Bitcoin Forum
June 28, 2024, 02:12:47 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: XXXNEWCOIN TROJAN  (Read 1250 times)
jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
March 09, 2013, 08:03:03 AM
 #1

At what point will someone relaase as "new coin" that is easily mined, but contains a trojan/virii of some sort that get you keys if not air gaped, or does something to your control of you computer....


eg...terracoins? has anyone even looked at he source code?Huh?

people just install this stuff hopign to get lots of coins early....



its going to happen at some point

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
Mike Christ
aka snapsunny
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003



View Profile
March 09, 2013, 08:04:07 AM
 #2

I keep thinking the same.  But I'm more worried a BTC client will have a backdoor.  Always use open source Grin

jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
March 09, 2013, 08:45:38 AM
 #3

I keep thinking the same.  But I'm more worried a BTC client will have a backdoor.  Always use open source Grin

are there enough people checking the open source though, i mean bitcoin qt yeah

but what about multibit (think probably)

terracoin nope I doubt it

setting a mining right up is one thing, but being a good programmer is another

being a good C++/Java programmer with crypto background to really take the time to look at the code, very few people here.

hmmm.....terra coin website screams doggey to me.

(disclosure I purchased a few 100 TC on VIR)

so I am talking myself down here

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
Severian
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
March 09, 2013, 08:48:06 AM
 #4

Or a fake wallet.

sourceforge.net/projects/bitboom/

I'm glad to see 0 downloads anyway.
jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
March 09, 2013, 08:51:54 AM
 #5

Or a fake wallet.

sourceforge.net/projects/bitboom/

I'm glad to see 0 downloads anyway.

wow yeah!!!!

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
Nicolai
Newbie
*
Offline Offline

Activity: 39
Merit: 0



View Profile
March 09, 2013, 02:40:14 PM
 #6

Bitboom:

Virustotal analysis:
 * Detection ratio: 7 / 43

Sandbox analysis:
 * Create auto-startup entry (so it run every time you start your computer)
 * Connects to bekiap3332424.sytes.net (85.107.169.23 = TurkTelecom) port 1604 (this is the malwares C&C)

Reverse Engineering:
 * Program has two embed resources: windows.rtf ("buffer") and windows1.rtf ("rawAssembly") which is copied to memory and the decompressed (this is a common trick to avoid AV detection)

This is clearly malware
Offthechain
Newbie
*
Offline Offline

Activity: 35
Merit: 0


View Profile
March 09, 2013, 02:55:42 PM
 #7

Nice detective work there!
Nicolai
Newbie
*
Offline Offline

Activity: 39
Merit: 0



View Profile
March 09, 2013, 05:31:56 PM
Last edit: July 12, 2014, 08:34:32 PM by Nicolai
 #8

Small update regarding "Bitboom"

Decompiling shows the malware is: "DarkComet" which has been 'cryptet' with some crappy C# "crypter" two times.

I have submittet all samples to virustotal (so all AV-companys can add detection to this malware) Smiley

If anyone have the time/desire, then please contact TurkTelecom and tell them that the IP "85.107.169.23" spread malware.
Also please help me getting this malware removed from sourceforge, by using the Report Abuse function: https://sourceforge.net/projects/bitboom/report_inappropriate

The malware was uploaded to SF by someone called "iakovl". Googling this name and you find a similar stackoverflow profile, looking at the questions he have made, and you'll see that his a C# developer: http://stackoverflow.com/users/501160/iakovl?tab=questions (just like the "wrapper" of the malware was written in).

Feel free to (ab)use this info. See below, however the TurkTelecom IP is most likely some random hacked computer in Turkey.
Severian
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
March 09, 2013, 05:34:54 PM
 #9

You are awesome, Nicolai. Thanks.
dust
Hero Member
*****
Offline Offline

Activity: 840
Merit: 1000



View Profile WWW
March 09, 2013, 10:28:03 PM
 #10

I'm surprised that no one has released an altcoin with malware in the binaries, but clean source on github.  I always build altcoins from source, and perform a quick audit of the commits on top of bitcoin to check if there is anything fishy.

Cryptocoin Mining Info | OTC | PGP | Twitter | freenode: dust-otc | BTC: 1F6fV4U2xnpAuKtmQD6BWpK3EuRosKzF8U
jubalix (OP)
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
March 09, 2013, 10:53:04 PM
 #11

I'm surprised that no one has released an altcoin with malware in the binaries, but clean source on github.  I always build altcoins from source, and perform a quick audit of the commits on top of bitcoin to check if there is anything fishy.

we probably should have some sort of pure bin. file checker or something




Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
iakovl
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
January 30, 2014, 04:27:33 PM
 #12

Small update regarding "Bitboom"

Feel free to (ab)use this info.

thank you for accusing me and doing a hell of a job framing someone

the ip is TurkTelecom... i on the other hand am from israel, not the same area in the world
i do develop C# a bit (see the QA on stackoverflow, not on the level of making malware)
would really appreciate if you remove the links and my name...

i don't use bitcoin, nor do am i involved in anything like "this" so be kind and don't point fingers on people with your crap "detective" work
ip = TurkTelecom, my stackoverflow profile = israel... not to hard to know the two apart
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!