Bitcoin Forum
June 27, 2024, 11:41:25 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Warning! BTC-e Voucher Email phishing alert!  (Read 3450 times)
makngeerwork
Full Member
***
Offline Offline

Activity: 141
Merit: 100

???


View Profile
May 02, 2017, 06:11:43 PM
 #21

same, just checked email....  what are we noobs?

Hi makngeerwork.

See attached your BTC-e vouchers.

You need to activate them within 8 hours.

The Access key is w8pKFy9KTM. You need to paste it to be able to view the document.

Thanks
William Anthony

███    TWITTER   FLUX   WHITEPAPER  ███
███    WEBSITE   GAMING ECOSYSTEM        MEDIUM      ███
███  TELEGRAM  VALVE  UBISOFT  ██████ Origin  GAMELOFT      FACEBOOK   ███
CoinHoarder
Legendary
*
Offline Offline

Activity: 1484
Merit: 1026

In Cryptocoins I Trust


View Profile
May 02, 2017, 06:21:17 PM
Last edit: May 02, 2017, 07:10:17 PM by CoinHoarder
 #22

I don’t think even 1 person falls for this but if they do, pray for their soul man.

I guess there are a few people stupid enough to make this worth their time, otherwise they wouldn't do it. It is simply a numbers game. Send the email to a million+ BTC-e users and you are bound to find someone stupid enough.

Older people that are computer illiterate may be more likely to open the file. Which reminds me... I need to inform my mom about this. She has some funds on BTC-e. I've tried for years to get her to move her BTC and LTC to cold wallets, but she doesn't seem too worried... I think older people have too much trust in the goodness of people's intentions.
Deadly7
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
May 02, 2017, 06:42:29 PM
 #23

I also received the same phishing email, even though I haven't posted here in years. 
iigor
Full Member
***
Offline Offline

Activity: 434
Merit: 105



View Profile
May 02, 2017, 07:28:03 PM
 #24

I scanned my pc with mb and mb anti-rootkit, in and out of safe mode and nothing has been found.

Here, content of the file:



free-bit.co.in
Hero Member
*****
Offline Offline

Activity: 1088
Merit: 531


Free Crypto in Stake.com Telegram t.me/StakeCasino


View Profile
May 02, 2017, 07:33:40 PM
 #25

I scanned my pc with mb and mb anti-rootkit, in and out of safe mode and nothing has been found.

Here, content of the file:




You scanned them with the file still being encrypted? Then of course nothing can be detected as a virus or harmful script. DON'T DECRYPT THE FILE ! Unless you have a save environment to do it (Virtual machine and sandbox!).

.freebitcoin.       ▄▄▄█▀▀██▄▄▄
   ▄▄██████▄▄█  █▀▀█▄▄
  ███  █▀▀███████▄▄██▀
   ▀▀▀██▄▄█  ████▀▀  ▄██
▄███▄▄  ▀▀▀▀▀▀▀  ▄▄██████
██▀▀█████▄     ▄██▀█ ▀▀██
██▄▄███▀▀██   ███▀ ▄▄  ▀█
███████▄▄███ ███▄▄ ▀▀▄  █
██▀▀████████ █████  █▀▄██
 █▄▄████████ █████   ███
  ▀████  ███ ████▄▄███▀
     ▀▀████   ████▀▀
BITCOIN
DICE
EVENT
BETTING
WIN A LAMBO !

.
            ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
▄▄▄▄▄██████████████████████████████████▄▄▄▄
▀██████████████████████████████████████████████▄▄▄
▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
  ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
       ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.PLAY NOW.
iigor
Full Member
***
Offline Offline

Activity: 434
Merit: 105



View Profile
May 02, 2017, 07:52:29 PM
 #26

So if i dont decrypt the file and just delete it, im safe?

singula
Sr. Member
****
Offline Offline

Activity: 462
Merit: 251



View Profile
May 02, 2017, 08:04:15 PM
 #27

I looked at the file ... it is an encrypted .doc

I have not tried opening it, but this approach is not typical for phishing, but for malware infections.

Some macro in the .doc would run (sometimes user is tricked to enable macros, sometimes an exploit is used to run macros without further user's intervention) and then the computer would get infected by some malware. Could be some ransomware, botnet, scareware, password stealer, banker, adware, but surely it will be something evil.

I am not going to examine it further to find which one it is.

Big brother is not watching you anymore. Big brother is telling you how to live.
kolloh
Legendary
*
Offline Offline

Activity: 1736
Merit: 1023


View Profile
May 02, 2017, 08:33:50 PM
 #28

So if i dont decrypt the file and just delete it, im safe?

Yeah, you should be. The file shouldn't be able to execute in its encrypted state afaik and I'm guessing the attacker encrypts it to avoid virus signature detection.
iigor
Full Member
***
Offline Offline

Activity: 434
Merit: 105



View Profile
May 02, 2017, 09:28:21 PM
Last edit: May 02, 2017, 11:15:24 PM by iigor
 #29

Then that password that they sent us is the key to run whats inside the file?

kolloh
Legendary
*
Offline Offline

Activity: 1736
Merit: 1023


View Profile
May 03, 2017, 05:17:01 AM
 #30

Then that password that they sent us is the key to run whats inside the file?

Yeah, it unencrypts the docx file which would allow it to run whatever malicious code is inside. Don't enter the password in or mess with the file. Just delete it is the safest course of action.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!