# As of Dec 2018 criminals carry out phishing attacks against vulnerable versions of Electrum asking them to download malware versions of Electrum. # For abuse desks around the world it is hard to determine whether or not a certain domain name or IP address participates in this scam. # Perpetrators have also used faked messages with manipulated screenshots to claim legit server domains would take part in sending phishing links, when this is not the case. # Please also see https://electrum.org/electrum-server-blacklist.json for an authoritative list of blacklisted server domain names # For more information about the issue please see https://blog.malwarebytes.com/cybercrime/2019/04/electrum-bitcoin-wallets-under-siege/ # # This is a list of electrum servers scanned for whether they distribute malware links or not # If you work at an abuse desk and have questions or would like to reproduce these results yourself please get in touch with Electrum Technologies at abuse@electrum.org # # Fri 1 Mar 03:44:01 CET 2024 # # Valid servers which are working as expected (no scam): # There are still some false-positives of scam servers detected as legitimate: # For blackpole.online the scammers are currently trying to avoid detection, by taking services offline - the domain is phishing! # } # # #IP-Addresses of servers in DNS-records identified to be phishing (with number of occurences in first column): # # # #IP-Addresses of servers in DNS-records which have been shut down (Port 50002 closed) but are still listed in DNS: # # #Scam servers which are sending a phishing URL (under certain conditions): #The list is reliable with no false-positives: #Abuse desks: Please block these domains # # # #Suspicous servers as part of a supposed school project with no current evidence of phishing #