Bitcoin Forum
June 24, 2024, 11:35:20 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Reporting potential Bitcoin botnet  (Read 1911 times)
PsykoTenshi (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 27, 2013, 02:47:47 AM
 #1

Simply put, today when I started my comp the gpu was throttling like crazy. Apparently someone managed to infiltrate a bitcoin miner bot into my computer. I know I didn't do that willingly at least, not having just a "mere" Radeon HD4890, that won't get me anywhere with bitcoins. Also I've even identified when and how I did (unwittingly) install it, but that's another story.

So I figured I'd go make the guy's easy money plan backfire on him by reporting his bitcoin info to the community.
Among the scripts I've found on my system, there was two url's, I hope that's enough.
Quote

I can also submit the .exe file that installs all this stuff for analysis if required.


P.S.: The only rules I saw was "no posting illegal stuff" and "I understand I'll be restricted to the Newbies section", I am not aware if posting someone's bitcoin info is "illegal" or similar. In any case, the guy is a just lowly gpu processor cycles and bitcoins leecher, he doesn't deserve any special treatment.
odolvlobo
Legendary
*
Online Online

Activity: 4354
Merit: 3274



View Profile
March 27, 2013, 02:53:13 AM
 #2

Because he has btcguild in his URL, he is likely to be mining in the btcguild pool. Contact btcguild (http://www.btcguild.com/), and perhaps they can ban him or something.

Join an anti-signature campaign: Click ignore on the members of signature campaigns.
PGP Fingerprint: 6B6BC26599EC24EF7E29A405EAF050539D0B2925 Signing address: 13GAVJo8YaAuenj6keiEykwxWUZ7jMoSLt
PsykoTenshi (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 27, 2013, 03:08:01 AM
Last edit: March 27, 2013, 03:22:56 AM by PsykoTenshi
 #3

Aw I'll have to make even more new accounts. Oh well, it'll make for an even more satisfactory (if) successful backfire on the guy's "free money" plan.

Edit: Silly me not noticing they have IRC-based support before making an account. :facepalm:
eleuthria
Legendary
*
Offline Offline

Activity: 1750
Merit: 1007



View Profile
March 27, 2013, 03:22:15 AM
 #4

Aw I'll have to make even more new accounts. Oh well, it'll make for an even more satisfactory (if) successful backfire on the guy's "free money" plan.

Thank you for coming into #btcguild IRC and reporting the user.  I'll be looking at the account shortly to see if other factors point to the account being a botnet (which in most cases is possible when an outside report is made).  If anything looks funny, paired with your report, the account will be disabled.

RIP BTC Guild, April 2011 - June 2015
eleuthria
Legendary
*
Offline Offline

Activity: 1750
Merit: 1007



View Profile
March 27, 2013, 04:12:48 AM
 #5

The user was confirmed as definitely showing botnet activity, and their workers have been disabled.

RIP BTC Guild, April 2011 - June 2015
fcmatt
Legendary
*
Offline Offline

Activity: 2072
Merit: 1001


View Profile
March 27, 2013, 04:16:52 AM
 #6

How did you install it?
mokahless
Sr. Member
****
Offline Offline

Activity: 471
Merit: 256



View Profile
March 27, 2013, 06:34:04 AM
 #7

I think it would be really cool to see what the exe installed. I'd love to run it in a vm.

davidblack
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
April 15, 2013, 09:17:23 AM
 #8

Hi - I'm looking into botnets & Bitcoin for Channel 4 News - anyone in the UK been affected and fancy talking to us?
PsykoTenshi (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
April 19, 2013, 03:35:09 PM
 #9

Oh... Sorry I didn't respond for so long, I utterly forgot about this.

@ fcmatt: Self extractor (poorly) disguised as game executable. I was careless, I know.

@ mokahless: Sent you PM.

@ davidblack: Well, I must say I feel honored, my English is good enough to pass as an English gentleman http://img14.imageshack.us/img14/4923/likeasiriconsmaller.png
I'm an ocean away, in Argentina (southern corner of South America). Thanks for the offer though Smiley

On a related note, hurray for eleuthria and his lightning fast response!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!