Author

Topic: {Warning}: Fake Blockchain.com Phishing site (Read 194 times)

mk4
legendary
Activity: 2870
Merit: 3873
Paldo.io 🤖
I assume the domain name registrars know the identities of those scammers who register phishing domains. Do the take any legal actions against them?
I'm really not sure about this so don't quote me on it, but as far as I know there are domain name registrars that require little to no personal information. That, or these scammers are most likely faking their information. And also taking note that most domain name sellers like Namecheap accepts bitcoin payments.

Wouldn't be better to offer the possibility for anyone who register a new domain name to reserve all its variants too or blacklist them. It would limit these phishing attacks significantly.
Most bigger companies actually do this, but mostly for only obvious typos. (e.g. facebok.com redirects to facebook.com). It would be unfeasible for these companies to own literally every single slightly-similar variants because it would literally be thousands and thousands of domains.
hero member
Activity: 2870
Merit: 594
I assume the domain name registrars know the identities of those scammers who register phishing domains. Do the take any legal actions against them?
Wouldn't be better to offer the possibility for anyone who register a new domain name to reserve all its variants too or blacklist them. It would limit these phishing attacks significantly.
I doubt that this criminals are giving out their true identify when registering this domain names. Yes, its possible that variants can be registered so that there's no way that this scammers to used that website name. However, scammers are very clever that's why they uses puny code attacks.
legendary
Activity: 2702
Merit: 3045
Top Crypto Casino
I assume the domain name registrars know the identities of those scammers who register phishing domains. Do the take any legal actions against them?
Wouldn't be better to offer the possibility for anyone who register a new domain name to reserve all its variants too or blacklist them. It would limit these phishing attacks significantly.
hero member
Activity: 2142
Merit: 670
Hire Bitcointalk Camp. Manager @ r7promotions.com
Another fake blockchain.com is on the wild. Just 9 day old site, please be careful.

(p)
Registrar Status   clientTransferProhibited
Dates   9 days old
Created on 2020-07-08
Again, new phishing sites, just created several days ago. Now, the site has gone. Hopefully, it was sut down by the system, not by the owner of the domain so that they can activate it again later.
Well, seen from the display at glance, it is same. if we are not careful enough, it will really trick us. Moreover, for those who are new in this crypto world, they may become victims so easily. Well, it is better to double or triple check the domain before login in. Personally, I have bookmarked the important sites in my browser so that we do not need to search anymore if going to log in or access the sites. It wil help to decrease the chance of the phishing. However, if it is about the new sites, really must be careful to triple check the url link and alos its domain carefully.

The "ュ" character seems to be a Japanese character so I don't think totally blocking such characters would be a great idea. Especially knowing that .com domains are just getting scarcer and scarcer as time goes.
Directly translate this character, and "ュ" means "The".  Cheesy Cheesy
Of course, the character will be allowed because it is Japanese character and the domain providers will not know if the domain initially will be used for phishing or scam. But with the report tiekcet, it will help us to let them know and shut down the sites.
legendary
Activity: 2576
Merit: 1655
How did you come across that site? The L looks really ugly like that too 😅.

Perhaps those criminals are in a hurry to release their website. Usually what they do is to redirect to a more readable but very dubious typo-squatting or puny code.  Grin

If everyone wanted to see how Namecheap address this issue you may look at the image below



The status says still awaiting but I can't access that fake site anymore. Thank you for those who have reported it to Google as well.
mk4
legendary
Activity: 2870
Merit: 3873
Paldo.io 🤖
can't those domain providers block punycode so domain like this won't be able to show up again?

The "ュ" character seems to be a Japanese character so I don't think totally blocking such characters would be a great idea. Especially knowing that .com domains are just getting scarcer and scarcer as time goes.
sr. member
Activity: 770
Merit: 268
can't those domain providers block punycode so domain like this won't be able to show up again?

reporting might be able to take it down but who knows if they just register it again on another name server.
mk4
legendary
Activity: 2870
Merit: 3873
Paldo.io 🤖
How did you come across that site? The L looks really ugly like that too 😅.

It's one of the "better", more tricky domains for phishing sites though. Sure it looks really weird when you intentionally look at it, but it's definitely a lot more deceiving than the typical sort of "blockchain.0029web.xyz" domain LOL.

Make sure to report this website bois: https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en
sr. member
Activity: 1932
Merit: 442
Eloncoin.org - Mars, here we come!
Well, here we go again, --it's an old trick that only careless people will be their victim.
If you noticed you can't drag down the page if you are looking for website details like company information or even the support button. It's clearly phishing site and I don't know if there will fall to them.

I visited that site and I can still able to access it, perhaps it is not yet down. I reported the phishing site too, indeed, thank you for the warning you have shared.
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
How did you come across that site? The L looks really ugly like that too 😅.
legendary
Activity: 2576
Merit: 1655
Another fake blockchain.com is on the wild. Just 9 day old site, please be careful.

Code:
login.xn--bockchain-0e5h.com
https://login.bュockchain.com/captcha



Quote
Domain Profile
Registrant   WhoisGuard Protected
Registrant Org   WhoisGuard, Inc.
Registrant Country   pa
Registrar   NAMECHEAP INC NameCheap, Inc.
IANA ID: 1068
URL: http://www.namecheap.com
Whois Server: whois.namecheap.com

(p)
Registrar Status   clientTransferProhibited
Dates   9 days old
Created on 2020-07-08
Expires on 2021-07-08
Updated on 0000-12-31

You can send reports here: https://support.namecheap.com/index.php?/Tickets/Submit

We need everyone's help to take this site down immediately.

Edit: Report submitted.

Quote

Thank you for contacting us. This is an automated response confirming the receipt of your ticket. Our team will get back to you as soon as possible. When replying, please make sure that the ticket ID is kept in the subject so that we can track your replies.

   Ticket ID: VIP-683-78889
   Subject: blockchain.com phishing website
   Department: Fraud / Phishing
   Type: Issue
   Status: Awaiting Staff Response
   Priority: High
Jump to: