Bitcoin Forum

Economy => Scam Accusations => Topic started by: prasha2 on January 23, 2017, 03:43:34 AM



Title: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: prasha2 on January 23, 2017, 03:43:34 AM
Hi Guys

User "Bitcoin Day Trade" made a post advertising a bitcoin trading book for FREE. The first comment caught my attention which mentioned the doc was password protected. I had heard of such a way of installing trojan (I think the doc asks you to enable micros or something), so I ran the doc through virus-total. And the result found out that there were indeed trojans in there - https://virustotal.com/en/file/56302e88bc7097c68940cbbfc2f8d8ff902a1c9f17f2c2820f1f6600c9acbfd7/analysis/1485141666/.

I have put a warning comment on the post. Please do your bit and paint his trust RED.

Also, is there a way to blacklist the website from which the doc is downloaded? - http://bitcoin-help.online

Profile - https://bitcointalk.org/index.php?action=profile;u=946159

POST - https://bitcointalk.org/index.php?topic=1761545.new#new


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: R00TC0IN on January 23, 2017, 03:48:41 AM
People should also look out for PDF ebooks there is a lot of fishy ones circulating the forum.

On another note there is a skype virus that users ask you to talk to them via skype then send you a image that has been edited and contains a virus hidden by Steganography

https://en.wikipedia.org/wiki/Steganography


Report the URL to places like virus total. it will get detected and added to block lists by AV's

https://www.virustotal.com/en/url/17b138f76b98a4708b84251fee6731ae4e35849a30b3b9f7dc432f8c09232baf/analysis/1485143465/

Just click the red devil to add a warning to the link its starting to be detected


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: U2 on January 23, 2017, 03:52:50 AM
Good thing you jumped on it. The sketchy asshole thinks he's going to make a decent amount from his fake generosity. What scum.


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: Lauda on January 23, 2017, 07:53:56 AM
He's been nuked. In the case of viruses or other types of malware, you should just report it and attach the virustotal scan (or post the scan in relevant thread if it's not self moderated).


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: prasha2 on January 23, 2017, 02:04:29 PM
I see that he has deleted all his posts. But still, let's at least leave him a neg feedback.


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: Joel_Jantsen on January 23, 2017, 07:37:12 PM
I see that he has deleted all his posts. But still, let's at least leave him a neg feedback.
No,he has been banned if you read the post above..No point in giving negative to a account which technically doesn't exist.


Title: Re: User "Bitcoin Day Trade" scamming by virus laden word doc
Post by: rizzlarolla on February 01, 2017, 05:17:31 PM
prasha2
Just saying thanks and letting you know you helped, i quote this from bitcoin.com, where Bitcoin Day Trade also posted,

-------------

rizzlarolla wrote: (jan 23)
quote from prasha2, (bct)

"User "Bitcoin Day Trade" made a post advertising a bitcoin trading book for FREE. The first comment caught my attention which mentioned the doc was password protected. I had heard of such a way of installing trojan (I think the doc asks you to enable micros or something), so I ran the doc through virus-total. And the result found out that there were indeed trojans in there - https://virustotal.com/en/file/56302e88 ... 485141666/.

I have put a warning comment on the post. Please do your bit and paint his trust RED.

Also, is there a way to blacklist the website from which the doc is downloaded? - http://bitcoin-help.online"

-----------

bientang replyed: (today, feb 1)
waw it is dangerous. thank for your warning because i wan to download and i read your post
thank you friend

-----------

(this thread on bitcoin.com is finally in the trashcan, moved today after bientang replyed)