Bitcoin Forum
April 27, 2024, 07:07:43 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Scam]: Fake Theta Wallet  (Read 133 times)
Baofeng (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1655



View Profile
July 11, 2020, 11:19:57 PM
Merited by TimeTeller (1), witcher_sense (1)
 #1

What happened: Fake and Clone Theta wallet. Do not used this website. The original one is https://wallet.thetatoken.org/unlock/keystore-file. And with the DeFi hype today, threat actors are catching up and using wallets to get someone fall for their trick.

Website:
Code:
http://thetatoke.org/

Archive: http://archive.is/TSphF



Quote
Whois Record for ThetaToke.org
 Domain Profile
Registrant Country   cn
Registrar   GoDaddy.com, LLC
IANA ID: 146
URL: http://www.whois.godaddy.com
Whois Server: whois.godaddy.com

(p)
Registrar Status   clientDeleteProhibited, clientRenewProhibited, clientTransferProhibited, clientUpdateProhibited
Dates   62 days old
Created on 2020-05-10
Expires on 2021-05-10
Updated on 2020-07-09    
Name Servers   NS55.DOMAINCONTROL.COM (has 54,213,256 domains)
NS56.DOMAINCONTROL.COM (has 54,213,256 domains)
 
Tech Contact   —
IP Address   104.203.20.6 - 22 other sites hosted on this server

https://whois.domaintools.com/thetatoke.org

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
1714244863
Hero Member
*
Offline Offline

Posts: 1714244863

View Profile Personal Message (Offline)

Ignore
1714244863
Reply with quote  #2

1714244863
Report to moderator
Once a transaction has 6 confirmations, it is extremely unlikely that an attacker without at least 50% of the network's computation power would be able to reverse it.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714244863
Hero Member
*
Offline Offline

Posts: 1714244863

View Profile Personal Message (Offline)

Ignore
1714244863
Reply with quote  #2

1714244863
Report to moderator
1714244863
Hero Member
*
Offline Offline

Posts: 1714244863

View Profile Personal Message (Offline)

Ignore
1714244863
Reply with quote  #2

1714244863
Report to moderator
1714244863
Hero Member
*
Offline Offline

Posts: 1714244863

View Profile Personal Message (Offline)

Ignore
1714244863
Reply with quote  #2

1714244863
Report to moderator
TimeTeller
Hero Member
*****
Offline Offline

Activity: 2716
Merit: 588


View Profile
July 11, 2020, 11:27:17 PM
Merited by Baofeng (1)
 #2

If they created it few months ago, I wonder how many people were already deceived by this site?
If you are a crypto user and wants to use online wallets, you need to make sure that you are in the legit sites.
Scammers will always find a way how to lure the users using similar domain names.
Baofeng (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1655



View Profile
July 12, 2020, 03:30:27 AM
 #3

If they created it few months ago, I wonder how many people were already deceived by this site?
If you are a crypto user and wants to use online wallets, you need to make sure that you are in the legit sites.
Scammers will always find a way how to lure the users using similar domain names.

We can't really tell if there are users who already fall for this trap, but what worry us all is that the website is still up and has the potential to trick new users.

And there are still more scam sites out there:

Code:
http://thetatokn.org/
http://thetatoen.org/
http://thetatken.org/
http://thetaoken.org/

And obviously, same actors behind. And I will assume that they have the this scam kits on their hand that's why it is very easy for them to create this sites.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
TalkStar
Copper Member
Hero Member
*****
Offline Offline

Activity: 1204
Merit: 737


✅ Need Campaign Manager? TG > @TalkStar675


View Profile WWW
July 12, 2020, 03:49:24 AM
 #4

And there are still more scam sites out there:

Code:
http://thetatokn.org/
http://thetatoen.org/
http://thetatken.org/
http://thetaoken.org/

And obviously, same actors behind. And I will assume that they have the this scam kits on their hand that's why it is very easy for them to create this sites.

Actually their target is specific and that's the reason why they are using almost same looking domains.

No doubt that all these sites are running by the same group of scammers and after revealing the truth of their one project they move to another one. Its interesting to see that this guys have good experience of choosing domain names for phishing sites. All these domain have been taken just by dropping one letter everytime.


.

▄██████████████████████████▄
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
███████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
▀██████████████████████████▀
.

.

.

.

████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████


████░█▄
████░███▄
████▄▄▄▄▄
█████████
█████████
█████████












.KUCOIN LISTING WORKFLOW.
.
.KUCOIN COMPANY PROFILE..

.

sharos
Jr. Member
*
Offline Offline

Activity: 551
Merit: 4


View Profile WWW
July 12, 2020, 04:15:10 AM
 #5

Now a Days, It’s difficult to found a safe place for cryptocurrency. I think, We don't need to wait much more to see a native using of Cryptocurrency. Already some school, collage accept fee by bitcoin. If all country accept cryptocurrency like native currency then government will take step against this type scammer.

I am waiting for that day.   
409H
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
July 12, 2020, 03:28:08 PM
Merited by CucakRowo (1)
 #6

By pivoting the infra, we have found many more of these: https://twitter.com/search?q=theta%20from%3Acryptophishing&src=typed_query&f=live
CucakRowo
Hero Member
*****
Offline Offline

Activity: 994
Merit: 593


aka JAGEND.


View Profile WWW
July 12, 2020, 05:59:04 PM
 #7

By pivoting the infra, we have found many more of these: https://twitter.com/search?q=theta%20from%3Acryptophishing&src=typed_query&f=live
Hey, thanks for sharing this information. Wonder from where he can found all those scam sites. That twitter account activities reminds me of ICOEthics.


409H
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
July 13, 2020, 03:53:25 PM
 #8

By pivoting the infra, we have found many more of these: https://twitter.com/search?q=theta%20from%3Acryptophishing&src=typed_query&f=live
Hey, thanks for sharing this information. Wonder from where he can found all those scam sites. That twitter account activities reminds me of ICOEthics.



This is my bot, which is fed the data from CryptoScamDB (another project that I maintain with MyCrypto). We find them by user reports and pivoting infrastructure via tools like passivedns Cheesy
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!