Bitcoin Forum
November 10, 2024, 08:30:10 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: MINING.ML malware  (Read 1118 times)
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 11, 2015, 04:18:11 PM
Last edit: August 11, 2015, 04:34:11 PM by LordCoder
 #1

I do not know where to post this, so please move if it's the wrong place

After I saw the software here: https://bitcointalk.org/index.php?topic=1150125.0
I decided to take a look at it.

Of course it installs a miner in your computer + a keylogger. Furthermore, it calls another executable after decrypting it via RunPE. A quick scan on Malwr showed the domain where it sends the stuff:
https://malwr.com/analysis/MzdjMjlmMzBkYzVhNGY2MjljNTE2OTQyYTljOTQwYjk/

Everything was protected with ConfuserEx so that AVs don't detect most of it.
The domain is: pownedfag.pw IP: 87.208.65.27.

Take care and do not download that shit.
Regards,
BanzaiBTC
Legendary
*
Offline Offline

Activity: 1526
Merit: 1002


Chipcoin Developer


View Profile WWW
August 11, 2015, 04:22:01 PM
 #2

This is the bastard...

https://bitcointalk.org/index.php?action=profile;u=405566

At least one of his accounts


LOLLOLLOL

What a sad bastard

ocminer
Legendary
*
Offline Offline

Activity: 2688
Merit: 1240



View Profile WWW
August 11, 2015, 04:27:23 PM
 #3

Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
DebitMe
Legendary
*
Offline Offline

Activity: 2800
Merit: 1012

Get Paid Crypto To Walk or Drive


View Profile
August 11, 2015, 04:29:28 PM
 #4

Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...

It must be a bot set up to post that link on a ton of threads.  I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though.

I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%.

Get paid crypto to walk or drive. Play Cubieverse! Earn Hundreds Monthly!
https://cubieverse.onelink.me/Hakd/xoz6sp52
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 11, 2015, 04:30:17 PM
 #5

Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...

It must be a bot set up to post that link on a ton of threads.  I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though.

I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%.

I have never seen a scammer with a closed account. Maybe they want to keep them, who knows.
ocminer
Legendary
*
Offline Offline

Activity: 2688
Merit: 1240



View Profile WWW
August 11, 2015, 04:31:52 PM
 #6

Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...

It must be a bot set up to post that link on a ton of threads.  I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though.

I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%.

Same for me, reported some - nothing happened...

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
goodguyed
Sr. Member
****
Offline Offline

Activity: 388
Merit: 250

Twitter: @goodguyed


View Profile
August 11, 2015, 04:36:55 PM
 #7

I can't imagine people click on those links.

I hope people don't click on those links.

Signature for sale by owner
ocminer
Legendary
*
Offline Offline

Activity: 2688
Merit: 1240



View Profile WWW
August 11, 2015, 04:37:34 PM
 #8

I can't imagine people click on those links.

I hope people don't click on those links.

Yes they do unfortuantely.. Otherwise those scammers wouldn't invest so much energy in such stuff...

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
logocreator
Legendary
*
Offline Offline

Activity: 1134
Merit: 1000


www.cryptodesign.cc


View Profile WWW
August 11, 2015, 04:46:06 PM
 #9

it is a virus, reported a few days ago, as ocminer says nothing happend

Suntouri
Full Member
***
Offline Offline

Activity: 170
Merit: 100



View Profile
August 11, 2015, 04:47:42 PM
 #10

This is the bastard...

https://bitcointalk.org/index.php?action=profile;u=405566

At least one of his accounts


LOLLOLLOL

What a sad bastard

[img]http://puu.sh/jxHbd/f2b2976983.png[ /img]
Its a robber account
I report 3-4 message and mods dont delete it :/ please mods, ban him now
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 11, 2015, 04:57:14 PM
 #11

it is a virus, reported a few days ago, as ocminer says nothing happend

I have suspected it has more than a miner inside, I didn't run it of course. Luckily I have reported it today so that nobody falls in that shit.
djm34
Legendary
*
Offline Offline

Activity: 1400
Merit: 1050


View Profile WWW
August 11, 2015, 04:58:54 PM
 #12

actually I reported already that guy twice, the post got deleted.
But yes that guy should be banned

djm34 facebook page
BTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze
Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
badam
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
August 11, 2015, 05:00:16 PM
 #13

This is the bastard...

https://bitcointalk.org/index.php?action=profile;u=405566

At least one of his accounts


LOLLOLLOL

What a sad bastard

[img]http://puu.sh/jxHbd/f2b2976983.png[ /img]
Its a robber account
I report 3-4 message and mods dont delete it :/ please mods, ban him now

Useless. he is posting from new accounts(but still old accounts at forum) all the time. I guess the virus gets the infected ones bt account too that's how he can get old accounts to post from
djm34
Legendary
*
Offline Offline

Activity: 1400
Merit: 1050


View Profile WWW
August 11, 2015, 05:02:12 PM
 #14

Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...

It must be a bot set up to post that link on a ton of threads.  I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though.

I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%.
it isn't a bot he created a thread on the mining sub forum and locked it so no one can post

djm34 facebook page
BTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze
Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
Mickeyb
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000

Move On !!!!!!


View Profile
August 22, 2015, 05:14:38 PM
 #15

So do you need to download a software from the website www.mining.ml or is it just enough to visit this website?

Thanks!
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 22, 2015, 05:15:39 PM
 #16

So do you need to download a software from the website www.mining.ml or is it just enough to visit this website?

Thanks!

Download the software. It's simply a .NET Framework, don't worry if you haven't run it.
Mickeyb
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000

Move On !!!!!!


View Profile
August 22, 2015, 05:17:31 PM
 #17

So do you need to download a software from the website www.mining.ml or is it just enough to visit this website?

Thanks!

Download the software. It's simply a .NET Framework, don't worry if you haven't run it.

Ok, so if I just entered the site, I have nothing to worry about?

Thanks for the help!
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 22, 2015, 05:20:24 PM
 #18

So do you need to download a software from the website www.mining.ml or is it just enough to visit this website?

Thanks!

Download the software. It's simply a .NET Framework, don't worry if you haven't run it.

Ok, so if I just entered the site, I have nothing to worry about?

Thanks for the help!

Nothing to worry about. Original domain: http://www.nutrilonexport.com/
LordCoder (OP)
Hero Member
*****
Offline Offline

Activity: 712
Merit: 500


View Profile
August 29, 2015, 01:50:10 PM
 #19

That asshole hacked this account, he didn't change the password luckily. Now I have bad rep Sad
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!