users to stay far from this malware coded website.


.

▄██████████████████████████▄
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
▀██████████████████████████▀
.

.

.

.

████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████


████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████












.KUCOIN LISTING WORKFLOW.
.
.KUCOIN COMPANY PROFILE..

.

sujonali1819
Legendary
*
Offline Offline

Activity: 2436
Merit: 1189


Need Campaign Manager?PM on telegram @sujonali1819


View Profile WWW
July 07, 2020, 03:16:31 PM
 #4

I reported a fake stellar airdrop here All are looking very similar to each other. Same technic to scam. First, collect emails, sending email to crypto user by a popular exchange named email, a spreadsheet for submitting info, Lastly force to download a wallet/software which have malware.

All seem the same scammer team is running these fake airdrops and malware to steal money.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
.
TalkStar
Copper Member
Hero Member
*****
Offline Offline

Activity: 1204
Merit: 737


✅ Need Campaign Manager? TG > @TalkStar675


View Profile WWW
July 07, 2020, 04:55:36 PM
 #5

I reported a fake stellar airdrop here All are looking very similar to each other. Same technic to scam. First, collect emails, sending email to crypto user by a popular exchange named email, a spreadsheet for submitting info, Lastly force to download a wallet/software which have malware.
Looks like they have a fixed roadmap by following that they are continuing their scam game. I am really curious to find out the source of emails by which they are targeting specific crypto users.  
 
All seem the same scammer team is running these fake airdrops and malware to steal money.
Yeap,,,most probably all these fake airdrop website owners are connected together and they have a strong source from where they get crypto users email.  


.

▄██████████████████████████▄
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
▀██████████████████████████▀
.

.

.

.

████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████


████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████












.KUCOIN LISTING WORKFLOW.
.
.KUCOIN COMPANY PROFILE..

.

sujonali1819
Legendary
*
Offline Offline

Activity: 2436
Merit: 1189


Need Campaign Manager?PM on telegram @sujonali1819


View Profile WWW
July 07, 2020, 05:08:04 PM
 #6

Yeap,,,most probably all these fake airdrop website owners are connected together and they have a strong source from where they get crypto users email.  
Yes, Obviously they have a strong source to collect emails. what I guess it could be this bitcointalk forum. Because what link I provided about stellar fake airdrop you can see a google form for submitting address and additional info where they put a slot for submitting bitcointalk username. So they know these people have a bitcointalk account too.

maybe they brought emails from the scam project, or they launch a fake airdrop or bounty where they asked for submitting email address. etc.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
.
btc_angela
Hero Member
*****
Offline Offline

Activity: 2604
Merit: 542



View Profile
July 08, 2020, 07:01:48 AM
 #7

Yeap,,,most probably all these fake airdrop website owners are connected together and they have a strong source from where they get crypto users email.  
Yes, Obviously they have a strong source to collect emails. what I guess it could be this bitcointalk forum. Because what link I provided about stellar fake airdrop you can see a google form for submitting address and additional info where they put a slot for submitting bitcointalk username. So they know these people have a bitcointalk account too.

There is a high chance that they are scraping emails here, or those bounties that are asking for emails in the past are being used by this scammers. Luckily, I haven't received any so far because I never joined bounty. And I agree that this is the same scammers all along, registering domain names one after another and then continue with that email list blast.


███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
$crypto$ (OP)
Legendary
*
Offline Offline

Activity: 2366
Merit: 1041


Smart is not enough, there must be skills


View Profile WWW
July 08, 2020, 10:19:26 AM
 #8

There is a high chance that they are scraping emails here, or those bounties that are asking for emails in the past are being used by this scammers. Luckily, I haven't received any so far because I never joined bounty. And I agree that this is the same scammers all along, registering domain names one after another and then continue with that email list blast.
I think it's like that they scrape the email from the previous bounty so they can easily send so many emails because it's already on their list, surely this will continue to be repeated and we will get the email really fed up with their trap.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
409H
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
July 10, 2020, 12:56:08 AM
Merited by robelneo (1)
 #9

Here's a run of the download in a sandbox: https://app.any.run/tasks/fa854a34-f9c9-4be6-9bfc-529ed16c94c3

Essentially, it installs a RAT on your system - most likely to steal keys/passwords/logins/cookies - and communicates via SOAP messages
robelneo
Legendary
*
Offline Offline

Activity: 3234
Merit: 1202


Bons.io Telegram Casino


View Profile WWW
July 10, 2020, 02:21:18 AM
 #10

Here's a run of the download in a sandbox: https://app.any.run/tasks/fa854a34-f9c9-4be6-9bfc-529ed16c94c3

Essentially, it installs a RAT on your system - most likely to steal keys/passwords/logins/cookies - and communicates via SOAP messages

Very interesting thank for posting this, now people will have an idea what happen when you visit the site and take the offer, the airdrop thing is now becoming very synonymous to scam, how many scams we have seen that cloak itself as airdrops, I already saw so many of it and some of them are being advertised on big channels like Adsense.


        █████████████████      ███████████████    ██████████  ████████    █████████████
    █    ███████   ███████  ████████      █████  ███████████ ████████    ██████   ██████ 
        █████████   ███████  ████████      █████  ████████████████████  ████████   ▀▀▀▀▀▀
   ▅▅  ████████   ███████  ████████      █████  ████████████████████  ████████
  █  ▀▀  ████████████████    ████████      █████  ████████████████████    ██████████████
     ▅▅████████   ███████  ████████      █████  ████████████████████              █████   
       ▀▀████████   ███████  ████████      █████  ████████████████████  ▄▄▄▄▄▄      █████
▅▅▅▅▄ ████████   ███████  ████████      █████  ████████ ███████████  ▀▀██████████████
        █████████████████     ████████████████   ████████ ███████████    ▀▀▀██████████


Your Intro
Telegram Casino
to Fun & Entertainment
The Next-Gen
Gaming Space
     ▃▃▃▃▃▃▃▃▃▃▃▃▃
  ▄▄█████████████▄▄
██▀               ▀████▄
                       ██
   ██            ■■    ██
 ██████        ■■  ■■  ███
   ██    ▀ ▀     ■■    ███     
     ▃▃▃▃▃▃▃▃▃▃        ██
    █████████████      ██
    ██          ████████▀
████▀           ▀█████▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!