LordCoder (OP)
|
|
August 11, 2015, 04:18:11 PM Last edit: August 11, 2015, 04:34:11 PM by LordCoder |
|
I do not know where to post this, so please move if it's the wrong place After I saw the software here: https://bitcointalk.org/index.php?topic=1150125.0I decided to take a look at it. Of course it installs a miner in your computer + a keylogger. Furthermore, it calls another executable after decrypting it via RunPE. A quick scan on Malwr showed the domain where it sends the stuff: https://malwr.com/analysis/MzdjMjlmMzBkYzVhNGY2MjljNTE2OTQyYTljOTQwYjk/Everything was protected with ConfuserEx so that AVs don't detect most of it. The domain is: pownedfag.pw IP: 87.208.65.27. Take care and do not download that shit. Regards,
|
|
|
|
|
ocminer
Legendary
Offline
Activity: 2688
Merit: 1240
|
|
August 11, 2015, 04:27:23 PM |
|
Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...
|
suprnova pools - reliable mining pools - #suprnova on freenet https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
|
|
|
DebitMe
Legendary
Offline
Activity: 2800
Merit: 1012
Get Paid Crypto To Walk or Drive
|
|
August 11, 2015, 04:29:28 PM |
|
Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...
It must be a bot set up to post that link on a ton of threads. I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though. I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%.
|
|
|
|
LordCoder (OP)
|
|
August 11, 2015, 04:30:17 PM |
|
Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...
It must be a bot set up to post that link on a ton of threads. I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though. I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%. I have never seen a scammer with a closed account. Maybe they want to keep them, who knows.
|
|
|
|
ocminer
Legendary
Offline
Activity: 2688
Merit: 1240
|
|
August 11, 2015, 04:31:52 PM |
|
Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...
It must be a bot set up to post that link on a ton of threads. I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though. I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%. Same for me, reported some - nothing happened...
|
suprnova pools - reliable mining pools - #suprnova on freenet https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
|
|
|
goodguyed
Sr. Member
Offline
Activity: 388
Merit: 250
Twitter: @goodguyed
|
|
August 11, 2015, 04:36:55 PM |
|
I can't imagine people click on those links.
I hope people don't click on those links.
|
Signature for sale by owner
|
|
|
ocminer
Legendary
Offline
Activity: 2688
Merit: 1240
|
|
August 11, 2015, 04:37:34 PM |
|
I can't imagine people click on those links.
I hope people don't click on those links.
Yes they do unfortuantely.. Otherwise those scammers wouldn't invest so much energy in such stuff...
|
suprnova pools - reliable mining pools - #suprnova on freenet https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
|
|
|
logocreator
Legendary
Offline
Activity: 1134
Merit: 1000
www.cryptodesign.cc
|
|
August 11, 2015, 04:46:06 PM |
|
it is a virus, reported a few days ago, as ocminer says nothing happend
|
|
|
|
Suntouri
|
|
August 11, 2015, 04:47:42 PM |
|
Its a robber account I report 3-4 message and mods dont delete it :/ please mods, ban him now
|
|
|
|
LordCoder (OP)
|
|
August 11, 2015, 04:57:14 PM |
|
it is a virus, reported a few days ago, as ocminer says nothing happend
I have suspected it has more than a miner inside, I didn't run it of course. Luckily I have reported it today so that nobody falls in that shit.
|
|
|
|
djm34
Legendary
Offline
Activity: 1400
Merit: 1050
|
|
August 11, 2015, 04:58:54 PM |
|
actually I reported already that guy twice, the post got deleted. But yes that guy should be banned
|
djm34 facebook pageBTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
|
|
|
badam
|
|
August 11, 2015, 05:00:16 PM |
|
Its a robber account I report 3-4 message and mods dont delete it :/ please mods, ban him now Useless. he is posting from new accounts(but still old accounts at forum) all the time. I guess the virus gets the infected ones bt account too that's how he can get old accounts to post from
|
|
|
|
djm34
Legendary
Offline
Activity: 1400
Merit: 1050
|
|
August 11, 2015, 05:02:12 PM |
|
Thanks for posting the info, I really wonder what the Mods are doing ... Usually they ban/delete everything but those malware attempts seem to stay forever...
It must be a bot set up to post that link on a ton of threads. I have seen it posted just randomly around and always report the post, not sure if it ever gets banned though. I had reported a bunch of them a few days ago, and the admins must have ignored it because it brought my accuracy down almost 10%. it isn't a bot he created a thread on the mining sub forum and locked it so no one can post
|
djm34 facebook pageBTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
|
|
|
Mickeyb
|
|
August 22, 2015, 05:14:38 PM |
|
So do you need to download a software from the website www.mining.ml or is it just enough to visit this website? Thanks!
|
|
|
|
LordCoder (OP)
|
|
August 22, 2015, 05:15:39 PM |
|
So do you need to download a software from the website www.mining.ml or is it just enough to visit this website? Thanks! Download the software. It's simply a .NET Framework, don't worry if you haven't run it.
|
|
|
|
Mickeyb
|
|
August 22, 2015, 05:17:31 PM |
|
So do you need to download a software from the website www.mining.ml or is it just enough to visit this website? Thanks! Download the software. It's simply a .NET Framework, don't worry if you haven't run it. Ok, so if I just entered the site, I have nothing to worry about? Thanks for the help!
|
|
|
|
LordCoder (OP)
|
|
August 22, 2015, 05:20:24 PM |
|
So do you need to download a software from the website www.mining.ml or is it just enough to visit this website? Thanks! Download the software. It's simply a .NET Framework, don't worry if you haven't run it. Ok, so if I just entered the site, I have nothing to worry about? Thanks for the help! Nothing to worry about. Original domain: http://www.nutrilonexport.com/
|
|
|
|
LordCoder (OP)
|
|
August 29, 2015, 01:50:10 PM |
|
That asshole hacked this account, he didn't change the password luckily. Now I have bad rep
|
|
|
|
|