As I have said in my previous post here,
Malicious Red Alert apps, now scammers are using the war between the Israel and Hamas to create fake websites asking for humanitarian aid in Gaza. And it was reported that there are fake sites already mimicking the real one like this fake Twitter account:
https://twitter.com/gazareliefaid
If you look closely at this account, at the right side is the website that they are promoting. But it's a fake site:
https://aidgaza.xyz/
Archived: https://web.archive.org/web/20231021235454/https://aidgaza.xyz/As we look closely at the domain information:
Raw Whois Data
Domain Name: AIDGAZA.XYZ
Registry Domain ID: D403470948-CNIC
Registrar WHOIS Server: whois.hostinger.com
Registrar URL: https://www.hostinger.com/
Updated Date: 2023-10-20T23:49:05.0Z
Creation Date: 2023-10-15T23:45:26.0Z
Registry Expiry Date: 2024-10-15T23:59:59.0Z
Registrar: HOSTINGER operations, UAB
Registrar IANA ID: 1636
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Organization: Privacy Protect, LLC (PrivacyProtect.org)
Registrant State/Province: MA
Registrant Country: US
Registrant Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Admin Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Tech Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Name Server: KOBE.NS.CLOUDFLARE.COM
Name Server: GRACE.NS.CLOUDFLARE.COM
DNSSEC: unsigned
Billing Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Registrar Abuse Contact Email:
[email protected]Registrar Abuse Contact Phone: +370.68424669
It was just recently created, but according to their fake twitter account, they have existed since 2011.
And if you clicked the Donate Button of the fake website, it will display 3 crypto addresses:
Bitcoin:
16gbXTmvxtrzieoh2vX3io7FhXK4WJryX2
Ethereum:
0x5E8b0df880A9f9F6e4D4090a84b3c1A02fF311b4
USDT (TRC 20):
TK4A9dfwqbJhzz4NeGJZBo9nVMJztxnT27
So far, those addresses just have minimal value to none. But who knows, maybe there are gullible individuals who are going to support and then deposit some of their hard earn crypto and think that they are doing a good value. So this is a warning.
I already sent an email to the domain registrar already to take action on this fake site:
Maybe you can also help in pressuring them by sending an email to:
[email protected]update:
[email protected]
And if everyone is curious as to what is the real website?
This is the legit one:
https://islamic-relief.org/news/islamic-relief-calls-for-support-for-humanitarian-aid-in-gaza/Source.