Bitcoin Forum
May 25, 2024, 05:35:05 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [SCAM] - CatalansCoin, Wallets are Infected with Malware!!  (Read 220 times)
Bitcoin_Arena (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2044
Merit: 1807


฿itcoin for all, All for ฿itcoin.


View Profile
April 28, 2019, 12:52:05 AM
 #1

What happened: CatalansCoin wallet is infected with Malware

1. Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=2577541

ANN: https://bitcointalk.org/index.php?topic=5128919.0
[Archived]: http://archive.fo/eKWye

2. Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=1079176

ANN: https://bitcointalk.org/index.php?topic=5133111
[Archived]: http://archive.fo/4uzH1

3. Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=1986279

ANN: https://bitcointalk.org/index.php?topic=5135335.0
[Archived]: http://archive.fo/5tHMw

Website: http://catalanscoin.com
[Archived]:http://archive.fo/OlUJr

Github:https://github.com/catalanscoin/catalanscoin
Archived:http://archive.fo/QSrCO



Windows wallet zip file has 4 executable files in it

Code:
https://github.com/catalanscoin/catalanscoin/releases/download/0.1.0/Windows-Release.zip

1. CatalansCoind.exe

14 engines detected malware in the file
https://www.virustotal.com/#/file/06c6425ef2a6b2ce555e31b6703ac5a5be68ec149bf39633162e5c2cb097ec7a/detection




2. zedwallet.exe

5 engines detected malware in this file
https://www.virustotal.com/#/file/8b0c8a6259979fbe559d8a6975bfe364fc2552c9964940f1b79450c45d202c3a/detection




3. catalans-service.exe

2 engines detected malware in the file
https://www.virustotal.com/#/file/40051cfccec260657e58824be2983cdee3ab15e9573b397c43dfdd29e2a1c4c1/detection



4. miner.exe

8 Engines detected Malware in the files
https://www.virustotal.com/#/file/3683f3a1c8c3cffc1bfbbae25ad191bef8beec76d8a736b185c0657ed8af47cb/detection




.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1305


Limited in number. Limitless in potential.


View Profile
April 28, 2019, 01:41:42 AM
 #2

You should report to moderator their ann thread instead if this is really a virus. Though most of the client wallet are detected as malware of most AV even the core client but the fact that this project is just a joke and potential scam. I will not mind them instead.
Bitcoin_Arena (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2044
Merit: 1807


฿itcoin for all, All for ฿itcoin.


View Profile
April 28, 2019, 01:18:22 PM
Last edit: April 28, 2019, 01:40:37 PM by Bitcoin_Arena
 #3

You should report to moderator their ann thread instead if this is really a virus. Though most of the client wallet are detected as malware of most AV even the core client but the fact that this project is just a joke and potential scam. I will not mind them instead.
Yes most have false positives but it's usually with a couple of AVs, not 8 or 10.
I reported to the mods but i am not sure how long they take to delete the threads.

I think DT members should so something for a mean time by tagging this chaps because I think there is a ring of guys spreading this malware over and over again.

after you install the wallet, took the 1.7 ether 0x566128F92063D95178b88b69D19C6E9b90796be5
A number of people are already victims.
Look at the transactions in one of the hacker's addresses
https://etherscan.io/address/0x679db306f7d4b04ff76c8ba4c60991c0d7e76f8e

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
catalanscoin
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
June 09, 2019, 07:01:20 PM
 #4

Thanks for your warning. I hope you prevented people from downloading fake wallets.
This is the only official ANN (nº 1 of your links): https://bitcointalk.org/index.php?topic=5128919.0
2 and 3 were phishing attemps.

I am sorry to answer on this old thread. It is on the first google positions, therefore, I had to answer in order to clean our damaged image.

CatalansCoin wallets were compiled in my own laptop, there is no virus here, nor the wallet ask for Administrator rights. Those threads are people impersonating us. Im sorry that some people lost ethereum after installing fake wallets, but there is nothing we can do.

There is no virus here, but I still decided to delete the first version of the wallet on github. We even already made a hardfork so the first release is useless at this point.

The new wallet hash is 8b634554b6ecd96f732ae83bfe56155e4ab62992df4c53adf76375a8263230dc

This wallet still show false positives on virustotal, however I can assure It's virus free: https://www.virustotal.com/gui/file/8b634554b6ecd96f732ae83bfe56155e4ab62992df4c53adf76375a8263230dc/detection

As I said on the official thread, If you are unsure when downloading a wallet, please check If you are using the official website / github, compile from sources or ask team. Even a file with 0 detections can be malicious.
logfiles
Copper Member
Legendary
*
Offline Offline

Activity: 1988
Merit: 1671


Top Crypto Casino


View Profile WWW
June 09, 2019, 11:11:43 PM
Last edit: July 19, 2023, 09:41:33 PM by logfiles
 #5

Thanks for your warning. I hope you prevented people from downloading fake wallets.
This is the only official ANN (nº 1 of your links): https://bitcointalk.org/index.php?topic=5128919.0
2 and 3 were phishing attemps.

Really?

I think you have forgotten that we already have archived versions of your ANN... Why did you edit it? Trying to cover your own tracks?
Look again in the archive: http://archive.fo/eKWye
Github profile with fake wallet that was reported is the same as the one on your ANN. So how does someone else attempt to phish through your ANN?

ANN before editing


ANN after editing


Reported Malicious wallet Github link:
Code:
https://github.com/catalanscoin/catalanscoin/releases/download/0.1.0/Windows-Release.zip



1. The first release was deleted because you probably know it very well that your wallet was malicious from the word go and wanted to cover your tracks

2. You Uploaded the whole zip file and then scanned it, but we all know that virus total isn't that accurate with zip folders. Individual files in the zip folder are very malicious as pointed out in the OP as the person took time to scan each file.

3. False positive can happen but when 5-6 or 8 engines detect something, then it probably not a false positive.

4.  The claim of someone's Ethers being stolen came from your own thread and not the "other fake threads"
after you install the wallet, took the 1.7 ether 0x566128F92063D95178b88b69D19C6E9b90796be5



I am even surprised why the DT members didn't tag you and the other profile that was reported by OP.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
dominguero
Full Member
***
Offline Offline

Activity: 428
Merit: 220


View Profile
June 10, 2019, 10:27:38 AM
Last edit: June 10, 2019, 11:47:26 AM by dominguero
 #6

What happened: CatalansCoin wallet is infected with Malware

1. Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=2577541

ANN: https://bitcointalk.org/index.php?topic=5128919.0
[Archived]: http://archive.fo/eKWye


This was the right ANN, with the GitHub links, I downloaded the first version before the actual fork with no problem.


These are phissing links, by Alexduma https://bitcointalk.org/index.php?action=profile;u=1079176 a know scammer and other random user.

The fakes ANN have phissing links to other directions that they post and different than the real ANN   https://github.com/githubcryptto/coinss/raw/master/Windows-Release.zip and https://bitbucket.org/astingl/catalans/downloads/Windows-Release.zip  (NO DOWNLOAD)



Windows wallet zip file has 4 executable files in it

Code:
https://github.com/catalanscoin/catalanscoin/releases/download/0.1.0/Windows-Release.zip

1. CatalansCoind.exe

14 engines detected malware in the file
https://www.virustotal.com/#/file/06c6425ef2a6b2ce555e31b6703ac5a5be68ec149bf39633162e5c2cb097ec7a/detection

2. zedwallet.exe

5 engines detected malware in this file
https://www.virustotal.com/#/file/8b0c8a6259979fbe559d8a6975bfe364fc2552c9964940f1b79450c45d202c3a/detection

3. catalans-service.exe

2 engines detected malware in the file
https://www.virustotal.com/#/file/40051cfccec260657e58824be2983cdee3ab15e9573b397c43dfdd29e2a1c4c1/detection

4. miner.exe

8 Engines detected Malware in the files
https://www.virustotal.com/#/file/3683f3a1c8c3cffc1bfbbae25ad191bef8beec76d8a736b185c0657ed8af47cb/detection




Catalanscoin is a Turtlecoin Fork, and Turtlecoin binaries have the same warnings.

https://github.com/turtlecoin/turtlecoin/releases/tag/v0.13.0

https://www.virustotal.com/gui/file/69a412c88bc4574bc2da7eb726be5de281d92e2bf4fb74ba0974c780e9065995/detection

https://www.virustotal.com/gui/file/12b309bae949bf264e2bb352143749397c5297be1c7d4c93ad4c07194bd09fbe/detection

https://www.virustotal.com/gui/file/9b2490925c11b4e8135ad59a66cd8f608d989839d1f5223b4fae2bd749a5501c/detection

I am only a user that made my own research, i have no other interest in the project, and I could be mistake.
 

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!