Beware of Clicking Links in Phishing Comments Pointing to STEEMIL.COM

in #scam6 years ago (edited)

Today, two users reported on the chat that their accounts were hacked. After a quick check, the hijacker(s) were posting comments with suspicious links under the guise of our dear friend @grumpycat.

https://steemit.com/@mrs-yammy/comments
https://steemit.com/@simplymike/comments

These accounts are currently blacklisted, until they are recovered by their original owners.

The links in those comments are all fake and point to STEEMIL.COM instead of STEEMIT.COM.

Here's an example:
https://steemd.com/tx/04bfbf2da9fda6a18832cd90758fdf465b6201a1
fake1.png

Notice the use of steemil.com in all the code, instead of steemit.com. The website seems to be running Condenser, the Steemit website app. DO NOT LOGIN TO IT.

Obviously it's a phishing attempt to lure more users into signing in to a malicious website located in Malaysia.

IP: 111.90.149.128
Decimal: 1868207488
Hostname: felidae28.ipchina163.com
ASN: 45839
ISP: Shinjiru Technology Sdn Bhd
Organization: Shinjiru Technology Sdn Bhd
Services: None detected
Type: Broadband
Assignment: Static IP
Continent: Asia
Country: Malaysia my flag
State/Region: Selangor
City: Shah Alam
Latitude: 3.0544 (3° 3′ 15.84″ N)
Longitude: 101.5169 (101° 31′ 0.84″ E)
Postal Code: 40200

I ran a whois on the domain, and it's indeed with a Malaysian registrar http://shinjiru.com.my, registered on 2018-03-04T10:20:04Z

Domain Name: STEEMIL.COM
Registry Domain ID: 2235087516_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.ilovewww.com
Registrar URL: http://shinjiru.com.my
Updated Date: 2018-03-04T10:20:05Z
Creation Date: 2018-03-04T10:20:04Z
Registry Expiry Date: 2019-03-04T10:20:04Z
Registrar: Shinjiru Technology Sdn Bhd
Registrar IANA ID: 1741
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Name Server: NS1.IPCHINA163.COM
Name Server: NS2.IPCHINA163.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

I also ran a database query for the string https://steemil.com since the domain's creation date
SELECT author FROM Comments WHERE body LIKE '%https://steemil.com%' AND created BETWEEN '2018/03/04' AND '2018/03/07'

It turns out, the impostors aren't only faking @grumpycat's comments, but others as well, such as:

https://steemd.com/tx/02e66607125ed8cfeccdf28dbcdf9ddb7294bf9a
fake2.png

https://steemd.com/tx/f1eca9a530b4e5aeeacb15cd137b98cb8460cdfe
fake3.png

There are over 1100 phishing comments so far, with multiple SQL hits, by the following 15 hacked accounts:
@aideedavies @beautyloving @boontjie @enjoyinglife @kilbride @lalo78 @leader-sapa @mcgrafite @mrs-yammy @omikunlejackson @qustodian @simplymike @thedavidadesina @timmy2426 @william21

Some of them have already recovered, some haven't yet.

ALWAYS be careful when you click ANY links and ALWAYS look at the URL you're visiting in the browser address bar.


Follow

Available & Reliable. I am your Witness. I want to represent You.

🗳 If you like what I do, consider voting for me 🗳

Vote

If you never voted before, I wrote a detailed guide about Voting for Witnesses.

Go to https://steemit.com/~witnesses. My name is listed in the Top 50. Click once.

Alternatively you can vote via SteemConnect

https://v2.steemconnect.com/sign/account-witness-vote?witness=drakos&approve=1

Sort:  
Loading...