Bitcoin Forum
May 27, 2024, 07:41:07 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [ATTN] New trojan spreads through skype and (possibly) steals wallet.dat.  (Read 1374 times)
r.willis (OP)
Jr. Member
*
Offline Offline

Activity: 42
Merit: 11


View Profile
April 07, 2013, 07:55:18 AM
 #1

http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype
Quote
There is a new malicious ongoing campaign on Skype. It’s active and kicking yet.
The infection vector is via social engineering abusing infected Skype by sending massive messages to the contacts like these ones:
i don't think i will ever sleep again after seeing this photo http://www.goo.gl/XXXXX?image=IMG0540250-JPG
tell me what you think of this picture i edited http://www.goo.gl/XXXXX?image=IMG0540250-JPG
<snip>
Finally something interesting is this:

And similar malware spreads bitcoin miner:
http://www.securelist.com/en/blog/208194210/Skypemageddon_by_bitcoining
Quote
So what does malware do? To be honest many things but one of the most interesting is it turns the infected machine to a slave of the bitcoin generator. The usage of CPU grows up significantly. Here is an example:

The mentioned process runs with the command ?bitcoin-miner.exe -a 60 -l no -o http://suppp.cantvenlinea.biz:1942/ -u XXXXXX0000001@gmail.com -p XXXXXXXX (sensitive data was replaced by XXXXXX) It abuses the CPU of infected machine to mine Bitcoins for the criminal.
Severian
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
April 07, 2013, 07:58:08 AM
 #2

Bitcoin on Windows?

*shudder*
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
April 07, 2013, 08:24:40 AM
 #3

Bitcoin on Windows?

*shudder*

Bitcoin $150 each way too soon?
*shudder*   

MaGNeT
Legendary
*
Offline Offline

Activity: 1526
Merit: 1002


Waves | 3PHMaGNeTJfqFfD4xuctgKdoxLX188QM8na


View Profile WWW
April 07, 2013, 08:30:50 AM
 #4

- Use long passphrase wallet.dat encryption (>20 characters).
- Keep at least one copy offline.

Now they can steal your wallet.dat and you still have plenty of time to send the coins to another wallet and change the receiving adresses at pools and exchanges.

luffy
Hero Member
*****
Offline Offline

Activity: 607
Merit: 500



View Profile
April 07, 2013, 08:37:48 AM
 #5

How do you realize that your wallet has been stolen before it is too late?
r.willis (OP)
Jr. Member
*
Offline Offline

Activity: 42
Merit: 11


View Profile
April 07, 2013, 09:06:03 AM
 #6

How do you realize that your wallet has been stolen before it is too late?
This, and they can log your passphrase just fine.
MaGNeT
Legendary
*
Offline Offline

Activity: 1526
Merit: 1002


Waves | 3PHMaGNeTJfqFfD4xuctgKdoxLX188QM8na


View Profile WWW
April 07, 2013, 10:29:14 AM
 #7

How do you realize that your wallet has been stolen before it is too late?
This, and they can log your passphrase just fine.

That's another reason to have one wallet for trading and one offline for keeping.
Jobe7
Full Member
***
Offline Offline

Activity: 238
Merit: 100


Now they are thinking what to do with me


View Profile
April 07, 2013, 10:44:14 AM
 #8

or don't use skype, I hate skype.

Or have a separate laptop/desktop that you use skype on.
MaGNeT
Legendary
*
Offline Offline

Activity: 1526
Merit: 1002


Waves | 3PHMaGNeTJfqFfD4xuctgKdoxLX188QM8na


View Profile WWW
April 07, 2013, 10:50:03 AM
 #9

or don't use skype, I hate skype.

Or have a separate laptop/desktop that you use skype on.

+1
Dabs
Legendary
*
Offline Offline

Activity: 3416
Merit: 1912


The Concierge of Crypto


View Profile
April 07, 2013, 02:29:01 PM
 #10

My computer is bare bones OS and office only. Everything else is either installed and run, or portable (as in portable apps, run from its own directory.) I use Deep Freeze to essentially make my computer it's own virtual machine. Once rebooted or shut down, it reverts back to it's "clean" state.

I don't use Skype or Yahoo messenger or any other software. If I have to use them, I download the app, save it somewhere, reboot (optional), install the app, use it, then reboot or shutdown as appropriate.

Now, my computer could be subject to some zero day malware, but I find that unlikely. I almost always sit behind some hardware firewall (router) and the other computers in the network have different anti-virus / anti-malware installed.

Or I could always take a look at GMER. (rootkit detector).

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!