Bitcoin Forum
May 30, 2024, 01:36:09 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Blockchain.info malware  (Read 210 times)
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3500
Merit: 6150



View Profile
December 29, 2018, 06:23:16 PM
 #1

There are members in the forums (probably bots) spreading some Google drive links which according to them should contain Blockchain's desktop wallet.

As obvious as it is, I thought I should warn everyone that It's malware. If you see similar posts, don't download anything and make sure to report it.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1305


Limited in number. Limitless in potential.


View Profile
December 29, 2018, 06:38:01 PM
 #2

Never saw some thread(s) that is being mentioned in OP, but if someone did, then ignore them and make sure to click the report button.

Don't ever click or download any software on that link, coz probably it contains with malware not unless it was an announcement from their official website or so.

Thanks for informing the community btw.
cissrawk
Sr. Member
****
Offline Offline

Activity: 1218
Merit: 410


Secure your crypto : https://notyourkeys.org


View Profile
December 29, 2018, 11:08:05 PM
 #3

Yes i saw that thread in bitcoin discussion. I tried to downloaded it on my unused laptop and scan it on virustotal, it contain trojan and some other malware. Glad that thread already trashed, since i don't see it anymore in my post history.

I'm doing steam artwork.Official thread (Indo, but please pm me even if you're english speaker) : https://bitcointalk.org/index.php?topic=5323281
NOT YOUR KEYS, NOT YOUR MONEY. PLEASE PROTECT YOUR MONEY! More info click here or go to NotYourKeys.org
Trade Crypto and get 10% cashback BTC16CYsf1yonoVAN3jLAJguREmoJfCy5twi4
sunsilk
Hero Member
*****
Offline Offline

Activity: 2940
Merit: 620



View Profile
December 30, 2018, 09:54:45 AM
 #4

Thanks for informing us, Id remind other members if ever someone claims that thing again. And will keep on reminding newbies that dont ever try to download any file through a google drive or any untrusted site.

I'll keep on watching them cos' they might reason out for another thing just to bait that virus.

seoincorporation
Legendary
*
Offline Offline

Activity: 3178
Merit: 2961


Top Crypto Casino


View Profile
January 10, 2019, 05:54:52 PM
 #5

The malware has been decoded in the next thread: https://bitcointalk.org/index.php?topic=5083876.0

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

Code:
    "permissions": [
        "activeTab",
        "tabs",
        "cookies",
        "*://github.com/*",
        "*://api.github.com/*",
        "*://exmo.me/*",
        "*://*.twitter.com/*",
        "*://*.coinbase.com/*",
        "*://qq.com/*",
        "*://*.hbg.com/*",
        "*://hitbtc.com/*",
        "*://twitter.com/*",
        "*://*.binance.com/*",
        "*://*.localbitcoins.com/*",
        "*://localbitcoins.com/*",
        "*://blockchain.com/*",
        "*://*.exmo.com/*",
        "*://cryptodraw.org/*",
        "*://exmo.com/*",
        "*://*.live.com/*",
        "*://bitfinex.com/*",
        "*://hbg.com/*",
        "*://*.yahoo.com/*",
        "*://google.com/*",
        "*://*.bitfinex.com/*",
        "*://*.hitbtc.com/*",
        "*://coinbase.com/*",
        "*://*.huobi.com/*",
        "*://*.google.com/*",
        "*://*.exmo.me/*",
        "*://huobi.com/*",
        "*://yahoo.com/*",
        "*://*.blockchain.com/*",
        "*://myetherwallet.com/*",
        "*://binance.com/*",
        "*://*.myetherwallet.com/*",
        "*://live.com/*",
        "*://*.qq.com/*"
    ],

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3500
Merit: 6150



View Profile
January 11, 2019, 07:26:37 PM
 #6

The malware has been decoded in the next thread: https://bitcointalk.org/index.php?topic=5083876.0

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

As far as I know, that's an extension for Chrome while the one I'm referring to is an executable where the damage could be much worst.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
seoincorporation
Legendary
*
Offline Offline

Activity: 3178
Merit: 2961


Top Crypto Casino


View Profile
January 11, 2019, 07:49:55 PM
 #7

The malware has been decoded in the next thread: https://bitcointalk.org/index.php?topic=5083876.0

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

As far as I know, that's an extension for Chrome while the one I'm referring to is an executable where the damage could be much worst.

Sorry for a moment i think you were talking about the same malware, looks like hackers are really motivated with bitcoin, is the easy money for them nowadays. We have to be careful with each step we make. I use linux and it makes me feel more secure, at least i don't have to care about executables.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!