Bitcoin Forum
November 06, 2024, 07:36:56 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bitgo Hacked? My computer Hacked? Or false positive?  (Read 166 times)
acegilz (OP)
Full Member
***
Offline Offline

Activity: 211
Merit: 100

1ACEGiLZnZoG7KUNkMwAT8tBuJ6jsrwj5Q


View Profile
May 11, 2018, 05:01:03 PM
 #1

https://imgur.com/a/VSDBeHc

AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
May 11, 2018, 06:05:22 PM
Last edit: May 12, 2018, 05:49:25 PM by AdolfinWolf
 #2


Seems like this happend to some people before, https://twitter.com/jronkain/status/919923991313375233 This happend in 2017. If that was real i think some more people would've noticed by now.

https://www.virustotal.com/url/5f41b558cc90c0dd5c8a6506f67ecb38daf343eb4375565ef8adcecaf3187bbb/analysis/1526061180/ gives a 0 / 67.
(Although i doubt that it scanned it correctly.)

Bitgo.com is a pretty popular site though, so if there was indeed something like a keylogger injected into the site, i'm sure people would've noticed by now.

Also, https://github.com/bitgo most of their wallets & tools seem to be open source. Not sure if their website itself is, but trying to hide a keylogger there really doesn't make sense.

bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1307


Limited in number. Limitless in potential.


View Profile
May 11, 2018, 06:32:15 PM
 #3

Seems it only appears on your computer or on AVG database particularly, I didn't get any error or alert when visiting the site using Norton while Bitgo has good reputation IMO

3. Your connection is intercepted by hacker or 3rd party. Try to use BitGo with paid VPN or Tor with proper configuration.
This might be the close reason of your issue.
TryNinja
Legendary
*
Offline Offline

Activity: 3010
Merit: 7435


Top Crypto Casino


View Profile WWW
May 11, 2018, 06:35:12 PM
 #4

This is the js file (which can be found in the BitGo login page) and that your antivirus is detecting as malicious: https://www.bitgo.com/js/BitGoJS.14b27091ae4a5ec9.js

And there is nothing wrong with it (AFAIK). Thus this is most likely just a false positive.

███████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████

███████████████████████
.
BC.GAME
▄▄▀▀▀▀▀▀▀▄▄
▄▀▀░▄██▀░▀██▄░▀▀▄
▄▀░▐▀▄░▀░░▀░░▀░▄▀▌░▀▄
▄▀▄█▐░▀▄▀▀▀▀▀▄▀░▌█▄▀▄
▄▀░▀░░█░▄███████▄░█░░▀░▀▄
█░█░▀░█████████████░▀░█░█
█░██░▀█▀▀█▄▄█▀▀█▀░██░█
█░█▀██░█▀▀██▀▀█░██▀█░█
▀▄▀██░░░▀▀▄▌▐▄▀▀░░░██▀▄▀
▀▄▀██░░▄░▀▄█▄▀░▄░░██▀▄▀
▀▄░▀█░▄▄▄░▀░▄▄▄░█▀░▄▀
▀▄▄▀▀███▄███▀▀▄▄▀
██████▄▄▄▄▄▄▄██████
.
..CASINO....SPORTS....RACING..


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
acegilz (OP)
Full Member
***
Offline Offline

Activity: 211
Merit: 100

1ACEGiLZnZoG7KUNkMwAT8tBuJ6jsrwj5Q


View Profile
May 11, 2018, 08:02:17 PM
Last edit: May 11, 2018, 09:15:53 PM by acegilz
 #5

can please someone using avg visit that login page and check if it also appears?

I use avg mac for some years and this is the first time.. weird

I have tried different browsers / vpn and the error persists
acegilz (OP)
Full Member
***
Offline Offline

Activity: 211
Merit: 100

1ACEGiLZnZoG7KUNkMwAT8tBuJ6jsrwj5Q


View Profile
May 11, 2018, 09:18:23 PM
 #6

I have another computer running avg windows and there is no issue. Cry

However, after installing avg antivirus on another mac computer and the error pops up also when visiting the site so Im a little bit more relieved, the strange thing is that scanning the direct js link OR scanning that js file (after dl) even on avg shows no virus.

The trojan name just by itself JS::Banker-ACK scares the shit out of me, especially showing on bitgo.. .  Shocked
Koadharber
Hero Member
*****
Offline Offline

Activity: 1168
Merit: 512


View Profile
May 12, 2018, 09:30:40 PM
 #7

This is the js file (which can be found in the BitGo login page) and that your antivirus is detecting as malicious: https://www.bitgo.com/js/BitGoJS.14b27091ae4a5ec9.js

And there is nothing wrong with it (AFAIK). Thus this is most likely just a false positive.
Ive been getting this notification too which it is detected with my ESET nod32 AV. which I do really see this is just a false positive yet that js file is really just into that log-in page and I had encountered some sites which do have that kind of detection. Sometimes these AV make me paranoid. Cheesy

Conasse
Jr. Member
*
Offline Offline

Activity: 336
Merit: 5

Culotte Jaune Officielle


View Profile
May 14, 2018, 09:04:16 PM
 #8

If BitGo was hacked it would be all over the news already and with a lot of posts about it here.
Surely a false positive I would say

Bouffe ma chatte, pas la planète!
squatz1
Legendary
*
Offline Offline

Activity: 1666
Merit: 1285


Flying Hellfish is a Commie


View Profile
May 15, 2018, 03:25:22 AM
 #9

I assure that that if BitGo was hacked we'd be in full meltdown mode, as a good amount of large exchanges (and large other companies) in crypto that control mass amounts of bitcoin use bitgo for their backend or even reserves. So this is probably just a false positive or somthing off of your side, nothing to be worried about if you're using 2fa anyway. Which I would always recommend

Or buy a trezor or a ledger.




▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄    ▄▄▄▄                  ▄▄▄   ▄▄▄▄▄        ▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄▄    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄
 ▀████████████████▄  ████                 █████   ▀████▄    ▄████▀  ▄██████████████   ████████████▀  ▄█████████████▀  ▄█████████████▄
              ▀████  ████               ▄███▀███▄   ▀████▄▄████▀               ████   ████                ████                   ▀████
   ▄▄▄▄▄▄▄▄▄▄▄█████  ████              ████   ████    ▀██████▀      ██████████████▄   ████████████▀       ████       ▄▄▄▄▄▄▄▄▄▄▄▄████▀
   ██████████████▀   ████            ▄███▀     ▀███▄    ████        ████        ████  ████                ████       ██████████████▀
   ████              ████████████▀  ████   ██████████   ████        ████████████████  █████████████▀      ████       ████      ▀████▄
   ▀▀▀▀              ▀▀▀▀▀▀▀▀▀▀▀   ▀▀▀▀   ▀▀▀▀▀▀▀▀▀▀▀▀  ▀▀▀▀        ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀   ▀▀▀▀▀▀▀▀▀▀▀▀        ▀▀▀▀       ▀▀▀▀        ▀▀▀▀▀

#1 CRYPTO CASINO & SPORTSBOOK
  WELCOME
BONUS
.INSTANT & FAST.
.TRANSACTION.....
.PROVABLY FAIR.
......& SECURE......
.24/7 CUSTOMER.
............SUPPORT.
BTC      |      ETH      |      LTC      |      XRP      |      XMR      |      BNB      |     more
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!