Bitcoin Forum

Economy => Service Discussion => Topic started by: LostDutchman on March 18, 2014, 07:42:46 AM



Title: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LostDutchman on March 18, 2014, 07:42:46 AM
http://www.theregister.co.uk/2014/03/17/mtgox_blog_hackers_malware_bitcoin_stealers/

"Leaked database' offering details of Bitcoin heists contained Trojan"

"A 700MB file that hackers claimed contains valuable database information on bankrupted MtGox is actually hiding Bitcoin wallet file-stealing malware, researchers have warned.

Kaspersky Lab’s Sergey Lozhkin claimed in a blog post last Friday that the entire data leak story, which emerged after MtGox CEO Mark Karpeles had his blog hacked, was invented to lure users into unwittingly downloading the malware.

Although the 716MB file features trades.zip, the file actually contains nothing but publically available data on MtGox trades, he said.

The real purpose of the file is Trojan malware designed to “search and steal” Bitcoin wallet files from the victim.

He continued:

    We detect the Windows Trojan (MD5:c4e99fdcd40bee6eb6ce85167969348d), a 4.3MB PE32 executable, as Trojan.Win32.CoinStealer.i and OSX variant as Trojan.OSX.Coinstealer.a. Both have been created with the Livecode programming language – an open-source and cross-platform application development language. When the victim executes the application, it looks like the back-office software for accessing the databases of Mt. Gox’s owning company, Tibanne Co. Ltd.

The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.

If the attackers find the latter, and they have been stored unencrypted, they will “gain access to all the Bitcoins the user has in his possession for that specific account”, Lozkhin warned.

A week ago, hackers hijacked MtGox CEO Karpeles’ blog and posted a file which they claimed had been nabbed from the company’s servers.

They said the file proved that the exchange, once the world’s largest, still controlled almost one million Bitcoins despite having just declared bankruptcy.

As interest in the exchange grows following its bankruptcy filing, MtGox has already released a notice warning former users not to fall for phishing emails piggy-backing on the case."

My $.02.

;)


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: Bit_Happy on March 18, 2014, 07:49:17 AM
The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.
I just remembered I need to better protect my LTC wallet before I start using it again.


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: S4VV4S on March 18, 2014, 07:50:04 AM
MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?



Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LostDutchman on March 18, 2014, 07:50:45 AM
The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.
I just remembered I need to better protect my LTC wallet before I start using it again.

Good idea!

My $.02.

;)


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LostDutchman on March 18, 2014, 07:51:17 AM
MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?



I dunno but what does it look like?

My $.02.

;)


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: devt on March 18, 2014, 07:53:46 AM
MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?


Is the site legit? I don't want to give my password to any hackers.


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: likehiro on March 18, 2014, 08:46:19 AM
MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?


Is the site legit? I don't want to give my password to any hackers.

Gox database was hacked so your passwords already are on hackers hands. Anyways, what will they do with that information? steal your bitcoins from mtgox? trololol


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LiteCoinGuy on March 18, 2014, 11:03:05 AM
i guess Mark did it  - you get GOXXED AGAIN   :P


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: BitOnyx on March 18, 2014, 11:46:54 AM
Well all of drama is starting again.

People should just move on and start lawsuits.


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: Bit_Happy on March 29, 2014, 01:30:39 AM
i guess Mark did it  - you get GOXXED AGAIN   :P

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  ???


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LostDutchman on March 29, 2014, 01:33:23 AM
i guess Mark did it  - you get GOXXED AGAIN   :P

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  ???

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

;)


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: Bit_Happy on March 29, 2014, 01:42:38 AM
i guess Mark did it  - you get GOXXED AGAIN   :P

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  ???

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

;)

Is Mark also the "Werewolf Of MtGox?"
Warren Z had another song I remember....Yes.....Mark's favorite:
"Send Lawyers Guns and Money, daddy get me out of this"


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: LostDutchman on March 29, 2014, 02:32:09 AM
i guess Mark did it  - you get GOXXED AGAIN   :P

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  ???

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

;)

Is Mark also the "Werewolf Of MtGox?"
Warren Z had another song I remember....Yes.....Mark's favorite:
"Send Lawyers Guns and Money, daddy get me out of this"

Mmmmmmmmmmmmmmmm............

Warren Zevon may well have been God On Earth.

I bootlegged a recording of one of his Kansas City concerts.

My $.02.

;)


Title: Re: MtGox remedy worse than the disease says Kaspersky researcher
Post by: Bit_Happy on March 29, 2014, 04:20:25 AM
Too many of the great live acts are old or dead now.
Lady goo-goo ain't no lady, she's just a bunch of ga-ga.