Bitcoin Forum
June 24, 2024, 03:09:33 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Other / Beginners & Help / Re: All my BTC were stolen from QT desktop wallet by this individual on: June 11, 2014, 09:24:21 PM
Don't know the service section part, but I will send two BTC for the safe return of the stolen coins to the 1HUJt.... address



Why would you send the coins back to that address when you already know it's compromised

my thoughts exactly, anyway I would go into cold storage. Is definatly safe from hackers. Some how many BTC did you lose?

11.76. Well over $7k worth
2  Economy / Services / Re: 2 BTC bounty for the return of 11.76 stolen btc Some relevant info inside on: June 11, 2014, 12:02:55 AM
It's a bit of a stretch but here is what I came up with:

Tazja is known as tazbox on a hackers forum (http://jomgegar.com/)
16th post in this topic shows tazbox probably is up to no good/linked to bitcoin (http://jomgegar.com/topic/2801-question-about-bitcoin/?hl=tazbox)

Then if we look a bit further we find this topic about tazja being a hacker: https://bitcointalk.org/index.php?topic=543660.0
If you look at post 18, you see a post of bitdonkey. He stated he also got hacked by tazja.
If we look up bitdonkey's post we see this post about him purchasing a VPS host: https://bitcointalk.org/index.php?topic=342443.msg5598973#msg5598973

Domain is tazbox. As stated previously, that is the username of Tazja. So either bitdonkey is tazja, or he wanted to make a website dedicated to his own hacker?

The extension of the domainname is not stated, but let's assume it's .fr, as he is french. Then we come up with:
contact:     Dubas Julien
address:     18, place de la mairie
address:     07200 Aubenas
country:     FR
phone:       +33 7 53 76 03 40
e-mail:      taznact@gmail.com
Possible second email: taznact@yahoo.com

And what if we search for taznact? Then this comes up as first result:
Antivirus scan for ... - VirusTotal
https://www.virustotal.com/latest-report.html?resource...
SHA256: 6debde863fce2217b8e7e8a58dd948f00c441eb15d5cba30a5a7103d469e07b8. File name: Taznact.exe. Detection ratio: 24 / 47. Analysis date ...


So the domainname tazbox.fr is now linked to not only sha256, but also to a file with the name taznact.exe (same as his email) which most likely contains a virus.

And the virus made you lose your bitcoin.
By the way, he seems to spread his virus through NZB (download website).
Look at his uploaded files: http://www.nzbking.com/poster/Taznact@yahoo.com%20(Taznact)/

Hope this helps!

If you manage to get your btc back, this is my address for a donation:
btc:1AHkjqevi3DcebECujHFAbJjLad58Dqt6A


Awesome sleuthing friend.  Certainly will remember if I make headway on return of stolen coins.
3  Economy / Services / Re: 2 BTC bounty for the return of 11.76 stolen btc Some relevant info inside on: June 10, 2014, 11:31:49 PM
If you get their first and real name, honestly what would you do ?
Unfortunately most people here (not everyone) seem to let it slide and would rather lose money then face to face confrontation.

would love a video of someone confronting a scammer!!

first I'll try to contact him politely and give him an opportunity to make nice.  I have friends in France. 
4  Other / Beginners & Help / Re: All my BTC were stolen from QT desktop wallet by this individual on: June 10, 2014, 11:20:03 PM
It's a bit of a stretch but here is what I came up with:

Tazja is known as tazbox on a hackers forum (http://jomgegar.com/)
16th post in this topic shows tazbox probably is up to no good/linked to bitcoin (http://jomgegar.com/topic/2801-question-about-bitcoin/?hl=tazbox)

Then if we look a bit further we find this topic about tazja being a hacker: https://bitcointalk.org/index.php?topic=543660.0
If you look at post 18, you see a post of bitdonkey. He stated he also got hacked by tazja.
If we look up bitdonkey's post we see this post about him purchasing a VPS host: https://bitcointalk.org/index.php?topic=342443.msg5598973#msg5598973

Domain is tazbox. As stated previously, that is the username of Tazja. So either bitdonkey is tazja, or he wanted to make a website dedicated to his own hacker?

The extension of the domainname is not stated, but let's assume it's .fr, as he is french. Then we come up with:
contact:     Dubas Julien
address:     18, place de la mairie
address:     07200 Aubenas
country:     FR
phone:       +33 7 53 76 03 40
e-mail:      taznact@gmail.com
Possible second email: taznact@yahoo.com

And what if we search for taznact? Then this comes up as first result:
Antivirus scan for ... - VirusTotal
https://www.virustotal.com/latest-report.html?resource...
SHA256: 6debde863fce2217b8e7e8a58dd948f00c441eb15d5cba30a5a7103d469e07b8. File name: Taznact.exe. Detection ratio: 24 / 47. Analysis date ...

So the domainname tazbox.fr is now linked to not only sha256, but also to a file with the name taznact.exe (same as his email) which most likely contains a virus.

And the virus made you lose your bitcoin.
By the way, he seems to spread his virus through NZB (download website).
Look at his uploaded files: http://www.nzbking.com/poster/Taznact@yahoo.com%20(Taznact)/

Hope this helps!

If you manage to get your btc back, this is my address for a donation:
btc:1AHkjqevi3DcebECujHFAbJjLad58Dqt6A


Great sleuthing.  I imagined he was french (as another victim described him( and yes the NZB file reminds me of something i downloaded on usenet that was supposed to be a movie file and instead ended up being an executable that i clicked on, but then nothing seemed to happen.  I will follow up on this.  Much appreciated and will keep you in mind for compensation.
5  Other / Beginners & Help / Re: All my BTC were stolen from QT desktop wallet by this individual on: June 09, 2014, 10:26:46 PM
Did you encrypt your wallet with password?

Next time don't use Windows. Use Mac OS X or GNU/Linux. If you store large amount of bitcoin, you may use cold storage / paper wallet.

Was you using windows without an outbound firewall? (Windows firewall does not block Outbound connections and any undetected key-logger would send everything to the hacker without you even knowing)

the wallet had passphrase encryption.  Not sure about the firewall.  Kasperski and AVG were on and nether triggered.   ran Malwarebytes.org scan and it did flag a bunch of stuff that the AV programs missed.  Certainly learned a lesson about importance of paper wallets.   

this character has posted to this community in the past.  I am hopeful moderators can DOXX him and hopefully together we can shame/coerce the guy to return the coins.
6  Economy / Services / 2 BTC bounty for the return of 11.76 stolen btc Some relevant info inside on: June 08, 2014, 09:44:22 PM
2 BTC bounty for the return of 11.76 stolen btc.

Looks like coins went to this wallet 12gEgguL2ciHqerypstKM5WYCMcxRKsnQ4  on 4/6 2014

This guy " Tazja" previously admitted to controlling the address my coins went to in this post (Anyone know him?)

https://bitcointalk.org/index.php?topic=259649.3240

Quote:

I use 2 adress,

12gEgguL2ciHqerypstKM5WYCMcxRKsnQ4 (i receive 0.018 btc in this adress)

And

1FtRXz2KdjttgSY9ojcQB7mQ5SBmf2cXLz


Link to transaction occurred on 4/6/2014:

https://blockchain.info/tx/cf8c8247490f9cabd976fdd47c87eb8b19b30a20109685592802d53f05f6991d
I am still not sure how thief got access but suspect a key logger from Usenet. I was running virus checker but it was either AVG or K labs and did not trigger anything. Any and all help tracking these down would be appreciated.
7  Other / Beginners & Help / Re: All my BTC were stolen from QT desktop wallet by this individual on: June 08, 2014, 09:31:52 PM
Don't know the service section part, but I will send two BTC for the safe return of the stolen coins to the 1HUJt.... address

8  Other / Beginners & Help / All my BTC were stolen from QT desktop wallet by this individual on: June 08, 2014, 09:02:29 PM
Looks like coins went to this wallet 12gEgguL2ciHqerypstKM5WYCMcxRKsnQ4

This guy " Tazja" admitted to controlling the address my coins went to in this post

Anyone know him?

https://bitcointalk.org/index.php?topic=259649.3240

Quote:

I use 2 adress,

12gEgguL2ciHqerypstKM5WYCMcxRKsnQ4 (i receive 0.018 btc in this adress)

And

1FtRXz2KdjttgSY9ojcQB7mQ5SBmf2cXLz


Link to transaction occurred on 4/6/2014:

https://blockchain.info/tx/cf8c8247490f9cabd976fdd47c87eb8b19b30a20109685592802d53f05f6991d
I am still not sure how thief got access but suspect a key logger from Usenet. I was running virus checker but it was either AVG or K labs and did not trigger anything. Any and all help tracking these down would be appreciated
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!