Monthly report attached - September 2023


Thanks for your continuous support!

Bad sites detected and shared with vendors for removal: 31



UrlScan IoCs
Balancer


Balancer DNS A hijack via EuroDNS staff social eng phish

My role to controlling the damage was limited to:



Search Balancer (1579 hits in 30 files of 30 searched)

Search "(balancеr|balqncer|balancer|balahcer|bqlancer|baIancer|balencer|baiencer|balancer-fi|balancer-fl|baiancer-fi|balencer-fi|balancer\.fi|balancer-fl|ba[l1][ae]ncer|b[ao]l[ae]ncer|b[aq]lancer|fi-balancer|app-balancer|bal-drop|airdropbal|balancerairdrop|[a-zA-Z]*balancer[a-zA-Z]*|[a-zA-Z]*bqlancer-[a-zA-Z]|[a-zA-Z]*balancer[a-zA-Z]*|a-zA-Z]*balancerfi[a-zA-Z]*|a-zA-Z]*bal-[a-zA-Z]*|[a-zA-Z]*baiancer[a-zA-Z]*)" (1579 hits in 30 files of 30 searched)



Sneak Peek in my abuse inbox


Metamask, airdrop, walletconnect, etc:


Search "airdrop" (450 hits in 30 files of 30 searched)
Search "binance" (2306 hits in 30 files of 30 searched)
Search "coinbase" (1929 hits in 30 files of 30 searched)
Search "elonmusk" (351 hits in 30 files of 30 searched)
Search "metamask" (621 hits in 30 files of 30 searched)
Search "pancakeswap" (272 hits in 30 files of 30 searched)
Search "sushiswap" (62 hits in 25 files of 30 searched)
Search "trustwallet" (30 hits in 14 files of 30 searched)
Search "walletconnect" (7 hits in 6 files of 30 searched)



Total potential bad hits for the month ~42K

Search "(usdc|claim|coinbase|colnbase|c0inbase|c0lnbase|cornbase|coirbase|balancer|balahcer|bqlancer|baIancer|[a-zA-Z]*1inch[a-zA-Z]*|[a-zA-Z]*1inch-[a-zA-Z]|[a-zA-Z]*oneinch[a-zA-Z]*|a-zA-Z]*1-inch[a-zA-Z]*|a-zA-Z]*1-inch[a-zA-Z]*|[a-zA-Z]*1inch[a-zA-Z]*|[a-zA-Z]*pancakesw[a-zA-Z]*|[a-zA-Z]*pancakesv[a-zA-Z]*|[a-zA-Z]*pancokesv[a-zA-Z]*|[a-zA-Z]*pancokesw[a-zA-Z]*|[a-zA-Z]*pancakosw[a-zA-Z]*|[a-zA-Z]*pancakkesw[a-zA-Z]*|[a-zA-Z]*pancake5[a-zA-Z]*|[a-zA-Z]*uniswap[a-zA-Z]*|[a-zA-Z]*uniswap-[a-zA-Z]|[a-zA-Z]*unisvap[a-zA-Z]*|a-zA-Z]*unisvap[a-zA-Z]*|a-zA-Z]*uni-[a-zA-Z]*|[a-zA-Z]*unisvv[a-zA-Z]*|unlswap"|[a-zA-Z]*uniswap[a-zA-Z]*|[a-zA-Z]*uniswap-[a-zA-Z]|[a-zA-Z]*unisvap[a-zA-Z]*|a-zA-Z]*unisvap[a-zA-Z]*|a-zA-Z]*uni-[a-zA-Z]*|[a-zA-Z]*pancakesw[a-zA-Z]*|[a-zA-Z]*pancakesv[a-zA-Z]*|[a-zA-Z]*pancokesv[a-zA-Z]*|[a-zA-Z]*pancokesw[a-zA-Z]*|[a-zA-Z]*pancakosw[a-zA-Z]*|[a-zA-Z]*pancakkesw[a-zA-Z]*|[a-zA-Z]*uniswap[a-zA-Z]*|[a-zA-Z]*uniswap-[a-zA-Z]|[a-zA-Z]*unisvap[a-zA-Z]*|dapp|wallets|wallect|synchr|rectify|unlock|walet|1inch|airdrop|ethereum|walet|wallet|coinbase|uniswap|pancakeswap|liquidity|vvallet|metamask|metamaks|metemask|metamaks|paraswap|exchange|liquidity|kraken|bitso|dapp|sushiswap|sushlswap|sushisvv|opensea|polygon|walletconnect|waletconect|waiietconnect)" (40963 hits in 29 files of 30 searched)



Multiple offenders exposed and banned in Discord

Responsible moderator: dubstard after: 2023-08-01  before: 2023-08-31 in: 👮︲moderation  = 76

As myself and Cosme, Danko, Gerg, Gleb and the rest of the mods are in somewhat different timezones (I am in EEST), we sort of "cover" for each other, while one is asleep, the other continues to monitor and swing the ban hammer, alongside with the bots, that autoban many offenders!
Also the new bot is doing a lot of automated cleaning up now!


Warnings issued Discord


Various fake Balancer copycats

 balancer-auth.pages.dev
 balancer.yaqeenwelfare.org
 www-balancer.com


balancer.gift
defi-balancer.com
twitter.com/balancer_dao


baiancer-fi.com
balancer-dex.com
balancerfi.site
balancerfinancial.com

balancer-dao.com
balancer-finance.com
balancer-stake.com

Fake airdrop scam warning
claim-bal.com




Twitter warning




balancer.ug


crypto-balancer.world
balancer-io.com



solariss.site



appbalancer.pages.dev
fi-balancer.pages.dev
balancerfi.pages.dev
balancer-app.pages.dev
balancer.connect-defi.com
balancerdex.com



balacer-v3.org
balencer.org
app-balance.finance
balacer-v2.com
v2-balancer.org
balancer.one
balancer.app



Key for DeBank

Still plenty of Computing Units available - 972K





Fake apps Google play store taken down - just 1 this month

Mobile trojan that could steal your assets as well if a malicious actors takes control over a Mobile device.

17 GH pull requests (PF, dot and metamask anti-phish repos) in September 2023

ℹNote that each PR blocks many scam URLs, so the total number of blocked sites is significantly larger than the PRs.




https://github.com/dubstard

Visibility 
Organization 
Sort 
MetaMask/eth-phishing-detect Remove FPs 
 blocklist removal
#13605 by dubstard was merged last week• Approved
MetaMask/eth-phishing-detect Block 44 scams 
 blocklist addition
#13589 by dubstard was merged 2 weeks ago• Approved
MetaMask/eth-phishing-detect Block 36 scams 
 blocklist addition
#13581 by dubstard was merged 2 weeks ago• Approved
MetaMask/eth-phishing-detect Block 36 scams 
 blocklist addition
#13568 by dubstard was merged 2 weeks ago• Approved
MetaMask/eth-phishing-detect Block 62 scams 
 blocklist addition
#13545 by dubstard was merged 2 weeks ago• Approved
MetaMask/eth-phishing-detect Block 70 scams 
 blocklist addition
#13534 by dubstard was merged 3 weeks ago• Approved
MetaMask/eth-phishing-detect Block 27 scams 
 blocklist addition
#13504 by dubstard was merged 3 weeks ago• Approved
MetaMask/eth-phishing-detect Block 72 scams 
 blocklist addition
#13487 by dubstard was merged 3 weeks ago• Approved
polkadot-js/phishing block event-acala.network 
#3875 by dubstard was merged 3 weeks ago• Approved

Took some time off this month



As scammers tend to be very active during weekends, I also try to be.