Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update add-domain #694

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ninjacatcher
Copy link
Contributor

@ninjacatcher ninjacatcher commented Jan 18, 2025

Phishing Domain/URL/IP(s):

electrun.net
atomik.cc
zaper.fi
rabby.la
majiceden.app
ledjer.app
tonkeeper.bz
tcnkecper.com
tonkeęper.com
tonkeéper.com
tangen.app
exoduc.cc
suiwallet.cc
suiwallet.ws
suiwcllct.com
paychex.la
opensea.ltd
open-sea-v2.us
opensea.nft-web3.com
ledger.domains
dudx.app
defillama.ltd
app.web-changenow.com
debanc.org
coinomi.cx
changenow-io.org
changenow.vip
info-changenow.com
www.changenow.dev
chcngencw.com
trezor.ltd
coinomi.fi
coinomi.bz

Impersonated domain

electrum.org
exodus.com
ledger.com
trezor.io
suiwallet.com
tonkeeper.com
some other cryptowallets/companies

Describe the issue

The domains on this list are used to spread phishing and malware. Most domains show a fake captcha from Cloudflare, which, when clicked, may take you to a third-party phishing company's malicious page. The redirect can also work automatically if the referrer was a domain of a search network like google.com, bing.com, duckduckgo.com, etc.

All domains use SEO techniques to get higher in the index of search networks. Absolutely all domains are registered with nicenic.net Hong Kong registrar, which is “bulletproof” because of its inconvenient abuse-reporting form and delaying investigation time or completely refusing to investigate unless a report to ICANN is initiated.

Related external source

https://www.virustotal.com/gui/domain/electrun.net
https://www.virustotal.com/gui/domain/atomik.cc
https://www.virustotal.com/gui/domain/zaper.fi
https://www.virustotal.com/gui/domain/rabby.la
https://www.virustotal.com/gui/domain/majiceden.app
https://www.virustotal.com/gui/domain/ledjer.app
https://www.virustotal.com/gui/domain/tonkeeper.bz
https://www.virustotal.com/gui/domain/tcnkecper.com
https://www.virustotal.com/gui/domain/tonkeęper.com
https://www.virustotal.com/gui/domain/tonkeéper.com
https://www.virustotal.com/gui/domain/tangen.app
https://www.virustotal.com/gui/domain/exoduc.cc
https://www.virustotal.com/gui/domain/suiwallet.cc
https://www.virustotal.com/gui/domain/suiwallet.ws
https://www.virustotal.com/gui/domain/suiwcllct.com
https://www.virustotal.com/gui/domain/paychex.la
https://www.virustotal.com/gui/domain/opensea.ltd
https://www.virustotal.com/gui/domain/open-sea-v2.us
https://www.virustotal.com/gui/domain/opensea.nft-web3.com
https://www.virustotal.com/gui/domain/ledger.domains
https://www.virustotal.com/gui/domain/dudx.app
https://www.virustotal.com/gui/domain/defillama.ltd
https://www.virustotal.com/gui/domain/app.web-changenow.com
https://www.virustotal.com/gui/domain/debanc.org
https://www.virustotal.com/gui/domain/coinomi.cx
https://www.virustotal.com/gui/domain/changenow-io.org
https://www.virustotal.com/gui/domain/changenow.vip
https://www.virustotal.com/gui/domain/info-changenow.com
https://www.virustotal.com/gui/domain/www.changenow.dev
https://www.virustotal.com/gui/domain/chcngencw.com
https://www.virustotal.com/gui/domain/trezor.ltd
https://www.virustotal.com/gui/domain/coinomi.fi
https://www.virustotal.com/gui/domain/coinomi.bz

Screenshot

Click to expand ![chrome_l8OE630Jwy](https://github.com/user-attachments/assets/69b69c04-6256-493d-952b-40455dd2e42f)

chrome_ngfck2Qi1O

chrome_Qx35oWtux9

chrome_U4vCe5gXbe

@ninjacatcher
Copy link
Contributor Author

tonkeéper.com - xn--tonkeper-f1a.com
tonkeęper.com - xn--tonkeper-reb.com
punycode domain names

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant