To access www.iMoose.com , please pay attention to below security rules:

One more rules shall be noted:

Don’t enable API if it was not required.

User may be attacked by phishing website via search engine referrals,browser plugins/extensions,third party or invalid apps。

It is recommended to install Netcraft extension to protect you from phishing attacks:https://toolbar.netcraft.com/

  • Risky search engine referalls, navigate user to phishing website

  • Risky brower plugins/extensions, navigate user to phishing website

  • Risky email with phishing link

  • Some users may install third party application to manage their investment portfolios, or install invalid APP from app store.

Phishing websites may induce user to expose their confidential information such as password, 2FA code. Therefore, Hackers can steal users’ coins through API withdrawls, abnormal buy/sell orders.

 

Below logs illustrate a phishing attack through searching engine referrals:

Server logs listed the process of coins stolen:

  • Login:     188.166.62.200    2018-02-05 09:54
  • Modify API :  188.166.62.200    2018-02-05 10:00
  • Confirm API withdraw : 188.166.62.200  2018-02-05 10:01
  • Login:     86.25.38.113    2018-02-05 10:02  
  • Complete API withdraw :   5.45.65.227  2018-02-05 10:02
  • Delete API :      86.25.38.113   2018-02-05 10:03

One victim attacked by phishing website described details as blow:

Appendix suspicious phishing website list