Hi, sorry to hear about your friends situation. I believe the domain is with an l
instead of an i
(at least the one I found that is up is with an l
). I'm writing an article about it, but it's very similar to a HitBTC phishkit I've dissected (https://medium.com/mycrypto/dissecting-a-hitbtc-phishing-site-8e631a6c29a3) - are you able to get your friend to to email me the audit log including suspicious IPs - harry[@]mycrypto[doot]com. I cannot help with any recovery, but it will help with building a case with LE.
You are viewing a single comment's thread from: