Bitcoin Forum

Bitcoin => Mining software (miners) => Topic started by: CD-RW on July 20, 2011, 08:12:52 AM



Title: Bitcoin mining with a virus or botnet on bitclockers
Post by: CD-RW on July 20, 2011, 08:12:52 AM
http://www.threatexpert.com/report.aspx?md5=69d0699d6b660db571a63b4b3eac4b7f

This is a virus/botnet. It uses IRC to get and send commands. Sure. But check out the 'bitcoin' command:
Code:
PRIVMSG #insomnia :[BITCOIN]: Downloading ufasoft bitcoin miner...
PRIVMSG #insomnia :[BITCOIN]: Mining started [user='nigger' url='http://pool.bitclockers.com:8332' proc='dnmsal' id='1288']

So it downloads 'http://ufasoft.com/files/open/bitcoin-miner.exe' and uses it to get bitcoins for the botherder.


I hope any bitclockers admins read this and will take appropriate steps.


Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: xcooling on July 20, 2011, 09:29:32 AM
Ouch, wouldn't mind looking at the source code for it though.

Could be a nice base to make a remote self updating miner for my multiple machines


Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: deslok on July 20, 2011, 11:55:58 PM
BTCguild had "thousands" of cpu miners connect to it after they were removed from the pool(that many cpu's makes a mess of things) they were ddosed for several days i wonder if this is an updated version of that botnet.
on another note how did you get that infromation do you have a computer that was infected with it a sample may be useful in preventing botnets from being a thorn in the side of bitcion in general.


Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: bal3wolf on July 21, 2011, 01:08:24 AM
If you have the bot you need to either give it to someone or do it yourself and find the dns they use and report it then that will pretty much kill them with no way to control them any longer.


Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: V2-V3 on July 21, 2011, 01:45:32 AM
CD-RW ,Thank you for the heads up

This was taken care of by Backburn over at BitClockers not too long ago.



Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: Boing7898 on July 22, 2011, 06:11:48 PM
I PMed it to Backburner not long time ago but it seems he ignored my pm..


Title: Re: Bitcoin mining with a virus or botnet on bitclockers
Post by: CD-RW on July 30, 2011, 05:07:10 PM
on another note how did you get that infromation do you have a computer that was infected with it a sample may be useful in preventing botnets from being a thorn in the side of bitcion in general.

I searched Threatexpert for 'BitCoin' somewhere in the virus, and got a few hits (http://www.threatexpert.com/reports.aspx?find=bitcoin&x=0&y=0)!