Bitcoin Forum
May 14, 2024, 11:51:26 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Malicious proces on Ubuntu via crypto wallets: Rpigdnos  (Read 1097 times)
samspaces (OP)
Legendary
*
Offline Offline

Activity: 1453
Merit: 1030


View Profile
November 14, 2015, 05:14:36 PM
Last edit: November 17, 2015, 12:51:11 AM by samspaces
 #1

I've managed to clear my digital ocean droplet of this little bastard program that eats up 100% cpu and restarts itself through parent process 1:

I created another older droplet, copied the /sbin/init to the infected droplet, removed the init file, deleted the program Rpigdnos in /bin, overwrote /sbin/init with the clean version and rebooted.

Likely wallet is Rublebit. Not sure though.

17-11 Update: not a crypto wallet issue, probably.
1715687486
Hero Member
*
Offline Offline

Posts: 1715687486

View Profile Personal Message (Offline)

Ignore
1715687486
Reply with quote  #2

1715687486
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715687486
Hero Member
*
Offline Offline

Posts: 1715687486

View Profile Personal Message (Offline)

Ignore
1715687486
Reply with quote  #2

1715687486
Report to moderator
MbccompanyX
Full Member
***
Offline Offline

Activity: 182
Merit: 100

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
November 15, 2015, 09:13:53 PM
 #2

Which other wallets you have on the machine? and what let you think that rublebit is the source of the malicious process?

notabeliever
Hero Member
*****
Offline Offline

Activity: 724
Merit: 504


View Profile
November 16, 2015, 01:52:42 AM
 #3

Might be 1337 too. My cpu has been throttling for awhile and trying to isolate the issue. Rubit had too many flagged virus from virustotal so I used an exchange instead. I only install  99% of the wallets that are clean from virustotal.
LucyLovesCrypto
Sr. Member
****
Offline Offline

Activity: 414
Merit: 251


View Profile
November 16, 2015, 02:00:39 AM
 #4

Might be 1337 too. My cpu has been throttling for awhile and trying to isolate the issue. Rubit had too many flagged virus from virustotal so I used an exchange instead. I only install  99% of the wallets that are clean from virustotal.

I don't have the answer but want to say that virustotal can miss things. Use a VM unless you trust the software 100%
MbccompanyX
Full Member
***
Offline Offline

Activity: 182
Merit: 100

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
November 16, 2015, 06:59:32 AM
 #5

Might be 1337 too. My cpu has been throttling for awhile and trying to isolate the issue. Rubit had too many flagged virus from virustotal so I used an exchange instead. I only install  99% of the wallets that are clean from virustotal.

I don't have the answer but want to say that virustotal can miss things. Use a VM unless you trust the software 100%

Or use sandbox with process explorer, sometimes is even better then using a virtual machine (some viruses have part of the code made for stop the execution if launched in a virtual machine)

samspaces (OP)
Legendary
*
Offline Offline

Activity: 1453
Merit: 1030


View Profile
November 16, 2015, 01:03:22 PM
 #6

I skipped 1337 so haven't used that one. Rublebit was one of the last wallets I installed. Could also be the 'Blurry' wallet or the 'Digitalcredits' wallet.
MbccompanyX
Full Member
***
Offline Offline

Activity: 182
Merit: 100

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
November 16, 2015, 01:15:06 PM
 #7

I skipped 1337 so haven't used that one. Rublebit was one of the last wallets I installed. Could also be the 'Blurry' wallet or the 'Digitalcredits' wallet.

If possible try to make a virtual machine and see if launching those wallets on different VM one of those shows the malicious process

HeroCat
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500


View Profile
November 16, 2015, 03:23:45 PM
 #8

Yes, that's true. In Linux you can never be safe from viruses  Wink Only in Windows, you can have protection through anti virus software  Grin
MbccompanyX
Full Member
***
Offline Offline

Activity: 182
Merit: 100

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
November 16, 2015, 03:30:22 PM
 #9

Yes, that's true. In Linux you can never be safe from viruses  Wink Only in Windows, you can have protection through anti virus software  Grin

There are antiviruses even on linux but aren't so know like windows antivirus, But even mac os isn't safe from viruses at the end too

samspaces (OP)
Legendary
*
Offline Offline

Activity: 1453
Merit: 1030


View Profile
November 17, 2015, 12:49:58 AM
 #10

I skipped 1337 so haven't used that one. Rublebit was one of the last wallets I installed. Could also be the 'Blurry' wallet or the 'Digitalcredits' wallet.

If possible try to make a virtual machine and see if launching those wallets on different VM one of those shows the malicious process

I have, a few hours ago. None of the suspected wallets triggered the program.
MbccompanyX
Full Member
***
Offline Offline

Activity: 182
Merit: 100

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
November 17, 2015, 07:09:20 AM
 #11

I skipped 1337 so haven't used that one. Rublebit was one of the last wallets I installed. Could also be the 'Blurry' wallet or the 'Digitalcredits' wallet.

If possible try to make a virtual machine and see if launching those wallets on different VM one of those shows the malicious process

I have, a few hours ago. None of the suspected wallets triggered the program.

Then close the whole thread and go in the rublebit thread telling sorry for raising such thing against the dev, and anyway next time check better what you download from websites you don't know....

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!