Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add-domain - phishing #736

Merged

Conversation

ninjacatcher
Copy link
Contributor

@ninjacatcher ninjacatcher commented Feb 1, 2025

Phishing Domain/URL/IP(s):

trust.wallet-web3.io
ton-keeper.info
metamack.io
atomi.cwallet.cc
ex.odous.org
tronlink.bet
trustwallet.ing
legder.cc
atomic-wallet.trade
exod.us.com
tonkeeper.ee

Impersonated domain

atomicwallet.io
tronscan.org
exodus.com
ledger.io
tonkeeper.com
metamask.io
some other cryptowallets/companies

Describe the issue

Most are exactly the same method of attack described in #694 and #703

Reminder: the content on the sites is disguised as a fake Cloudflare captcha, once clicked on which redirects to a third-party “cloaked” domain, most commonly via the /2.php link.

Detailed examples of such a redirect:
On Cloudflare Radar: https://radar.cloudflare.com/scan/5562f860-3f86-474b-b8b6-a887088116c8/summary
On urlscan.io: https://urlscan.io/result/f891eb09-0aa4-4f85-a6f5-407ae5ea16bb/

image

Anti-detect “system” has basic AV protection methods, using IP type detection mechanisms and UserAgent types, as this request failed: https://urlscan.io/result/4a759a20-1722-4aa3-9bb2-b63ace9718d5/.

Related external source

https://www.virustotal.com/gui/domain/trust.wallet-web3.io
https://www.virustotal.com/gui/domain/ton-keeper.info
https://www.virustotal.com/gui/domain/metamack.io
https://www.virustotal.com/gui/domain/atomi.cwallet.cc
https://www.virustotal.com/gui/domain/ex.odous.org
https://www.virustotal.com/gui/domain/tronlink.bet
https://www.virustotal.com/gui/domain/trustwallet.ing
https://www.virustotal.com/gui/domain/legder.cc
https://www.virustotal.com/gui/domain/atomic-wallet.trade
https://www.virustotal.com/gui/domain/exod.us.com
https://www.virustotal.com/gui/domain/tonkeeper.ee

Screenshot

Click to expand So far, only one active company has been able to take a screenshot of it

image

@g0d33p3rsec g0d33p3rsec merged commit 6d94b27 into Phishing-Database:master Feb 2, 2025
1 check passed
@g0d33p3rsec
Copy link
Contributor

Excellent report. Many thanks for the contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants