Another set of sites, this time for Capital One:
https://sites.google.com/abcrypt.com/capitalone-login/home links to
https://rebrand.ly/960141 which redirects to
https://captitone.com/logi/
error page https://captitone.com/err/
tawk.to chat widget https://tawk.to/chat/6661e2b09a809f19fb3a3ace/1hvn5r0sa .
Jack is working late on a Friday night, keep him company and have some chats with him!
Another new one:
https://sites.google.com/abcrypt.com/cryptocomlogin/home
links to:
https://rebrand.ly/45d087
which redirects to:
crypologs.com
Registrant Name: Nitin Kumar
Registrant Organization: Nitin Kumar
Registrant Street: J-234 Saket
Registrant City: New Delhi
Registrant State/Province: Uttar Pradesh
Registrant Postal Code: 110053
Registrant Country: IN
Registrant Phone: +91.9384758493
error page:
We’re sorry … Note: Your Crypto Account is Blocked. Our support representatives have come across certain suspicious activities on your account. Chat Now There was a technical issue with your Account. Please try again later or call our customer...
Est. reading time: 1 minute
tawk.to web chat:
https://tawk.to/chat/666e09569a809f19fb3e3f10/1i0et8um9
Another one I found today:
https://sites.google.com/metamaslogi.com/metamask-login/home
links to https://rebrand.ly/ebd380
which redirects to
https://metamsik.com/logoc/
Error page:
Important Message ! Due to account maintenance or failed verification, you’ll no longer be able to access your account. To lift this restriction, get in touch with the expert. Error Code: ERRX9:74HY Chat Now
Est. reading time: 1 minute
On the same IP 162.241.85.150 as many other scams recorded in this thread.
A few more I found today:
Import Using Mnemonic Phrase You can restore your crypto wallet using your mnemonic phrase. This enables you to manage, send, purchase, and swap your cryptocurrency seamlessly. Your mnemonic phrase remains encrypted in browser’s local storage and is...
Est. reading time: 1 minute
https://phantomapk.com/enter/
ElmerFudde2020:
with redirector Log In
I got rebrand.ly to block that link (they are quick to address complaints via email at support at rebrandly dot com, especially considering it’s a U.S. holiday weekend) and it seems like the scammers already made another one! https://rebrand.ly/fd503b .
Here’s another PayPal phishing site that popped up today:
PayPal Login : My PayPal Account Login | Official Website now points to
https://rebrand.ly/641fbe , which redirects to
https://paypaloficial.com/log/ , which we know is official because it has a misspelled “oficial” in the domain name.
Someone forgot to obfuscate the WHOIS info for this domain:
Domain Name: PAYPALOFICIAL.COM
Registry Domain ID: 2919920815_DOMAIN_COM-VRSN
Registrar WHOIS Server: Whois.bigrock.com
Registrar URL: www.bigrock.com
Updated Date: 2024-09-25T16:32:20Z
Creation Date: 2024-09-25T16:27:50Z
Registrar Registration Expiration Date: 2025-09-25T16:27:50Z
Registrar: BigRock Solutions Ltd.
Registrar IANA ID: 1495
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: Not Available From Registry
Registrant Name: Nitin
Registrant Organization: Nitin
Registrant Street: J-232 DES
Registrant City: Delhi
Registrant State/Province: Delhi
Registrant Postal Code: 110023
Registrant Country: IN
Registrant Phone: +91.2334323454
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: [email protected]
Error page at https://paypaloficial.com/err/ ,
with tawk.to chat link https://tawk.to/chat/66ca29a350c10f7a00a00ebd/1i62r5a2m .
A new PayPal website with several “error” pages:
https://paypll.info/?s=e
https://paypll.info/errs/ has a U.S. phone number, which I am unable to verify.
https://paypll.info/errr/ links to the tawk.to account https://tawk.to/chat/67092fe82480f5b4f58c07de/1i9tu69dj ;
https://paypll.info/err/ links to a different chat account, https://tawk.to/chat/670803dbaf33b684b75058bc/1i9rku4mm , where Jack is actively responding.
And another new PayPal site:
https://paylogss.com/?s=e
From the RDAP (WHOIS) info:
Nitin Kumar
New Delhi
Uttar Pradesh
110053
IN
[email protected]
+91.9384758493
ElmerFudde2020:
Found at Error! .
Domain registrant: Jack Morris
New Jersey
08854
US
[email protected]
+1.2512924943