Bitcoin Forum
May 08, 2024, 01:55:00 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Infecting people with fake "Darkwallet"  (Read 1964 times)
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
December 29, 2015, 11:55:21 AM
 #1

I just wanted to give you a heads up guys , we all know that Darkwallet is not fully funded and developers dropped the project , I noticed since yesterday that there is few posts about it but it's not the same wallet obviously ...

Someone probably bought the domain (fake) just to scam and infect people : Darkwallet.co while the real domain is : Darkwallet.is
Darkwallet.co executable : https://www.virustotal.com/pt/file/3a5474cdc3bd26746686f11c67e9b008911d8f1e4432cb746564969082b3745a/analysis/1451326638/ (thanks to pedrog for checking)

Here are few posts :

https://bitcointalk.org/index.php?topic=1305921.0
https://bitcointalk.org/index.php?topic=1306144.msg13375884#msg13375884
https://bitcointalk.org/index.php?topic=1307436.msg13385072#msg13385072
https://bitcointalk.org/index.php?topic=1307430.msg13385011#msg13385011
https://bitcointalk.org/index.php?topic=1306144.msg13375884#msg13375884

Stay safe and don't download it or even visit the website .

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
1715176500
Hero Member
*
Offline Offline

Posts: 1715176500

View Profile Personal Message (Offline)

Ignore
1715176500
Reply with quote  #2

1715176500
Report to moderator
1715176500
Hero Member
*
Offline Offline

Posts: 1715176500

View Profile Personal Message (Offline)

Ignore
1715176500
Reply with quote  #2

1715176500
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715176500
Hero Member
*
Offline Offline

Posts: 1715176500

View Profile Personal Message (Offline)

Ignore
1715176500
Reply with quote  #2

1715176500
Report to moderator
1715176500
Hero Member
*
Offline Offline

Posts: 1715176500

View Profile Personal Message (Offline)

Ignore
1715176500
Reply with quote  #2

1715176500
Report to moderator
1715176500
Hero Member
*
Offline Offline

Posts: 1715176500

View Profile Personal Message (Offline)

Ignore
1715176500
Reply with quote  #2

1715176500
Report to moderator
mexxer-2
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1005


4 Mana 7/7


View Profile
December 29, 2015, 11:59:51 AM
Last edit: December 29, 2015, 12:15:43 PM by mexxer-2
 #2

-snip-
Thanks for the warning(even though I don't use altcoinsseems bitcoin related, haven't used it anyway). Another thing that I might add is report such posts to the moderators using the (similarly named) feature, with the comment as "Malware , virustotal link: LINK", as any posts containing malware are not accepted in the forum.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
December 29, 2015, 12:13:23 PM
 #3

-snip-
Thanks for the warning(even though I don't use altcoins). Another thing that I might add is report such posts to the moderators using the (similarly named) feature, with the comment as "Malware , virustotal link: LINK", as any posts containing malware are not accepted in the forum.

I usually report them as well, I didnt get around to it yet.

Darkwallet is no alt coin though, its a chrome plugin wallet for bitcoin that focused heavily on anonymity (build in stealth addresses (can be reused without compromising privacy) and coinjoin sending). One of the main devs has vanished a while back, I honestly though the wallet is back. Either with a fork or the original dev team. Didnt have the time to check though.


Im not really here, its just your imagination.
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
January 09, 2016, 08:37:22 AM
 #4

It seems like are back to work : https://bitcointalk.org/index.php?topic=1320350.new#new

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 09, 2016, 09:14:51 AM
 #5

Best "news" money can buy, I yelled at them on twitter, maybe it will do something. Does "themerkle" have a thread and/or account here?

Edit: they also have a mail, can anyone inform the reddit sheep? -> https://www.reddit.com/r/Bitcoin/comments/404hg4/dark_wallet_new_amazing_updates_2016_most/

Im not really here, its just your imagination.
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
January 09, 2016, 09:23:20 AM
 #6

Best "news" money can buy, I yelled at them on twitter, maybe it will do something. Does "themerkle" have a thread and/or account here?

Yes It seems like they do :

Signature campaign : https://bitcointalk.org/index.php?topic=1249297.0
User : https://bitcointalk.org/index.php?action=profile;u=534999

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 09, 2016, 09:27:50 AM
 #7

Left them a negative rating for now.

link to article: http://themerkle.com/news/dark-wallet-offers-privacy-and-anonymity-to-bitcoin-users/
archive: https://archive.is/s9I2a

Im not really here, its just your imagination.
Xmaseven
Full Member
***
Offline Offline

Activity: 124
Merit: 100


View Profile
January 09, 2016, 09:56:45 AM
 #8

I just wanted to give you a heads up guys , we all know that Darkwallet is not fully funded and developers dropped the project , I noticed since yesterday that there is few posts about it but it's not the same wallet obviously ...

Someone probably bought the domain (fake) just to scam and infect people : Darkwallet.co while the real domain is : Darkwallet.is
Darkwallet.co executable : https://www.virustotal.com/pt/file/3a5474cdc3bd26746686f11c67e9b008911d8f1e4432cb746564969082b3745a/analysis/1451326638/ (thanks to pedrog for checking)

Here are few posts :

https://bitcointalk.org/index.php?topic=1305921.0
https://bitcointalk.org/index.php?topic=1306144.msg13375884#msg13375884
https://bitcointalk.org/index.php?topic=1307436.msg13385072#msg13385072
https://bitcointalk.org/index.php?topic=1307430.msg13385011#msg13385011
https://bitcointalk.org/index.php?topic=1306144.msg13375884#msg13375884

Stay safe and don't download it or even visit the website .

why not post also in scam accusation board? is a scam attempt!
No all users read this forum section Sad
S3cco
Hero Member
*****
Offline Offline

Activity: 2036
Merit: 528


❤ Bitcoin Garden


View Profile WWW
January 09, 2016, 10:35:18 AM
 #9

Stay safe and don't download it or even visit the website .

Thanks for the alert. A similar post appeared on Bitcoin Garden, too: http://bitcoingarden.tk/forum/index.php?topic=6054.0

I did not delete the original post, I just deactivated the link and moved the topic in the scam board, adding a comment. When I saw that something immediately let me think there's was something wrong there. I think it could be educative leaving that post alive to show how a scam post looks like.

This is not the first time somebody try to post a fake op to convince people downloading malware. It is very common to see this kind of posts for software claiming to be super bitcoin miners (allowing to solo mine btc on normal pc) or bitcoin private key generators (from public addresses). Needless to say this kind of software cannot exist.

My suggestion is to mentally count from 1 to 1,000,000 before downloading binary files from a source you don't know. Do some google research instead, the truth will emerge in short time.

Hacker, Pirate, Milf Hunter, Owner of Bitcoin Garden
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
January 09, 2016, 09:45:11 PM
 #10

Nothing special when it comes to malware. Just report and we will nuke them on sight. I've already nuked several myself.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 09, 2016, 09:54:07 PM
 #11

Just got a message from them on twitter, the article was updated to show the proper link.

Post on reddit was removed as well.

Im not really here, its just your imagination.
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
January 10, 2016, 07:28:45 AM
 #12

Nothing special when it comes to malware. Just report and we will nuke them on sight. I've already nuked several myself.

Posts were already removed by mods already , I posted something else related to that . I suppose you can only nuke someone on the forums and not on blogs and newspaper websites .



Just got a message from them on twitter, the article was updated to show the proper link.

Post on reddit was removed as well.


I'm going to close scam accusations topic for now then , In case they come back with that kind of stuff I will open it once again .

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
OmegaStarScream (OP)
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
January 30, 2016, 06:54:25 AM
 #13

It seems like they are back . See this user : https://bitcointalk.org/index.php?action=profile;u=748438;sa=showPosts , he is spamming in different sections .

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
deepceleron
Legendary
*
Offline Offline

Activity: 1512
Merit: 1032



View Profile WWW
January 30, 2016, 07:59:20 AM
 #14

It's much better to just go after the resources of the person directly.

The registrar of the .co TLD is:
http://www.cointernet.com.co/

Their US parent company is:
https://www.neustar.biz/services/domain-name-registry

I'll bet you can get the domain pulled for abuse of the registrar's policies.

http://www.cointernet.com.co/politicas-procedimientos - 4.4 of Política de Administración del Dominio .CO states that the domain shall not be used for any illegal purposes.

Then go after the hosting, the cloud proxy account, etc. Get them to turn over account details.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!