Bitcoin Forum
May 30, 2024, 03:34:01 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Eaglecoin wallet is heavily infected with trojans!!  (Read 743 times)
jc12345 (OP)
Legendary
*
Offline Offline

Activity: 1638
Merit: 1013


View Profile
August 28, 2015, 06:00:33 PM
Last edit: August 29, 2015, 02:41:51 AM by jc12345
 #1

NBGH keep deleting my warning posts in the Eaglecoin thread and has now locked the thread at the point just after he says there is a new wallet and big news is coming. He is obviously hoping that unsuspecting people will download the infected wallet and then he steals their passwords and wallet.dat files.

Here is the Virustotal link to the wallet he posted on 25 August and judge for yourself. Be very careful of the Eaglecoin wallet and compare the SHA256 checksum to the Virustotal checksum to see if you are running an infected wallet.

Wallet updated.Big news coming for eagle very soon

https://www.virustotal.com/en/file/0f56e64231cbccdae04476b1f8e0426574e8a1908d330e0defa2212ff152a3d1/analysis/1440815970/

Original (now locked) thread. https://bitcointalk.org/index.php?topic=1104710.0
Panadacoin
Sr. Member
****
Offline Offline

Activity: 296
Merit: 251


View Profile
August 28, 2015, 06:02:22 PM
 #2

Wow if that is the real virustotal upload, that goes way beyond any false positive I have ever seen.
jc12345 (OP)
Legendary
*
Offline Offline

Activity: 1638
Merit: 1013


View Profile
August 28, 2015, 06:05:32 PM
 #3

Wow if that is the real virustotal upload, that goes way beyond any false positive I have ever seen.

It is probably the most infected I have seen so far.
SIX3P0
Sr. Member
****
Offline Offline

Activity: 247
Merit: 250



View Profile
August 28, 2015, 06:33:46 PM
 #4

more positives dont necessarily mean its more infected, just easier detected   Wink
hashmaster1
Hero Member
*****
Offline Offline

Activity: 851
Merit: 1000


Do You Even Onion Bro?


View Profile
August 28, 2015, 09:35:04 PM
 #5

This happen to me 2 weeks ago got link to get 1 week of free mining on cloud mining 5 minutes after i downloaded it all my coin from my computer wallets were stolen even the coins i had on the exchanges where stolen i had sent coins to local bitcoin they took those to ........these people are low life steeling of people that have invested money into this miners  the cost of electricity and are time  im really tiered of it now you can't even trust some Dev it getting pretty bad......this just make crypto currency look bad...Make sure before you download something to check for TROGANS .......WE NEED MORE PEOPLE LIKE.... JC12345....THANKS FOR THE WARNING.....

                                 
                  █████████████████████████████▒
               ▒███████████████████████████████▓░
             ▒████▓                         ░▓███▒░░
         ░▒▓████▓░                            ░▓███▓▓▒▒░░
▓▓▓▓▓████████▓▒               ░░░▒▒▒▒▒░         ░▒█████████▓▓▓▓▓
████████▓▒▒░              ░▒▓▓▓▒▒▒▒▒▒▒▓▓▓▓▒         ░░▒▒████████
▓██▓                   ░▒▓▓▓▒▒▒▒▒▒▒▒▒▒▒▒▒▓███▒░             ███▓
▒███                 ░▓█▓▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▓▓█████▒░         ▓▓█░
░█▓█░               ▓█▓▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▓▓▓▓▓▓█████▓██░     ▓███░
 ▓██▓             ▒██▒▒░▒▒▒▒▒▒▒░▒▒▒▒▒▒▒▒▒▒▒░▒▒░  ░▓█▓      ███▓
 ▒█▓█░           ▓█▓▒▒▒▒▒▒▒▒▒▒░▒░▒░░░░░▒▒░ ░▒░░▓███▓      ▒███▒
  █▓█▓          ▓█▓▒▓▒▒▒▒░░░░░░░░░░░░▒▓▒▒░░▒▒▓█████░      ███▓
  ▒█▓█░        ░██▓▓▒░░░░░░░░░▒▓▒░ ░░░ ░░▒▒▓▓▓▓▓█▒█░     ▓███▒
   ▓▓▓▓        ███▒░░░░░▒░░░▒▒▒▒▒░░░░░▒▒▒▒▒▒▒▒▒▓▓ █░    ▒███▒
   ░▓▓▓▓   ░▒▒ █▓▒▒▒▒▒▓▓▓▒░▒░░░░░░░▒▒▒▒▒▒▒▒▒░▒▒▓ ▒█    ░████▒
    ░▓▒▓▒ ░▓████▓▓▓▒▒▒▓▒░░░░░░░░░▒▒▒▒▒▒▒▒▒▒▒▒▒▒  ██   ░████▒
     ▒▓▓██  ▓████▓▒▒░░░░░░░░░▒▒▒▒▒▒▒▒▒▒▒░▒░▒▒░ ░██▒  ░████▒
      ▓████  ░██████▓▓▓▓▓▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒░░  ░███▓  ░████░
       ▒████   ▓█▓░█████▓▓▒▒▒▒▒▒▒▒▒▒░░░░░░▒▓████░  ▒████▒
        ░████▒  ▒░   ▒██████▓▓▓▒▒▒▒▒▒▒▓██████▓░   ▓████▒
          ████▓         ░▒▓██████████████▓░░    ░████▓
           ▒████▒                              ▓████░
             ▓████░                          ▒████▒
              ░████▓░                      ▒████▓
                ░████▓░                  ▒████▓░
                  ░████▓░              ▒████▓░
                     ░▓████▒          ▓████▒░
                       ░▒████▓░    ▒████▓▒
                          ░▓████▓▓████▓░
                             ▒█████▓░
                               ░▒▒░
✬✬✬✬✬

bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
August 29, 2015, 03:44:23 AM
 #6

Thanks for advice,  This guys now could are moving on new coins. Anyway always backup you wallets and lock it, When you have noted that you wallet was stolen, Try of use another computer to unlock you wallet and transfer funds to another adress more safe, it will give less time to an attack of brute force to found the pass.
jc12345 (OP)
Legendary
*
Offline Offline

Activity: 1638
Merit: 1013


View Profile
August 29, 2015, 06:04:49 AM
 #7

Thanks for advice,  This guys now could are moving on new coins. Anyway always backup you wallets and lock it, When you have noted that you wallet was stolen, Try of use another computer to unlock you wallet and transfer funds to another adress more safe, it will give less time to an attack of brute force to found the pass.

My advice would be:

1) Always install all wallets for coins on a standalone system or in a sandbox environment.
2) Always move coins to offline wallets (cold storage) and keep only a minimum in a hotfile. A Hotfile is the wallet.dat currently on your PC in the normal location ..\roaming\coinname\wallet.dat | ~/.coinname/wallet.dat. Offline or cold storage is when you copy your main wallet.dat with your coins in it to a USB stick/(s) and remove the wallet.dat from your PC. Offline or cold storage is also sending your coins to a paper wallet. This is problematic through for staking coins and that is why I prefer POW coins. if you do have staking coins, put them on a dedicated Raspbery Pi that runs Linux.
3) If you are uncomfortable with a Windows wallet then don't use a Windows wallet but compile and use a Linux wallet.
4) If anyone quotes a wallet download link, make sure that the quoted link still matches and that the checksums are the same.
5) Always first run the wallet through Virustotal.com to get some level of assurance.
6) After 2 days or so run a wallet through Virus total again and re-analyse to see if the scan engines pick anything up after having worked since.
7) Install software that scramble the data between your keyboard and the operating system so that keylogging malware records garbage and attackers cannot steal your coins because they cannot unlock your wallet.dat with the "garbage" password.
8.) Always encrypt your wallet.dat with a long password of 20+ characters consisting of uppercase and lowercase letters, digits and non-alphabetic characters like * or &.

What is interesting is that this particular Eaglecoin wallet only had one obscure detection of a suspicious file on Virustotal when it released a few days back. It was strange enough though to raise the alarm bells with me. After first submission, the AV scan engines then started working on it and by 2 days later, almost half of them have classified the Trojan/(s) and were able to detect it accurately. This could happen because it is possible to obfuscate a virus or to change it slightly so that attack signatures do not pick it up. Sometimes malware can also fool a sandbox behavior analysis. It is important though to get a file into Virustotal asap so that the code is logged.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!