Bitcoin Forum
May 24, 2024, 10:36:07 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Hacked account spreading malware - mizna  (Read 1001 times)
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2884
Merit: 2327


View Profile
August 22, 2015, 03:06:45 PM
Last edit: August 24, 2015, 03:20:41 PM by Quickseller
 #1

The account popadrac is posting links containing a mining [dot] ml (<<-- caution malware) referral link in various threads.

It looks like he has posted it 10 times so far and is replying to threads instead of creating new ones as he was previously.
this was resolved

Now Mizna is doing the same thing.
everaja
Hero Member
*****
Offline Offline

Activity: 490
Merit: 500


~ScapeGoat~


View Profile
August 22, 2015, 03:18:24 PM
 #2

The account popadrac is posting links containing a mining [dot] ml (<<-- caution malware) referral link in various threads.

It looks like he has posted it 10 times so far and is replying to threads instead of creating new ones as he was previously.

I guess there is a Bunch of People behind these Stuffs as before few days back i saw numerous Sr.Members account Posting this Type of [dot] ml link , This link contain cookie stealing Virus.
They were Posting from Numerous Sr.Members accounts in Various sections and Just Locking the Thread so that no one could comment in That.

I guess there is No hacked Sr.Member account with Them Now , so they are Now Using Members Account and i can guarantee that they have been getting a good Profit from Here that why they are not quitting.

hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
August 22, 2015, 03:42:43 PM
 #3

 Been handling what I can.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2884
Merit: 2327


View Profile
August 24, 2015, 03:19:23 PM
 #4

There is another one - https://bitcointalk.org/index.php?action=profile;u=405490 Mizna

He has made 18 posts so far with referral spam/malware. I will update the OP
bram_vnl
Legendary
*
Offline Offline

Activity: 1148
Merit: 1000


View Profile
August 24, 2015, 03:32:43 PM
 #5

go to this topic for new spam/malware members https://bitcointalk.org/index.php?topic=1149215.msg12229060#msg12229060
Cyrus
Ninja
Administrator
Legendary
*
Offline Offline

Activity: 3780
Merit: 2952



View Profile
August 24, 2015, 04:04:08 PM
 #6


Handled everything that I could, reported some of his other spam posts and reported him in the Staff forum also.
Even temporarily moved a thread started by a newbie to a section I moderate just so I could delete more of his posts.
This is maybe the 5th or so hacked account spamming this site.
Unfortunately theymos doesn't blacklist URLs that often and I could only handle the reports in the Economy(minus Speculation) forum.

Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2884
Merit: 2327


View Profile
August 24, 2015, 04:08:57 PM
 #7


Handled everything that I could, reported some of his other spam posts and reported him in the Staff forum also.
Even temporarily moved a thread started by a newbie to a section I moderate just so I could delete more of his posts.
This is maybe the 5th or so hacked account spamming this site.
Unfortunately theymos doesn't blacklist URLs that often and I could only handle the reports in the Economy(minus Speculation) forum.
Good job, and thanks for handling those posts/threads.

Quote
This is maybe the 5th or so hacked account spamming this site.
It has been more then that, I would guess the number is closer to 10, but if you count other sites the hacker owns then it would be a lot more. The hacker is apparently a serial scammer
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
August 24, 2015, 04:53:35 PM
 #8

There's surely been more than ten of them. We were getting a couple daily a week or two ago but they seem to have slowed down now. Was out all day today but looks like cyrus handled all the ones I usually do. Easily handled over 500 reports on those infected accounts alone this month.

Wonder if this is his new line of attack:


Url was for bitmain.co not .com (which I removed).

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2884
Merit: 2327


View Profile
August 24, 2015, 05:30:12 PM
 #9

Wonder if this is his new line of attack:


Url was for bitmain.co not .com (which I removed).
I am not sure if that is the same person or not, as this does not match his MO. However that is defiantly someone who is trying to steal money by posting phishing links. A quick look at the site on tor does not reveal anything that it tries to get you to download so I don't think it is trying to spread malware. It did let me "login" to "my" bitmaintech account using random letters as both my email and password (I didn't even enter a "@" symbol) to purchase an S5+ Roll Eyes
Pathi
Sr. Member
****
Offline Offline

Activity: 244
Merit: 250



View Profile
August 24, 2015, 07:53:32 PM
 #10

As far as I can tell Bitmain does NOT have any s5+ in stock either.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!