Bitcoin Forum
June 20, 2024, 06:56:45 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [WARNING][SCAM]Fake Stellar airdrop from fake HitBTC accounts  (Read 149 times)
witcher_sense (OP)
Legendary
*
Offline Offline

Activity: 2380
Merit: 4372


🔐BitcoinMessage.Tools🔑


View Profile WWW
August 26, 2020, 05:30:43 AM
Merited by The Cryptovator (1), ScamViruS (1), Symmetrick (1)
 #1

What happened: Fake/malicious website
 
ANN: not listed here yet

Scammers Website:
Code:
https://official-stellar.com/


http://web.archive.org/web/20200730150244/https://xn--sellar-ilb.com/
https://archive.is/wLVEu

Quote
Domain Name: OFFICIAL-STELLAR.COM
Registry Domain ID: 2555371346_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.registrar.eu
Registrar URL: http://www.openprovider.com
Updated Date: 2020-08-24T20:59:19Z
Creation Date: 2020-08-24T20:52:14Z
Registry Expiry Date: 2021-08-24T20:52:14Z

Recently I recieved two emails at once from "HitBTC Support" and "HitBTC Info", which was obviously a fake, but I wonder
why scammer chose that scam exchange to promote fake website and airdrops. Doesn't look very attractive.
Proof: https://bitcointalk.org/index.php?topic=5168200.msg52162889#msg52162889




According to whois, website is only two days-old and impersonating official stellar.org albeit it doesn't look similar to official one.



In order to "claim" your free 2500 XLM, you need to download some malicious software (Windows only Grin).
VirusTotal didn't find anything red in that file, but I believe this software is somehow trying to steal private keys or something like that.

Either way, it is a scam and should be avoided at all costs. Be careful.


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
ScamViruS
Hero Member
*****
Offline Offline

Activity: 1778
Merit: 720


Top Crypto Casino


View Profile WWW
August 26, 2020, 07:31:30 PM
 #2

I also received this fake giveway email. When I started checking their activities, I saw that they were trying to attack through Malware. Those who are tempted to download and install this app, their entire system may fall under the control of scammers. I checked their app and the VirusTotal showing that malware exists in this app.




VirusTotal: https://www.virustotal.com/gui/url/2cdc7e86a6934509561602491e375cd697eba72c492fe230dfd211ac3b45b87a/detection

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
CryptoYar
Hero Member
*****
Offline Offline

Activity: 1064
Merit: 638



View Profile
August 27, 2020, 04:30:56 AM
 #3

I remember a few months back, I received a similar email, I was asked to visit a website to claim xlm coins. [ Just like this website.]
However, I downloaded it and scanned at Virustotal before installing it, it was a malware. I can say with certainty that this is the same group every time they send an email with different domains.

@witcher_sense Did you also receive this through email? Or you have found some other way.

*Edit* 
Sorry, I had not seen it.
 
Quote
Recently I recieved two emails at once from "HitBTC Support" and "HitBTC Info", which was obviously a fake, but I wonder
why scammer chose that scam exchange to promote fake website and airdrops. Doesn't look very attractive.
Proof:
Furious 7
Hero Member
*****
Offline Offline

Activity: 2898
Merit: 674


https://duelbits.com/


View Profile
August 27, 2020, 08:03:51 AM
 #4

I also received this fake giveway email. When I started checking their activities, I saw that they were trying to attack through Malware. Those who are tempted to download and install this app, their entire system may fall under the control of scammers. I checked their app and the VirusTotal showing that malware exists in this app.
....

VirusTotal: https://www.virustotal.com/gui/url/2cdc7e86a6934509561602491e375cd697eba72c492fe230dfd211ac3b45b87a/detection
The scamer sends a large number of emails simultaneously including me receiving the notification email. Will this scamer really continue to act by sending a link via email? oh no, if the application is really installed, the data will be easily stolen with a malware virus.

That's a good catch for exposing a scam like this to the public so it's an example to avoid.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!