MetaMask / eth-phishing-detect

Utility for detecting phishing domains targeting Web3 users
Other
1.1k stars 956 forks source link

[Legitimate Site Blocked] openseax.net #6043

Closed ghost closed 2 years ago

ghost commented 2 years ago

http://openseax.net/

trn1ty commented 2 years ago

This domain isn't registered. It's not legitimate and there's no reason to prematurely allowlist it as it is visually similar to opensea.io.

ghost commented 2 years ago

It is registered, live and it's not in anyway affiliated with opensea.io. Please review again and I hope it complies with your policy. Thanks

trn1ty commented 2 years ago

No, this website is probably a scam. There's no disambiguation from OpenSea except that it "[eliminates] OPENSEA's shortcomings" and there's an address to which people should send money with no discernible return. The link to a whitepaper ("/whitepaper.pdf") is broken and the copyright notice has a hyperlink to the "OpenSeaX DevTeam" that goes to the site itself again. Here's some raw WHOIS data:

Domain name: openseax.net
Registry Domain ID: 2658387459_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: http://www.namecheap.com
Updated Date: 0001-01-01T00:00:00.00Z
Creation Date: 2021-11-29T21:27:55.00Z
Registrar Registration Expiration Date: 2022-11-29T21:27:55.00Z
Registrar: NAMECHEAP INC
Registrar IANA ID: 1068
Registrar Abuse Contact Email: email@namecheap.com
Registrar Abuse Contact Phone: +1.9854014545
Reseller: NAMECHEAP INC
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: 
Registrant Name: Redacted for Privacy
Registrant Organization: Privacy service provided by Withheld for Privacy ehf
Registrant Street: Kalkofnsvegur 2 
Registrant City: Reykjavik
Registrant State/Province: Capital Region
Registrant Postal Code: 101
Registrant Country: IS
Registrant Phone: +354.4212434
Registrant Phone Ext: 
Registrant Fax: 
Registrant Fax Ext: 
Registrant Email: email@withheldforprivacy.com
Registry Admin ID: 
Admin Name: Redacted for Privacy
Admin Organization: Privacy service provided by Withheld for Privacy ehf
Admin Street: Kalkofnsvegur 2 
Admin City: Reykjavik
Admin State/Province: Capital Region
Admin Postal Code: 101
Admin Country: IS
Admin Phone: +354.4212434
Admin Phone Ext: 
Admin Fax: 
Admin Fax Ext: 
Admin Email: email@withheldforprivacy.com
Registry Tech ID: 
Tech Name: Redacted for Privacy
Tech Organization: Privacy service provided by Withheld for Privacy ehf
Tech Street: Kalkofnsvegur 2 
Tech City: Reykjavik
Tech State/Province: Capital Region
Tech Postal Code: 101
Tech Country: IS
Tech Phone: +354.4212434
Tech Phone Ext: 
Tech Fax: 
Tech Fax Ext: 
Tech Email: email@withheldforprivacy.com
Name Server: dns1.namecheaphosting.com
Name Server: dns2.namecheaphosting.com
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2021-11-30T04:11:50.90Z <<<
For more information on Whois status codes, please visit https://icann.org/epp

This site was bought and registered after you submitted it to the allowlist. I almost bought it as an example phishing domain.

it's not in anyway affiliated with opensea.io

That's the problem. It appears to be, and even if it is completely legitimate I smell a trademark case as this is a competitor to a site with pretty much the same name.

Also, please stop filing duplicate issues.