Bitcoin Forum
May 25, 2024, 02:24:36 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Fake Corona Anti-virus software  (Read 255 times)
TravelMug (OP)
Hero Member
*****
Offline Offline

Activity: 2646
Merit: 851



View Profile
March 26, 2020, 03:35:46 AM
Last edit: October 19, 2023, 04:20:24 AM by TravelMug
Merited by rodskee (2), BITCOIN4X (2), ABCbits (1), Baofeng (1), DdmrDdmr (1), Maus0728 (1), PrimeNumber7 (1), Symmetrick (1)
 #1

So cyber criminals are now creating a fake website, supposedly an anti-virus software. Instead what you're going to get is a BlackNET RAT, which has the ability to:

• Deploying DDOS attacks
• Taking screenshots
• Stealing Firefox cookies
• Stealing saved passwords
• Implementing a keylogger
• Executing scripts
• Stealing Bitcoin wallets

Actual image of the fake site

Website:

Code:
https://corona-antivirus.com/

Download link:

Code:
http://antivirus-covid19.site/update.exe

Although as of now the download link is not working, but I'm sure those bad actors are going to relaunched it very soon and probably patching things up to that it will be hard to detect by AV. Now that most are working from home, just be very careful. They even added a bitcoin donation address. So far none has fallen for this and try to donate on that address.


Bitcoin Address:
Code:
15tvkwqxRw1rXPBsbbh3jUSNYkGg123fY7

A detailed technical explanation here: https://blog.malwarebytes.com/threat-analysis/2020/03/fake-corona-antivirus-distributes-blacknet-remote-administration-tool/

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
mk4
Legendary
*
Offline Offline

Activity: 2772
Merit: 3838


Paldo.io 🤖


View Profile
March 26, 2020, 04:38:55 AM
Merited by 20kevin20 (1)
 #2

From the first link: "Your mobile device actively protects you against the Coronaviruses (Cov) while the app is running."

If a certain person actually thinks a mobile app can protect him/her from COVID-19 then I don't even know what to say.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
PrimeNumber7
Copper Member
Legendary
*
Offline Offline

Activity: 1624
Merit: 1899

Amazon Prime Member #7


View Profile
March 26, 2020, 04:58:25 AM
 #3

I have to wonder how many people actually think the coronavirus is something their computer can get or that it is something they can get from their computer.

This has got to be the result of a poor translation of a poor translation.
Maus0728
Legendary
*
Offline Offline

Activity: 1918
Merit: 1577


Bitcoin Casino Est. 2013


View Profile
March 26, 2020, 06:11:50 AM
 #4

Who the heck will believe in that particular joke? Even tho it is stated only for fun. It has the possibility to confuse illiterate end users.

Also the website looks like another bought website in the market which are particularly used for scamming people. I remember HEX website wherein the website user interface is similar with that of the antivirus Cheesy

Anyways, can this be reported? If yes, where can I possibly report it?

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
20kevin20
Legendary
*
Offline Offline

Activity: 1134
Merit: 1597


View Profile
March 26, 2020, 09:41:10 AM
 #5

From the first link: "Your mobile device actively protects you against the Coronaviruses (Cov) while the app is running."

If a certain person actually thinks a mobile app can protect him/her from COVID-19 then I don't even know what to say.

I've seen videos of people saying only computers have viruses, not humans, so this doesn't surprise me at all. But I guess the same guys cannot use a damn Bitcoin if that's all the knowledge they have.



The fake website looks so good, damn it! If you aren't the type of person to download any shit off the Internet, then I don't even know why you'd need an antivirus. I haven't had one in years - whenever I tried to, it deleted and blocked all the important files, I swear..
NotATether
Legendary
*
Offline Offline

Activity: 1610
Merit: 6761


bitcoincleanup.com / bitmixlist.org


View Profile WWW
March 26, 2020, 10:39:18 AM
 #6

I have reported this site to Google Safe Browsing and encourage you all to do the same.


.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
sheenshane
Legendary
*
Offline Offline

Activity: 2422
Merit: 1228


View Profile WWW
March 26, 2020, 10:43:38 AM
 #7

snip-
Anyways, can this be reported? If yes, where can I possibly report it?
The same question as here, if not yet reported we will help others and report this phishing to, safebrowsing/report_phis/..

That is the reason I hate downloading from browsing on the website because we even don't know how safe they are. Even in google Playstore I always read and check feedbacks from others to have referenced before I downloaded the apps.

Thank you for sharing OP, I think you must include this thread of yours on "How and Where to Report Phishing Websites". This is great stuff and very helpful to newbies out there.
Bazlur
Member
**
Offline Offline

Activity: 364
Merit: 12


View Profile
March 26, 2020, 11:07:10 AM
 #8

I have reported this site to Google Safe Browsing and encourage you all to do the same.


I am also reported this site because some people may fall in danger by installiing the software. Some people may become curious about the website and install the software to see "Is this really working? "and fall in danger. So it is high time to report the website.


███    TWITTER     █████████████████ MEGABSC ████████████████████     WHITEPAPER     ███
███       ANN                  ██████  HYBRID DEFI ON BINANCE SMART CHAIN  █████    FACEBOOK PAGE    ███
███  TELEGRAM  █████████████████     SWAP      ███████████████████       MEDIUM      ███
UserU
Hero Member
*****
Offline Offline

Activity: 2044
Merit: 532


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
March 26, 2020, 11:56:55 AM
 #9

From the first link: "Your mobile device actively protects you against the Coronaviruses (Cov) while the app is running."

If a certain person actually thinks a mobile app can protect him/her from COVID-19 then I don't even know what to say.

You'd be surprised how many recently tens of thousands of new websites are taking advantage of this trend. We even have to deal with Corona porn and merchandises Cheesy

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█
▄▄▄▀▀▀▀▀▀▀▄▄▄
▄▄▀▀▄ ▄ ▀ ▀ ▀ ▄ ▄▀▀▄▄
▄▀▄ ▀               ▀ ▄▀▄
█ ▄                     ▄ █
█ ▄  █████  ▄███▄  ▄███▄  ▄ █
█ ▄   ██▄▄   ██ ██  ██ ██   ▄ █
█ ▄   ▀▀▀██  ██ ██  ██ ██   ▄ █
█ ▄   ▄▄ ██  ██ ██  ██ ██   ▄ █
█ ▄  ▀███▀  ▀███▀  ▀███▀  ▄ █
█ ▄                     ▄ █
▀▄ ▀ ▄             ▄ ▀ ▄▀
▀▀▄▄ ▀ ▄ ▄ ▄ ▄ ▀ ▄▄▀▀
▀▀▀▄▄▄▄▄▄▄▀▀▀

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
UserU
Hero Member
*****
Offline Offline

Activity: 2044
Merit: 532


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
March 26, 2020, 11:59:36 AM
 #10

I have reported this site.

Good job, cybersecurity companies are catching up too Cheesy

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█
▄▄▄▀▀▀▀▀▀▀▄▄▄
▄▄▀▀▄ ▄ ▀ ▀ ▀ ▄ ▄▀▀▄▄
▄▀▄ ▀               ▀ ▄▀▄
█ ▄                     ▄ █
█ ▄  █████  ▄███▄  ▄███▄  ▄ █
█ ▄   ██▄▄   ██ ██  ██ ██   ▄ █
█ ▄   ▀▀▀██  ██ ██  ██ ██   ▄ █
█ ▄   ▄▄ ██  ██ ██  ██ ██   ▄ █
█ ▄  ▀███▀  ▀███▀  ▀███▀  ▄ █
█ ▄                     ▄ █
▀▄ ▀ ▄             ▄ ▀ ▄▀
▀▀▄▄ ▀ ▄ ▄ ▄ ▄ ▀ ▄▄▀▀
▀▀▀▄▄▄▄▄▄▄▀▀▀

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
Coyster
Legendary
*
Offline Offline

Activity: 2030
Merit: 1251


Life's but a walking shadow!


View Profile
March 26, 2020, 12:43:24 PM
 #11

There are a lot of individuals who only know that there is a virus spreading all over the world by the name corona virus, they know nothing more about it, neither have have they read anything on what sort of virus it is, how it can be transmitted, the preventive measures and other whatnots, this group of people are the ignorant ones and though it's hard to believe, they are actually the ones that can fall this kind of scam, they are only driven by the fear of the virus, that fear can make them download this and lose a lot.
blue Snow
Legendary
*
Offline Offline

Activity: 1512
Merit: 1029


#SWGT CERTIK Audited


View Profile WWW
March 26, 2020, 01:02:36 PM
 #12

Website:
Code:
https://corona-antivirus.com/
Virus total detected 4 Malicious link at that site
https://www.virustotal.com/gui/url/8653be1d721f31ecc0cc668e3aa928623352883b94ca3068968dc9f6cedec39f/detection

Download link:
Code:
http://antivirus-covid19.site/update.exe
Virus total detected 3 Malicious in download link
https://www.virustotal.com/gui/url/3fd0154a5192424d93df575cbbf9f0d2f45b969b359b257f3caa27b51a7aac37/detection

>> Newbie or beginner shouldn't click those links to avoid your PC from malware injection.

hugeblack
Legendary
*
Offline Offline

Activity: 2520
Merit: 3688


View Profile WWW
March 26, 2020, 01:16:50 PM
 #13

Corona is a hot topic so you will find that some people try to use this name in the free promotion of a project as a friend has prepared a drink with this name.
Perhaps the hacker/scammer tries to add some things like that the program asks you to add a sensor to make sure that you are not infected, or that it displays the number of cases and other justifications that may make sense to people who do not have sufficient programming information.

You can report it to make sure it is deleted.
TravelMug (OP)
Hero Member
*****
Offline Offline

Activity: 2646
Merit: 851



View Profile
March 27, 2020, 07:02:32 AM
 #14

Thanks to everyone who have reported this malicious websites.

It has been taken down already. But we shouldn't be too complacent, as Developing Story: Coronavirus Used in Malicious Campaigns.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!