Bitcoin Forum
September 24, 2024, 03:21:08 PM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [SCAM] pangoıinminer.com (homograph/Punycode attack)!!!  (Read 165 times)
SFR10 (OP)
Legendary
*
Offline Offline

Activity: 3136
Merit: 3521


Crypto Swap Exchange


View Profile WWW
August 03, 2022, 12:50:04 PM
Last edit: September 26, 2022, 06:45:16 PM by SFR10
Merited by stompix (2), The Cryptovator (2), JeromeTash (1), Stalker22 (1)
 #1

What happened :
While I was browsing the Mining board, I noticed a new user with a couple of posts [one of them is a newly created thread] that clearly shows he/she is shilling for a specific website and when I looked closer, I noticed it's one of those Punycode attacks!
- It appears that they're taking advantage of the fact that the original website (previous archive) is currently down!

Scammers Profile Link:
Innominer

Reference Link:
Latest posts of Innominer [archived]

Additional Notes:
If you go to their website and copy everything from the search bar and post it anywhere, it'll lead to the following result:

Code:
https://www.xn--pangoinminer-54b.com/shop/

Tagged and "created a flag".

Update:

Look who's back [new account = Sirocco3] promoting the "link in the subject field" after a short hiatus and it appears that he/she included another fake website in the mix as well...

Reference Link:
Latest posts of Sirocco3 [archived]

Tagged and "created a flag".

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Stalker22
Legendary
*
Offline Offline

Activity: 1638
Merit: 1393



View Profile
August 03, 2022, 08:06:27 PM
 #2

Upon reviewing his profile, it appears that the moderators have deleted all of his posts. I wonder why he has not been nuked yet.

I supported the flag.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
JeromeTash
Legendary
*
Offline Offline

Activity: 2282
Merit: 1248


Heisenberg


View Profile
August 03, 2022, 08:45:14 PM
 #3

Upon reviewing his profile, it appears that the moderators have deleted all of his posts. I wonder why he has not been nuked yet
Wait, are people who post scam/phishing links always nuked as well? I thought they usually nuke mostly newly created spambots and profiles that share malicious links or malware.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Stalker22
Legendary
*
Offline Offline

Activity: 1638
Merit: 1393



View Profile
August 03, 2022, 10:12:27 PM
Merited by NeuroticFish (1)
 #4

Upon reviewing his profile, it appears that the moderators have deleted all of his posts. I wonder why he has not been nuked yet
Wait, are people who post scam/phishing links always nuked as well? I thought they usually nuke mostly newly created spambots and profiles that share malicious links or malware.

It is a newbie account with only two posts, and both were used to spread malicious links. I would nuke his ass. Grin
https://ninjastic.space/search?author=Innominer

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
SFR10 (OP)
Legendary
*
Offline Offline

Activity: 3136
Merit: 3521


Crypto Swap Exchange


View Profile WWW
August 05, 2022, 09:38:26 AM
 #5

I wonder why he has not been nuked yet.
It probably has something to do with the fact that it only counted as a phishing/spoofed website, but it's not going to have a negative effect on this case since I'm pretty sure the scammer in question realized he/she got caught and edited the subject field of the above thread with a smiley before it got deleted [not sure why ninjastic.space doesn't have the edited version].

Wait, are people who post scam/phishing links always nuked as well?
AFAIK, this usually doesn't happen but perhaps there's been some exceptions in the past:


Btw, thanks guys for supporting the flag Smiley

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
The Cryptovator
Legendary
*
Offline Offline

Activity: 2352
Merit: 2216

Signature space for rent


View Profile WWW
August 05, 2022, 07:43:01 PM
 #6

The type of domain itself is suspicious to me. I don't click these types of a domain when I see them. Any legit brand wouldn't choose this kinda fucking domain. So we need just stay away from such suspicious things that we aren't familiar with. Shouldn't be greedy, so you can avoid a lot of scams in your life. Thanks, OP for sharing with us, keep it up.

Signature Space for Rent
NotATether
Legendary
*
Offline Offline

Activity: 1736
Merit: 7278


In memory of o_e_l_e_o


View Profile WWW
August 06, 2022, 04:53:16 AM
Merited by SFR10 (1)
 #7

pangoiinminer .com

Code:
https://www.xn--pangoinminer-54b.com/shop/

Lynx without UTF-8 support displays that as: pangoM-DM-1inminer.com.

This is actually a good offensive tool that can be made against homographic punycode. The entire page is read, all of the HTTP[ S ]:// links are extracted by regex up to the next slash (don't worry, HTML on regex is fine in this case, and then if there are any junked-up characters like M-DM-1, then it is definiely a punycode link and a bot can report it to moderators.

To ease system load, it can periodically refresh "most recent unread posts" - but it has the disadvantage that it report the post if it comes from anybody. That means this post itself would also get reported to mods.

SFR10 (OP)
Legendary
*
Offline Offline

Activity: 3136
Merit: 3521


Crypto Swap Exchange


View Profile WWW
September 26, 2022, 06:44:50 PM
 #8

Look who's back [new account = Sirocco3] promoting the "link in the subject field" after a short hiatus and it appears that he/she included another fake website in the mix as well...

Reference Link:
Latest posts of Sirocco3 [archived]

Tagged and "created a flag".

Added to the first post!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!