Bitcoin Forum
November 07, 2024, 02:50:52 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bfgminer.org - Malicious virus website  (Read 4839 times)
Spendulus (OP)
Legendary
*
Offline Offline

Activity: 2912
Merit: 1386



View Profile
August 02, 2013, 03:37:21 PM
Last edit: August 10, 2013, 05:00:47 PM by Spendulus
 #1

Hi -

I tried to download bfgminer today, and from Google this came up, #2 in the rankings (link destroyed so you cannot accidentally load it)

bfgminer . org

The site does a pretty good job of looking authentic.

Clicking on 64 bit, you get a mass of browser hijacks and other things downloaded.  They are definitely malicious loads and after they are installed, they prompt you to install additional ones.  If you want to try this to see, please do it in a virtual machine under vmware or such, not on one of your production machines.

I hope that this website is not the product of the guys that wrote the program and support it.

8/10/13 Verified, it is not the work of those that wrote bfgminer.
xjack
Hero Member
*****
Offline Offline

Activity: 539
Merit: 500



View Profile
August 03, 2013, 07:27:41 PM
 #2

At the bottom of the page...

This site is not affiliated with BFGMiner and is not the official page of the software.

xjack - 1xjackDMgJCLn1LDtbgh51DYw6uRgeHVb
Reputation thread - https://bitcointalk.org/index.php?topic=482124.0
Spendulus (OP)
Legendary
*
Offline Offline

Activity: 2912
Merit: 1386



View Profile
August 10, 2013, 04:06:43 PM
 #3

At the bottom of the page...

This site is not affiliated with BFGMiner and is not the official page of the software.
The more I thought about it, the more this site troubles me.  So I have dug into what it does on a virtual machine.

DO NOT LOAD THIS SITE!

Again, I am using a virtual machine and am going to keep it quaranteened.

Here is the html that provides the lead in for the naive user click - on the "Windows 32 bit", which appears to provide a download of the bfgminer software.  NOTE I HAVE INTERJECTED SPACES TO PREVENT ANY ACCIDENTAL CLICKING:

<a href="http : //7802cb7d . tinylinks.co"><strong>Windows 32 bit</strong></a>........

another similar link follows for the 64 bit windows.

This leads to a page with a linkbucks reference and an attempt to download "opendownloadmanager", then an auto download of what appears to be the 3.14 program file for bfgminer from luke.dashjr.org/programs/bitcoin/files.  That's a hidden directory, might be some issues there.
 
Following this ad.yieldmanager is installed - this is notorious stuff that continually pops up adds on your desktop even after you close the browser.

At some point 'sweetpacks' is installed, another well known browser and search engine hijacker.

HERE IS THE PROBLEM:

Anyone who has downloaded bfgminer from this site and used it has compromised security, and could easily find their bitcoins and/or passwords stolen or reported.

Who are the scammers that own the domain?  They are cloaked.  
As bitcoin has been now defined as money, bfgminer.org is, I think, engaged in phishing and a higher level of illegal activity than just the malware and hijacking.

Domain ID:D168369843-LROR
Domain Name:BFGMINER.ORG
Created On:06-Apr-2013 16:53:16 UTC
Last Updated On:18-Jul-2013 23:27:13 UTC
Expiration Date:06-Apr-2014 16:53:16 UTC
Sponsoring Registrar:eNom, Inc. (R39-LROR)
Status:CLIENT TRANSFER PROHIBITED
Registrant ID:d3030885d199b972
Registrant Name:WhoisGuard Protected
Registrant Organization:WhoisGuard, Inc.
Registrant Street1:P.O. Box 0823-03411

Checking enom, here is the reseller:


Namecheap.com
http://namecheap.com
8939 S. Sepulveda Blvd. #110 - 732
Westchester , CA
+1.6613102107
+1.5555555555
support@namecheap.com
For additional assistance, please call 1 (425) 274-4500 or
Submit a Ticket in our Guest Help Center.

Therefore, owners of the bfgminer product can have this website taken down by directing their request / demand to support@namecheap.com.
os2sam
Legendary
*
Offline Offline

Activity: 3586
Merit: 1098


Think for yourself


View Profile
August 10, 2013, 04:12:46 PM
 #4

Always download mining software directly from the Authors provided site.

That principal should be followed for ANY software you download from the internet these days.

Sad state of affairs indeed.
Sam

A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
A: Top-posting.
Q: What is the most annoying thing on usenet and in e-mail?
Spendulus (OP)
Legendary
*
Offline Offline

Activity: 2912
Merit: 1386



View Profile
August 10, 2013, 04:20:53 PM
 #5

Always download mining software directly from the Authors provided site.

That principal should be followed for ANY software you download from the internet these days.

Sad state of affairs indeed.
Sam

I agree, but also, I think this is a live, active, major scam.  Here is a bit more.

AGAIN, REPEATING:  I AM USING A VIRTUAL MACHINE.  DO NOT DO THIS ON YOUR PHYSICAL BOX UNLESS YOU KNOW WHAT YOU ARE DOING.  YOU WILL BE DOWNLOADING VIRUS AND MALWARE.

The first request to the user after he clicks on "32 bit" is for him to download "opendownloadmanager".  Now a lot of people would probably do that, thinking that the download manager is needed because of the program size or something.  What happens is a file from that website entitled "Setup.exe" is downloaded.

Now what is downloaded if one goes to opendown load manager . com (I am destroying the link because it is UNSAFE) and click to download?

Setup_ODM.exe

A different program....

Yes, my friends.   They have a SPECIAL PROGRAM VERSION, Setup.exe for you dedicated, hard working bfgminers.  

Maybe a VERY special program....
os2sam
Legendary
*
Offline Offline

Activity: 3586
Merit: 1098


Think for yourself


View Profile
August 10, 2013, 05:00:31 PM
 #6

I agree, but also, I think this is a live, active, major scam.  Here is a bit more.

Yep, I have no problem with your reporting and investigation.  Very helpful I think Smiley.

I'm just stating the obvious in simple terms in case anyone else has the urge to google any program for the purpose of downloading and installing.

Always exercise common sense.
Sam

A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
A: Top-posting.
Q: What is the most annoying thing on usenet and in e-mail?
Spendulus (OP)
Legendary
*
Offline Offline

Activity: 2912
Merit: 1386



View Profile
August 10, 2013, 05:06:40 PM
Last edit: August 10, 2013, 05:34:48 PM by Spendulus
 #7

I agree, but also, I think this is a live, active, major scam.  Here is a bit more.

Yep, I have no problem with your reporting and investigation.  Very helpful I think Smiley.

I'm just stating the obvious in simple terms in case anyone else has the urge to google any program for the purpose of downloading and installing.

Always exercise common sense.
Sam
Understand.  Now I'm going to report this problem to google.  Let's see how long/if they list the site as "Warning! This site could damage your computer".  And of course if they do not, the perps would not be the small time scammer but the THEY.  (Earth shakes slightly, all eyes look to sky for evidence of drones hovering closeby)

DONE!  Here is their auto respond:

Report Sent

Thanks for sending a report to Google. Now that you've done your good deed for the day, feel free to:

1. Take a second to rejoice merrily for doing your part in making the web a safer place.

2. Make sure you have upgraded your web browser to the latest version, and that you have applied the latest patches for your operating system.

3. Learn more about malware that can infect your computer on Stopbadware.org.



LOL...I am so warm and fuzzy feelings inside that Google is our happy friend and not a dark minion of the creepy and spreading evil forces. 
desired_username
Hero Member
*****
Offline Offline

Activity: 886
Merit: 1013


View Profile
August 26, 2013, 11:27:53 AM
 #8

The malicious website is still active.
Luke-Jr
Legendary
*
Offline Offline

Activity: 2576
Merit: 1186



View Profile
August 30, 2013, 01:15:50 PM
Last edit: August 30, 2013, 04:52:19 PM by Luke-Jr
 #9

I'm in touch with the author of this fan site and asked her to look into it.
Apparently it's related to some "Linkbucks" thing that's supposed to simply be a click-through with ads.
Should be removed soon, if it's actually malware. :/

Edit: She says she'll be updating the links to directly download 3.2.0 from my site in a few hours.

Edit: I've confirmed the site now links to the official downloads directly.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!