Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: M.Antonio on March 26, 2022, 09:14:28 AM



Title: bitcoin core exploit alert
Post by: M.Antonio on March 26, 2022, 09:14:28 AM
i download bitcoin core but I receive alerts from antivirus . exploit alert blocked website 192.42.116.20


like this

https://www.virustotal.com/gui/url/318b451ec79d0ac229ebc3694d474ac626e6a44e4fdee840970c7e45b44b2eed

Forcepoint ThreatSeeker   proxy avoidance
Comodo Valkyrie Verdict   software-hardware
Webroot   Proxy Avoidance and Anonymizers

is safe to keep bitcoin core ?


Title: Re: bitcoin core exploit alert
Post by: ABCbits on March 26, 2022, 11:44:48 AM
is safe to keep bitcoin core ?

Assuming you download it from legit source (such as bitcoin.org[1] or bitcoincore.org[2]) and verify the hash/signature, it is safe to use Bitcoin Core. It is known that some antivirus make false positive report on cryptocurrency[3].

[1] https://bitcoin.org/en/download (https://bitcoin.org/en/download)
[2] https://bitcoincore.org/en/download/ (https://bitcoincore.org/en/download/)
[3] https://bitcoinmagazine.com/culture/wasabi-wallet-launches-bitcoinissafe-campaign-to-counter-erroneous-antivirus-detections (https://bitcoinmagazine.com/culture/wasabi-wallet-launches-bitcoinissafe-campaign-to-counter-erroneous-antivirus-detections)


Title: Re: bitcoin core exploit alert
Post by: DdmrDdmr on March 26, 2022, 02:24:19 PM
The negative reports from VirusTotal are perhaps related to the IP being as a Tor Exit node, and I recalled reading something about some Tor exit notes being rouge, trying to replace BTC addresses and such:
https://www.schneier.com/blog/archives/2021/12/someone-is-running-lots-of-tor-relays.html

Also see the numerous reports here: https://www.abuseipdb.com/check/192.42.116.20

Perhaps it's an issue along the line of the describs in the referencd article.


Title: Re: bitcoin core exploit alert
Post by: coupable on March 26, 2022, 07:09:59 PM
This is not new, assuming you downloaded the file from a trusted source. Antivirus software usually is not able to recognize cryptocurrency wallets and therefore lists them as malware.
It would be a good idea to tell us the source you used to download the wallet before trying to install it on your device again, so that you can avoid any possible damages. If it's from a proper source, and you are using also a proper source of reliable antivirus, all what you have to do is ignoring those alerts and continue downloading the blockchain or you can desactivate antivirus software for a few hours to avoid unnecessary noises .


Title: Re: bitcoin core exploit alert
Post by: M.Antonio on March 26, 2022, 08:37:18 PM
i download from https://bitcoin.org

I'm downloading now  copy of the blockchain .it goes extremely slow . i am now in 5 august 2017

I received another 5 alerts in an hour

https://www.virustotal.com/gui/url/2b6ea0f6681f39bd06e4398867ef349b169aea1a5f5c6012e69b929903c84ee8/details


Title: Re: bitcoin core exploit alert
Post by: BitMaxz on March 26, 2022, 11:51:41 PM
I received another 5 alerts in an hour

https://www.virustotal.com/gui/url/2b6ea0f6681f39bd06e4398867ef349b169aea1a5f5c6012e69b929903c84ee8/details


What exactly Antivirus you are using?

It seems few nodes or peers are being blocked by your antivirus I suggest you if you want to run and sync the Bitcoin core better exclude Bitcoin from scanning or disable your Antivirus or switch to another antivirus because your AV is giving false-positive reports. I'm using Kaspersky but it doesn't give any false reports.


Title: Re: bitcoin core exploit alert
Post by: AmoreJaz on March 26, 2022, 11:57:17 PM
I received another 5 alerts in an hour

https://www.virustotal.com/gui/url/2b6ea0f6681f39bd06e4398867ef349b169aea1a5f5c6012e69b929903c84ee8/details

What exactly Antivirus you are using?

It seems few nodes or peers are being blocked by your antivirus I suggest you if you want to run and sync the Bitcoin core better exclude Bitcoin from scanning or disable your Antivirus or switch to another antivirus because your AV is giving false-positive reports. I'm using Kaspersky but it doesn't give any false reports.

as he mentioned he downloaded from bitcoin.org, then i won't be worrying here as it is a trusted source. high likely that he's getting false positive reports here because of the antivirus that he is using.. if he is very worried, why not try installing the lighter version, which is the electrum.


Title: Re: bitcoin core exploit alert
Post by: pooya87 on March 27, 2022, 07:49:40 AM
if he is very worried, why not try installing the lighter version, which is the electrum.
Same issues could rise for Electrum too. I have had my anti-virus (ESET Internet Security) complain about it in the past and blocked some IP addresses of some nodes.
The only solution to solve any doubts and worries is to compile from source code and run that instead. After all different bitcoin softwares such as bitcoin core and electrum are open source so that you can see every little thing they do.


Title: Re: bitcoin core exploit alert
Post by: M.Antonio on March 27, 2022, 08:28:52 AM
i use Malwarebytes

i download today Bitcoin Core version v22.0.0 from https://bitcoin.org  and I continued  download blocks from where I left off -10 august 2017

I have not received any more alerts in 2 hours download

progress 0.10 % per hour


Title: Re: bitcoin core exploit alert
Post by: seoincorporation on March 27, 2022, 06:18:59 PM
Bitcoin nodes use TOR and if some of those IP gets blacklisted by an antivirus then the bitcoin core will be flagged, I feel that's the problem in your case.

You should change your Anti Virus or white flag the software. That should fix the problem.


Title: Re: bitcoin core exploit alert
Post by: Wind_FURY on March 28, 2022, 05:55:25 AM
I received another 5 alerts in an hour

https://www.virustotal.com/gui/url/2b6ea0f6681f39bd06e4398867ef349b169aea1a5f5c6012e69b929903c84ee8/details


What exactly Antivirus you are using?

It seems few nodes or peers are being blocked by your antivirus I suggest you if you want to run and sync the Bitcoin core better exclude Bitcoin from scanning or disable your Antivirus or switch to another antivirus because your AV is giving false-positive reports. I'm using Kaspersky but it doesn't give any false reports.


There's defintely more than a 75% chance that it's a false positive. I experienced the same thing before when I installed a POW miner in one of my computers, years ago. Tin-foil hats on, but I believe anti-virus software are being used by a group of anti-Bitcoin technology companies and corporations for an anti-Bitcoin/anti-decentralization push. They want to censor you.

OP, learn to use open source software, start with Linux.


Title: Re: bitcoin core exploit alert
Post by: BitMaxz on March 28, 2022, 10:37:25 PM
i use Malwarebytes

i download today Bitcoin Core version v22.0.0 from https://bitcoin.org  and I continued  download blocks from where I left off -10 august 2017

I have not received any more alerts in 2 hours download

progress 0.10 % per hour

So Malwarebytes is your Antivirus?

Actually, it's not an antivirus it is an Anti-malware tool you should have an Anti-virus to protect your PC from virus attacks Kaspersky would be the best option, I tested them for more than 9yrs.

So there is a possibility that your PC is infected not the Bitcoin core itself if you scan the Bitcoin core to VirusTotal it's totally clean even with Malwarebytes or other AntiVirus like Kaspersky.

Do you have Anti-virus installed on your PC other than Malwarebytes?


Title: Re: bitcoin core exploit alert
Post by: M.Antonio on March 29, 2022, 10:59:21 AM
i use Malwarebytes

i download today Bitcoin Core version v22.0.0 from https://bitcoin.org  and I continued  download blocks from where I left off -10 august 2017

I have not received any more alerts in 2 hours download

progress 0.10 % per hour

So Malwarebytes is your Antivirus?

Actually, it's not an antivirus it is an Anti-malware tool you should have an Anti-virus to protect your PC from virus attacks Kaspersky would be the best option, I tested them for more than 9yrs.

So there is a possibility that your PC is infected not the Bitcoin core itself if you scan the Bitcoin core to VirusTotal it's totally clean even with Malwarebytes or other AntiVirus like Kaspersky.

Do you have Anti-virus installed on your PC other than Malwarebytes?


I have Bitdefender

why progress 0.10 % per hour ? so slow



Title: Re: bitcoin core exploit alert
Post by: darkv0rt3x on March 29, 2022, 11:06:46 AM
As already have been said, make sure to download from official sources and check the signatures. Other than that, just ignore/add to whitelist in your AV. Simple as that!
If the software was infected from the sources, everyone would be getting those AV warnings... Those are false positives, for sure!


Title: Re: bitcoin core exploit alert
Post by: NeuroticFish on March 29, 2022, 12:44:00 PM
I received another 5 alerts in an hour

Indeed, depending on the antivirus/anti-malware system, it may detect various suspicious things because of TOR or may detect even malicious data (real or not) in the actual blockchain data. But since that data is never interpreted as something your computer would have to run, it should be fine.

why progress 0.10 % per hour ? so slow

Also as said, the blockchain is 425+GB in size, which means long download and also the need for a lot of disk space. If your internet connection is good, you have plenty of RAM and you have SDD (not necessarily for the whole 425+GB), some settings here and there can improve the speed a lot.


Even more, a light wallet like Electrum, which doesn't need the whole blockchain and synchronizes in seconds, may actually be the wallet you're looking for.
Just if you switch to that, make sure you also verify it.


Title: Re: bitcoin core exploit alert
Post by: M.Antonio on March 31, 2022, 08:41:03 AM
I received another 5 alerts in an hour

Indeed, depending on the antivirus/anti-malware system, it may detect various suspicious things because of TOR or may detect even malicious data (real or not) in the actual blockchain data. But since that data is never interpreted as something your computer would have to run, it should be fine.

why progress 0.10 % per hour ? so slow

Also as said, the blockchain is 425+GB in size, which means long download and also the need for a lot of disk space. If your internet connection is good, you have plenty of RAM and you have SDD (not necessarily for the whole 425+GB), some settings here and there can improve the speed a lot.


Even more, a light wallet like Electrum, which doesn't need the whole blockchain and synchronizes in seconds, may actually be the wallet you're looking for.
Just if you switch to that, make sure you also verify it.

i have 8 giga Ram no ssd .i have good internet connection

i want to support bitcoin red with a node

i see now only 3 active conection .i have 10 active conection to new york coin wallet and is a 3 milion usd market cap coin

  i think malwarebyte block tor IPs nodes


Title: Re: bitcoin core exploit alert
Post by: NeuroticFish on March 31, 2022, 08:47:18 AM
i want to support bitcoin red with a node

i see now only 3 active conection .i have 10  3 active conection to new york coin wallet and is a 3 milion usd market cap

Bitcoin red is a token and it's not related to bitcoin.
I don't even know what's that New York coin - whether is a coin or token.
You are mixing up badly bitcoin with altcoins and tokens. Each coin has its own blockchain. Bitcoin core works with bitcoin only.
You seem to be very confused with all those altcoins/shitcoins/tokens around. You should read more first...


Title: Re: bitcoin core exploit alert
Post by: DdmrDdmr on March 31, 2022, 09:14:49 AM
<…>
I’m not sure whether to interpret the above as @NeuroticFish has, or whether you mean this alternative option:

"Bitcoin red" would be Spanglish for "Bitcoin network" ("red" in Spanish is "network" in English). You would therefore be trying to set-up your own bitcoin node, as inferred by from where you made the download (stated in a prior post).

You’re still going slow (right?), and wondering why. As a comparison, you state that you’ve only got 3 connections, whilst having 10 on another (unrelated) wallet.


Title: Re: bitcoin core exploit alert
Post by: M.Antonio on March 31, 2022, 07:12:41 PM
i want to support bitcoin red with a node

i see now only 3 active conection .i have 10  3 active conection to new york coin wallet and is a 3 milion usd market cap

Bitcoin red is a token and it's not related to bitcoin.
I don't even know what's that New York coin - whether is a coin or token.
You are mixing up badly bitcoin with altcoins and tokens. Each coin has its own blockchain. Bitcoin core works with bitcoin only.
You seem to be very confused with all those altcoins/shitcoins/tokens around. You should read more first...


I wanted to say Bitcoin network

i install doge coin and new york coin core full node wallet in 2017

I'm not new . and I wanted to have king bitcoin  crypto full node


Title: Re: bitcoin core exploit alert
Post by: DeathAngel on March 31, 2022, 07:24:35 PM
The thread title panicked me man, damn it. Yeah, as others have said, it’s just your anti virus being overly sensitive. You scared me though, OP. I need a drink now :D


Title: Re: bitcoin core exploit alert
Post by: NeuroticFish on March 31, 2022, 07:50:48 PM
I wanted to say Bitcoin network

Thanks for clearing up.

"Bitcoin red" would be Spanglish for "Bitcoin network" ("red" in Spanish is "network" in English). You would therefore be trying to set-up your own bitcoin node, as inferred by from where you made the download (stated in a prior post).

Impressing guess! I don't know Spanish, so I've taken everything ad literam, especially as he mentioned another altcoin too.

i have 8 giga Ram no ssd .i have good internet connection

With no SSD it will keep being pretty much slow.
A bigger dbcache should help though. That means to add this into bitcoin.conf (if it's missing, you can create in Bitcoin's data folder)

Code:
dbcache=4800

Another thing of help could be to add to your antivirus' exclusion list (if it has any) the folders blocks and chainstate from Bitcoin's data folder. Nothing is meant to be executed from there anyway.