Updated: Mar 30, 2020
I've started collecting some website and example of spam messages and website as during this period.
this page will get updated over time so keep it monitored. if you know more put them in the comments and I'll integrate the missing one.
To report a new one, add them in the comment section below and on this website: https://www.phishtank.com/
Safe map of coronavirus: https://gisanddata.maps.arcgis.com/apps/opsdashboard/index.html#/bda7594740fd40299423467b48e9ecf6
Following some domains with the source, they were mentioned (as not every website has been verified take it with a pinch of salt. The sites at the top have been verified while the ones at the bottom have been just announced.
List of covid 19 malicious URLs (phishing/spam)
New from abuse.ch
GuLoader payload URL: https://urlhaus.abuse.ch/url/332150/
Lindsay Kaye, director of operation outcomes at Recorded Future, specifically called out the following domains as potentially dangerous:
Forbes - Bernardo Quintero
Address released from Polish Police:
For the full list go here
As a rule of thumb, those are some guidance:
Beware of online requests for personal information. A coronavirus-themed email that seeks personal information like your Social Security number or login information is a phishing scam. Legitimate government agencies won’t ask for that information. Never respond to the email with your personal data.
Check the email address or link. You can inspect a link by hovering your mouse button over the URL to see where it leads. Sometimes, it’s obvious the web address is not legitimate. But keep in mind phishers can create links that closely resemble legitimate addresses. Delete the email.
Watch for spelling and grammatical mistakes. If an email includes spelling, punctuation, and grammar errors, it’s likely a sign you’ve received a phishing email. Delete it.
Look for generic greetings. Phishing emails are unlikely to use your name. Greetings like “Dear sir or madam” signal an email is not legitimate.
Avoid emails that insist you act now. Phishing emails often try to create a sense of urgency or demand immediate action. The goal is to get you to click on a link and provide personal information — right now. Instead, delete the message.