Bitcoin Forum
November 11, 2024, 05:38:21 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 »  All
  Print  
Author Topic: Bitcoin Malware  (Read 4056 times)
nero987
Sr. Member
****
Offline Offline

Activity: 259
Merit: 250


View Profile
September 01, 2015, 12:41:39 PM
 #41

Do any of the popular virus scanners detect this?

If the particular version of the malware you received is not yet flagged by your av: No it doesn't.

This is arround for some time already...
It first came up on Evo market arround 1 month before the exit scam.
I have the source code of v1.3 here.
Before you compile the malware you set some parameters, which include the process name.
In Snorek's "examples" its Chrome32.exe or AcroRd32.exe, but it can be literally everything.

About anti malware:
The program does not make any connection to the internet, for this reason it is almost never picked up by anti-virus/malware software.
When a particular compilation of the malware (with particular process name) is reported to an antivirus database, only that version will be picked up by av's...
There are some av's that notice that part of the code is comparable to know malware, but thats only a minority of the av's....


damn, practice your english nero!

edit: I'm not selling/sharing the source code, neither sharing any detailled information how it actually works!

So can someone tell me what the source of the malware is? Is it something that infects chrome? In that case im safe? I use Mozilla firefox. Thanks for the heads up anyway.

It has nothing to do with chrome itself. The first version of this malware that was sold advised to use "chrome.exe" as process name, because it would look least suspicious (as long as you do have chrome on your pc Tongue).
Meanwhile there are dozens of "new" versions of this malware with other process names then "chrome.exe".
This malware is mostly injected in a pdf!

The copied address gets replaced 5-15% of the times an adress is copied.
The first 3-6 characters of the "new" address will be the same as the first characters of the originally copied address.

It is hard to get picked up by av's just because the malware doesn't connect to the internet...
wearehatetherules
Full Member
***
Offline Offline

Activity: 195
Merit: 100

★YoBit.Net★ 200+ Coins Exchange & Dice


View Profile
September 05, 2015, 04:45:40 AM
 #42

i never heard before about this,it that reallly exist?

ranochigo
Legendary
*
Offline Offline

Activity: 3038
Merit: 4420


Crypto Swap Exchange


View Profile
September 05, 2015, 07:24:56 AM
 #43

So can someone tell me what the source of the malware is? Is it something that infects chrome? In that case im safe? I use Mozilla firefox. Thanks for the heads up anyway.

It has nothing to do with chrome itself. The first version of this malware that was sold advised to use "chrome.exe" as process name, because it would look least suspicious (as long as you do have chrome on your pc Tongue).
Meanwhile there are dozens of "new" versions of this malware with other process names then "chrome.exe".
This malware is mostly injected in a pdf!

The copied address gets replaced 5-15% of the times an adress is copied.
The first 3-6 characters of the "new" address will be the same as the first characters of the originally copied address.

It is hard to get picked up by av's just because the malware doesn't connect to the internet...
Antiviruses usually check the application's signature and match it against their database. If it matches, the antivirus would flag it. This would require you to have the latest database download. I have to say the virus would be quite intensive to carry out on a large scale. If the address gets replaced with an address that has a first few address identical to it, they need to generate a large amount of vanity addresses or even use the victim's computer to generate one and send the private key to the server. This has to be done in a fast pace unless a fake lag can be implemented when the address is being paste.

Antivirus won't be foolproof and people can use crypter to avoid detections by antiviruses.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Hopalong
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
September 05, 2015, 08:20:01 AM
 #44

i would love to use linux but my wifi stick doesnt have the drivers for linux

I bet there are drivers around. Sometimes you have to search to find out what hardware you have and not what it is labeled with.

On my reserve laptop the wifi use intel drivers in windows but it was produced by broadcom so i had to get broadcom drivers to get it working in linux.


About linux security...   I have an old laptop with ubuntu.  It is formated corectly with a partisjon for each user level and cryptated. I have lost the password and it is impossible to get in. No live cd can start and it is no way to get to the disks. Even a mini linux on a usb stick cant read the disks.
mallard
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
September 05, 2015, 09:19:04 AM
 #45

i would love to use linux but my wifi stick doesnt have the drivers for linux

I bet there are drivers around. Sometimes you have to search to find out what hardware you have and not what it is labeled with.

On my reserve laptop the wifi use intel drivers in windows but it was produced by broadcom so i had to get broadcom drivers to get it working in linux.


About linux security...   I have an old laptop with ubuntu.  It is formated corectly with a partisjon for each user level and cryptated. I have lost the password and it is impossible to get in. No live cd can start and it is no way to get to the disks. Even a mini linux on a usb stick cant read the disks.

Do you need to recover the files, or do you just want the laptop working again?
You should be able to just use a program like dd to clear out the disk, and then you will be able to install an operating system again.
RealBitcoin
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1009


JAYCE DESIGNS - http://bit.ly/1tmgIwK


View Profile
September 05, 2015, 01:12:30 PM
 #46

Linux.

No anti-this and anti-that software. Ditch Windows and use Linux, you'll avoid most of these types of attacks.
If you are looking for a linux version that has a windows feel I suggest Linux Mint, you can use wine for most windows programs but games have a lot of compatibility issues.

Don't forget linux is free :http://www.linuxmint.com/

Is linuxmint more secure than ubuntu?

What are the differences between the 2?

What about keyloggers, webcam trojans, clipboard stealers, kernel malware and screen capture malware?

Hopalong
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
September 05, 2015, 01:56:06 PM
 #47

i would love to use linux but my wifi stick doesnt have the drivers for linux

I bet there are drivers around. Sometimes you have to search to find out what hardware you have and not what it is labeled with.

On my reserve laptop the wifi use intel drivers in windows but it was produced by broadcom so i had to get broadcom drivers to get it working in linux.


About linux security...   I have an old laptop with ubuntu.  It is formated corectly with a partisjon for each user level and cryptated. I have lost the password and it is impossible to get in. No live cd can start and it is no way to get to the disks. Even a mini linux on a usb stick cant read the disks.

Do you need to recover the files, or do you just want the laptop working again?
You should be able to just use a program like dd to clear out the disk, and then you will be able to install an operating system again.

Everything important was backed up on an external disk so my data was safe. I have not checked if gparted can read the partisions yet but i think it should. I do have a bit of fun trying to get acces to the disks.

I have tried to secure a disk in windows but every live cd was able to read it. Dont get why linux is so much better at this.
mallard
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
September 05, 2015, 02:59:38 PM
 #48

Linux.

No anti-this and anti-that software. Ditch Windows and use Linux, you'll avoid most of these types of attacks.
If you are looking for a linux version that has a windows feel I suggest Linux Mint, you can use wine for most windows programs but games have a lot of compatibility issues.

Don't forget linux is free :http://www.linuxmint.com/

Is linuxmint more secure than ubuntu?

What are the differences between the 2?

What about keyloggers, webcam trojans, clipboard stealers, kernel malware and screen capture malware?

Linux Mint is based on Ubuntu.
There isn't much difference between the two.
confirmation120
Full Member
***
Offline Offline

Activity: 224
Merit: 100



View Profile
September 05, 2015, 04:22:56 PM
 #49

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley
Didn't know this kind of malware exists. I need to check and scan my laptop right away after reading this
seVell
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
September 09, 2015, 11:40:38 PM
 #50

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley

it is safer to store your coins on a hardware wallet:

https://bitcointalk.org/index.php?topic=899253.0

Doesn't this malware work even if you use a Trezor for example? I guess that people should be always careful and double check. MyTrezor Web wallet works in the browser as well.

The truth of the matter is that everybody should be double checking are addresses changed. If anybody  can have a copy of this malware for a $1, this means that this malware can become very widespread.

Not to mention that you have to trust the hardware manufacturer and the seller and probably other middle-mans.
Remember remember the 5th of November
Legendary
*
Offline Offline

Activity: 1862
Merit: 1011

Reverse engineer from time to time


View Profile
September 10, 2015, 01:23:53 AM
 #51

Chrome is the malware.


it seems logical ...  Grin

You made me doublecheck Smiley
As usual, the malware seems to be using names quite similar with known software.
The normal browser is chrome.exe, not chrome32.
I guess that the same story goes to acrobat reader too, but since I don't use it I cannot check.


But really, the ones who run windoze with no antivirus on... they just ask for it.
That's very clever. Since Chrome spawns multiple instances of itself, it can be very easy to disguise a process with the same name, nobody will be any wiser.

BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
Kakmakr
Legendary
*
Offline Offline

Activity: 3542
Merit: 1965

Leading Crypto Sports Betting & Casino Platform


View Profile
September 10, 2015, 06:02:30 AM
 #52

Just check the address after you pasted it, and you would be fine.  Wink I have 1 FREE anti-virus software package and 1 Full commercial version installed on one computer, and I have had no problems at all so far. < Avast & Kaspersky > Luckily these two has not clashed, because they usually do.

Keep some honey traps around to trigger flags when possible hacks are being done on you. <Small amounts of coins in wallets, easily accessible> When they are empty and you have not done that, you know you are compromised.   

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Q7
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


View Profile WWW
September 10, 2015, 10:14:42 AM
 #53

If you can afford it, get two pc. I have with myself one with a lower spec which is connected to the internet all the time and i even use it for installing untrusted new software. The other one is basically most of the time offline and no other software installed in it except browsers, together with my hot wallet

pooya87
Legendary
*
Offline Offline

Activity: 3626
Merit: 11027


Crypto Swap Exchange


View Profile
September 10, 2015, 11:50:28 AM
 #54

If you can afford it, get two pc. I have with myself one with a lower spec which is connected to the internet all the time and i even use it for installing untrusted new software. The other one is basically most of the time offline and no other software installed in it except browsers, together with my hot wallet


you don't need to spend that much in order to have a secure environment that you can safely install and use a bitcoin wallet.
all you need is a USB disk which is super cheep , and linux that you can download free (like Ubuntu).

1) make persistent live linux on the USB disk
2) change a couple of settings so that it would never connect to network.
3) install your favorite bitcoin wallet

**) don't forget to check the signature of both linux and bitcoin wallet

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
JohnBelfast
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
September 10, 2015, 11:51:38 AM
 #55

Most alt coin wallets have some sort of virus in it. Go to altcoin discussion and you wil find a thread which highlights all the coins with viruses and exposed them with code refernces
zero01
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
September 10, 2015, 12:29:44 PM
 #56

it happened to me about a hour ago but heres a guide on how to get rid of it if it is on your pc
10
Remove the malware
Finally remove it from your computer:
1.
Start Windows Task Manager and terminate the Chrome32.exe or
AcroRd32.exe process!
2.
Go to %appdata% in your file browser.
3.
Delete AppData/Roaming/Adobe (x86) folder.
4.
Delete AppData/Local/Google (x86) folder.
If you don't terminate the malware manually, as it is described
in the first point you can't delete one of the folder.
If you've deleted the Adobe folder it won't start again on your
computer, so you're good, but to completly remove it you have to
do one more thing:

Start the Registry Editor (regedit) and delete our software from
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n"
If you don't find it, check HKEY_LOCAL_MACHINE instead of
HKEY_CURRENT_USER


hope it helps this malware is being sold for $1.10 in bitcoin

The information that is helpful friend
I hope with this information, our friends the others do not get bitcoin  malware
RealBitcoin
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1009


JAYCE DESIGNS - http://bit.ly/1tmgIwK


View Profile
September 10, 2015, 04:21:18 PM
 #57

it happened to me about a hour ago but heres a guide on how to get rid of it if it is on your pc
10
Remove the malware
Finally remove it from your computer:
1.
Start Windows Task Manager and terminate the Chrome32.exe or
AcroRd32.exe process!
2.
Go to %appdata% in your file browser.
3.
Delete AppData/Roaming/Adobe (x86) folder.
4.
Delete AppData/Local/Google (x86) folder.
If you don't terminate the malware manually, as it is described
in the first point you can't delete one of the folder.
If you've deleted the Adobe folder it won't start again on your
computer, so you're good, but to completly remove it you have to
do one more thing:

Start the Registry Editor (regedit) and delete our software from
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n"
If you don't find it, check HKEY_LOCAL_MACHINE instead of
HKEY_CURRENT_USER


hope it helps this malware is being sold for $1.10 in bitcoin

This virus is just easier to bypass if you just encrypt your clipboard. Its a clipboard virus so if anything tries to modify it, it will be signalled as a modified encryption cant be decrypted after.

There are many tools that can help you with that, so you will be perfectly protected agains all kinds of clipboard attacks.

balvio
Hero Member
*****
Offline Offline

Activity: 1437
Merit: 550


XVP AMBASSADOR


View Profile
May 23, 2016, 12:52:58 PM
 #58

thank you for posting such things, I am a newbie so I find them useful

Viyamore
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500


View Profile
May 23, 2016, 01:04:30 PM
 #59

Thank you also for these tutorial information ..so many viruses now are scatteeing on internet ,sometimes google if i open these forum ,virus on battery  . I do close it always not cleaning then if i will clean its recommend an app to download and to install i think it is a propaganda or tactics for them to use the application to earn money.

But i don't encountered yet that bitcoin malwares i think my malwares is on browser.


                 ▄▄▄██████████████████▄▄▄
            ▄▄██▀▀▀▀▀███████████████████████▄▄
        ▄▄███▀   ▄▄▄   ▀████████████████████████▄▄
     ▄██████  ▄███████▄  ▀██████████████████▀▀▀█████▄
   ▄███████    ███▀▀ ██    ███████████  ███▀  ▄███████▄
  █████████▄  ▄█▀  ▄███    ██████████  ▄██  ▄███████████
 ██████████████▀  ████▀   ▄██▀▀▀████  ▄████▀  ███████████
██████████████▀  ▄███▀   ▄█▀  ▄▄ ██▀ ▄█  ██  █████████████
██████████████   ▀     ▄██▀  ▄█  █▀  █   █▀▄  ▀███████████
█████████████▀  ▄███▄  ▀██   ██ ▄▄▄  █▀ ▄▄▀█▄  ▀▄█████████
█████████████   █████   ▀██▄ ▀▄████▄  ▄███▄▀  ▄███████████
 █████   ▀██▀  ▄█████    █▀▀█████████████████▀███████████
  ████   ▄█▀   █████    ██ ▀▄█▀▄▄▀█ ▀▄▀█▀▄▀ █▀█ ▀▄██████
   ▀███▄▄   ▄█▄ ▀▀     ███ █ █ ▄▄▄█  █ █ █  █ █ ██████▀
     ▀██████████▄▄▄▄▄█████▄█▄██▄▄██ █▄███▄█▄█▄█▄████▀
        ▀▀██████████████████████████████████████▀▀
            ▀▀██████████████████████████████▀▀
                 ▀▀▀██████████████████▀▀▀
      ..Powered by..
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
|
|
|
|

   ▀██▄       ▀████▄
▄    ▀██          ▀██▄
██▄ ▄███         ▄█████▄▄
 ▀███████▄     ▄██▀ ▀▀████
      ▀████▄ ▄██▀     ▀█▀
        ▀████▄
        ▄█▀████▄
      ▄███▄▀▀████▄
    ▄████▀    ▀████▄
  ▄████▀        ▀██▀█▄
  ▀██▀            ▀██▀
Gaugh
Full Member
***
Offline Offline

Activity: 135
Merit: 100


View Profile
May 23, 2016, 01:16:38 PM
 #60

Most alt coin wallets have some sort of virus in it. Go to altcoin discussion and you wil find a thread which highlights all the coins with viruses and exposed them with code refernces



Well, an altcoin paper wallet cannot have a virus in it. Undecided
Pages: « 1 2 [3] 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!