{"id":99,"date":"2023-02-13T00:17:27","date_gmt":"2023-02-13T05:17:27","guid":{"rendered":"https:\/\/freshphish.info\/?p=99"},"modified":"2023-02-13T00:17:28","modified_gmt":"2023-02-13T05:17:28","slug":"bitcoin-phish","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=99","title":{"rendered":"Bitcoin Phish"},"content":{"rendered":"\n<p>Here&#8217;s a type of phish I haven&#8217;t seen before. It intends to make the victim believe they opened some sort of a Bitcoin mining account a year ago that has since accumulated several thousand dollars, and uses that as bait to get information from the victim.<\/p>\n\n\n\n<p>Here&#8217;s the email:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"274\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam00-1024x274.png\" alt=\"\" class=\"wp-image-100\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam00-1024x274.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam00-300x80.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam00-768x206.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam00.png 1106w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The link as shown is rewritten by Proofpoint to go to their URL Defense URL so they can keep victims from getting to the phishing site once Proofpoint discovers the fraudulent email. Clicking on an unprotected link gets you to this page:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"799\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam02-1024x799.png\" alt=\"\" class=\"wp-image-103\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam02-1024x799.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam02-300x234.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam02-768x599.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam02.png 1063w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">The page shows what looks to be a large number of small transactions that have built up to the range of $30,000.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"832\" height=\"797\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam03.png\" alt=\"\" class=\"wp-image-104\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam03.png 832w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam03-300x287.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam03-768x736.png 768w\" sizes=\"auto, (max-width: 832px) 100vw, 832px\" \/><figcaption class=\"wp-element-caption\">It also has a scrolling box of text, appearing to be other users chatting about how surprised they are about the money coming to them.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"897\" height=\"668\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam04.png\" alt=\"\" class=\"wp-image-105\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam04.png 897w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam04-300x223.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam04-768x572.png 768w\" sizes=\"auto, (max-width: 897px) 100vw, 897px\" \/><figcaption class=\"wp-element-caption\">The victim can type a message in but in the time I watched, I never got a response.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"794\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam05-1024x794.png\" alt=\"\" class=\"wp-image-106\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam05-1024x794.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam05-300x233.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam05-768x595.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam05.png 1058w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"588\" height=\"672\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam06.png\" alt=\"\" class=\"wp-image-107\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam06.png 588w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam06-263x300.png 263w\" sizes=\"auto, (max-width: 588px) 100vw, 588px\" \/><figcaption class=\"wp-element-caption\">Clicking on the link for support brings up a chat window.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"633\" height=\"678\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam07.png\" alt=\"\" class=\"wp-image-108\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam07.png 633w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam07-280x300.png 280w\" sizes=\"auto, (max-width: 633px) 100vw, 633px\" \/><figcaption class=\"wp-element-caption\">The window is grayed out while support searches for your account.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"650\" height=\"679\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam09.png\" alt=\"\" class=\"wp-image-110\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam09.png 650w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam09-287x300.png 287w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><figcaption class=\"wp-element-caption\">They eventually find your account and you&#8217;re provided a button to fill out the form to receive your funds.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"664\" height=\"823\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam10-1.png\" alt=\"\" class=\"wp-image-111\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam10-1.png 664w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/02\/bitcoinscam10-1-242x300.png 242w\" sizes=\"auto, (max-width: 664px) 100vw, 664px\" \/><figcaption class=\"wp-element-caption\">Clicking the button brings you to a page asking for your credit card or Bitcoin wallet number.<\/figcaption><\/figure>\n\n\n\n<p>I didn&#8217;t go any further than this but I would imagine providing a credit card will result in your card being used fraudulently and likely sold on the dark web. Providing your Bitcoin wallet will likely lead to a prompt for your passphrase.<\/p>\n\n\n\n<p>I would hope that anyone that has a Bitcoin wallet would know enough about this to not fall for this trick but someone that doesn&#8217;t have one might not know any better and provide a credit card to receive the funds.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here&#8217;s a type of phish I haven&#8217;t seen before. It intends to make the victim believe they opened some sort<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=99\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Bitcoin Phish<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[36],"class_list":["post-99","post","type-post","status-publish","format-standard","hentry","category-phish","tag-bitcoin"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/99","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=99"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/99\/revisions"}],"predecessor-version":[{"id":112,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/99\/revisions\/112"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=99"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=99"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=99"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}