Bitcoin Forum
April 24, 2024, 08:17:47 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: My CEX.IO account has been hacked and has been drained dry.  (Read 3777 times)
0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 02:16:59 PM
 #1

Hello all,
My cex.io account has just been hacked and drained dry.
I am in contact with Admin and they are investigating it.
The offender used the following weblink as his means of doing so.
mineramicasa.com/minera/
I am doing this as a means of helping others avoid this same trap.
I am a bit SAD because the BTC's that I had invested in the site are on loan to me, and I do not have any means of paying it back.
But I have some faith in the CEX.IO Admin team to hopefully recover my now empty account.
Imagine a world without SCUMBAGS, wouldn't it be nice?
Thanks.

0zman
1713989867
Hero Member
*
Offline Offline

Posts: 1713989867

View Profile Personal Message (Offline)

Ignore
1713989867
Reply with quote  #2

1713989867
Report to moderator
1713989867
Hero Member
*
Offline Offline

Posts: 1713989867

View Profile Personal Message (Offline)

Ignore
1713989867
Reply with quote  #2

1713989867
Report to moderator
"You Asked For Change, We Gave You Coins" -- casascius
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713989867
Hero Member
*
Offline Offline

Posts: 1713989867

View Profile Personal Message (Offline)

Ignore
1713989867
Reply with quote  #2

1713989867
Report to moderator
1713989867
Hero Member
*
Offline Offline

Posts: 1713989867

View Profile Personal Message (Offline)

Ignore
1713989867
Reply with quote  #2

1713989867
Report to moderator
1713989867
Hero Member
*
Offline Offline

Posts: 1713989867

View Profile Personal Message (Offline)

Ignore
1713989867
Reply with quote  #2

1713989867
Report to moderator
bryant.coleman
Legendary
*
Offline Offline

Activity: 3654
Merit: 1217


View Profile
January 04, 2014, 02:26:58 PM
 #2

Saddened to hear this. How much did you lose? Do you have any idea how it happened? i.e compromised system, key logger, stolen passwords.etc?

0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 02:34:41 PM
 #3

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.
Frost000
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
January 04, 2014, 02:38:53 PM
 #4

Did you have 2-FA turned on for your account?

Either way, sorry for your loss... This seems to happen a lot more than it should.
0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 02:44:14 PM
 #5

No I didn't. My Smartphone has been out of order. I pick it up tomorrow.
Was going to do exactly that when I got it back, too late.
I feel very much like this guy.  Cry and his mate  Embarrassed.
All I hope to do now is stop him from draining anyone else's account.
I think he needs a good poke in the EYE.
BunworthBanshee
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile
January 04, 2014, 02:50:47 PM
 #6

Oh man that sucks. so sorry to here that.

It seams that most people that are getting hacked did not have 2factor on there accounts. and there have been a good few.

So do you think it was the bot or the java that you ran?

0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 02:58:31 PM
 #7

I'm no coder, but I feel that it was the JAVA.
One of the dumped files was LOGIN_DATA
I opened it in Notepad only to see all of my web login account names + a lot of other code.
I'm lucky that I don't have an online wallet.
So far my CEX account is the only one that has been compromised. But that could change.
Unfortunately CEX is where all of my BTC were.
I'm just waiting on Admin now. I will reply later with updates on status of this.
0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 03:34:43 PM
 #8

UPDATE:

CEX Admin have managed to get me back online and my funds are 100% still there.
Good work CEX.IO resolved quickly. Now I can sleep. It is 2:30 am here in Australia.
Good night all.
 Grin Grin Grin Grin Grin

0zman
Frost000
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
January 04, 2014, 03:40:53 PM
 #9

Glad to hear it! I'm really happy for you! Looks like you'll have some peaceful sleep... Smiley

Once you get your phone back, remember to activate 2-FA!
0zman (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
January 04, 2014, 03:47:35 PM
 #10

Thanks,
Yes it will be priority number 1.
Have a good day to everyone, wherever you are on this Beautiful blue planet.
I'm off to the land of NOD.
s1lverbox
Legendary
*
Offline Offline

Activity: 2310
Merit: 1039


View Profile
January 04, 2014, 04:52:21 PM
 #11

Hello all,
My cex.io account has just been hacked and drained dry.
I am in contact with Admin and they are investigating it.
The offender used the following weblink as his means of doing so.
mineramicasa.com/minera/
I am doing this as a means of helping others avoid this same trap.
I am a bit SAD because the BTC's that I had invested in the site are on loan to me, and I do not have any means of paying it back.
But I have some faith in the CEX.IO Admin team to hopefully recover my now empty account.
Imagine a world without SCUMBAGS, wouldn't it be nice?
Thanks.

0zman

So my understanding is that your machine been injected with java from website and this way someone sucked all info from webrowser or computer.
No spyware or good antyvir installed?? What browser you using?

My browser blocking this plugin to run, so u had to click on it.
Safest way is to disable java in browser
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 05, 2014, 02:20:34 AM
 #12

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss
Frost000
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
January 05, 2014, 03:02:18 AM
 #13

Lesson for everyone. Never run a Java plugin. Sorry for your loss

That and turn on 2-FA as soon as you can, while making sure to keep your keys in a safe place. Obviously, it's not 100% foolproof, but it can save you from a lot of trouble a lot of the time.
rudrigorc2
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000



View Profile
January 05, 2014, 06:50:24 AM
 #14

you dont need a phone to use it.

https://github.com/gbraad/html5-google-authenticator

take care.
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 05, 2014, 06:55:48 AM
 #15

you dont need a phone to use it.

https://github.com/gbraad/html5-google-authenticator

take care.

Thanks for that. I was worrying about that last night. Got 2fa on so many sites now. What if my phone disappeared ...... now I know what to do Smiley
rudrigorc2
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000



View Profile
January 05, 2014, 06:59:45 AM
 #16

you dont need a phone to use it.

https://github.com/gbraad/html5-google-authenticator

take care.

Thanks for that. I was worrying about that last night. Got 2fa on so many sites now. What if my phone disappeared ...... now I know what to do Smiley

youre welcome
s1lverbox
Legendary
*
Offline Offline

Activity: 2310
Merit: 1039


View Profile
January 05, 2014, 10:18:36 AM
Last edit: January 05, 2014, 12:52:17 PM by s1lverbox
 #17

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest if any one, to run it sundboxed.

I do not encourage anyone to download and open this file.

Files provided to analyse what contains that plugin and how they taking info from machine.
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 05, 2014, 11:27:06 AM
 #18

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest any one to run it sundboxed.

You've lost me ..... what Java are you encouraging people to download and run given that the thread was about someone who ran some Java and got hacked because of it ?
s1lverbox
Legendary
*
Offline Offline

Activity: 2310
Merit: 1039


View Profile
January 05, 2014, 12:46:01 PM
 #19

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest any one to run it sundboxed.

You've lost me ..... what Java are you encouraging people to download and run given that the thread was about someone who ran some Java and got hacked because of it ?

My intention was to provide applet which trying to load by visiting site given by OP, to someone who can check what's that plugin doing. I done it sundboxed and plugin done nothing to my laptop.
Someone who knows Java can check it and can provide info how cex account was emptied.
By downloading zip and unpack it nothing will happen. U have to applet.jar to have effect.
I did check this file by opening in editor but cannot find anything-i dont know what im looking for anyway.
johningreece
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile
January 05, 2014, 04:44:08 PM
 #20

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??
bornkiller
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
January 05, 2014, 04:57:24 PM
 #21

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??

My account was hacked too on 3 of jan about 21.30. But I don't run anything. It was about 5 BTC in GHS ant BTC. My account is frozen now.
There is no viruses on my pc, i've just checked it out.

I think that somebody has been stolen db with logins and e-mail from cex.io...
johningreece
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile
January 05, 2014, 05:02:12 PM
 #22

I am hoping that cex will make this right, either erstore the btc or provide enought temporary GHS to remine the lost btc.  What have they told you?
not.you
Legendary
*
Offline Offline

Activity: 1726
Merit: 1018


View Profile
January 05, 2014, 05:14:02 PM
 #23

Java is a huge malware vector.  I do not run it on my PC's for reasons such as this.  This is the first time I have heard of it being used for BTC related hack stuff but it has long been used to make your webmail accounts send spam for the malware writers that wind up encouraging your friends to click malicious links since the email comes from you.  It is also frequently used to install trojans and other crap on your PC.  There is a reason java has updates almost bi-weekly.  Don't install java on any computer unless it is essential to some app you use and then don't use that computer to surf the web.
Frost000
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
January 05, 2014, 06:22:36 PM
 #24

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??

Did you have 2-FA enabled for your account?

Cex.io has been a mixed bag in the past, it seems, when it comes to hacked accounts. On the site's troll box, there have been users explaining that they had their funds withdrawn as well, with Cex.io doing nothing about it. So who know...
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 06, 2014, 02:54:48 AM
 #25

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest any one to run it sundboxed.

You've lost me ..... what Java are you encouraging people to download and run given that the thread was about someone who ran some Java and got hacked because of it ?

My intention was to provide applet which trying to load by visiting site given by OP, to someone who can check what's that plugin doing. I done it sundboxed and plugin done nothing to my laptop.
Someone who knows Java can check it and can provide info how cex account was emptied.
By downloading zip and unpack it nothing will happen. U have to applet.jar to have effect.
I did check this file by opening in editor but cannot find anything-i dont know what im looking for anyway.

You don't know what you are looking for? So why look?

Leave security analysis to people that know what they are doing. They don't need advise about sandboxes either Wink
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 06, 2014, 02:56:21 AM
 #26

I think cex.io need to comment about this.

How many accounts have been hacked in the last week and funds stolen? Is cex.io safe at all now?
johningreece
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile
January 06, 2014, 08:26:19 AM
 #27

read this:

http://mentaso.com/bitcoin-news/cex-part-2-the-hacked-account-and-children-playing-grownups.html
Justin00
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
January 06, 2014, 09:30:47 AM
 #28

hmm.. so if im understanding correctly... the hacker can easily get someones username/btc address and the hack.. part is the finding the persons email address ?

empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 06, 2014, 10:14:04 AM
 #29

another bitcoin site with iffy security - what a shock
s1lverbox
Legendary
*
Offline Offline

Activity: 2310
Merit: 1039


View Profile
January 06, 2014, 11:17:38 AM
 #30

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest any one to run it sundboxed.

You've lost me ..... what Java are you encouraging people to download and run given that the thread was about someone who ran some Java and got hacked because of it ?

My intention was to provide applet which trying to load by visiting site given by OP, to someone who can check what's that plugin doing. I done it sundboxed and plugin done nothing to my laptop.
Someone who knows Java can check it and can provide info how cex account was emptied.
By downloading zip and unpack it nothing will happen. U have to applet.jar to have effect.
I did check this file by opening in editor but cannot find anything-i dont know what im looking for anyway.

You don't know what you are looking for? So why look?

Leave security analysis to people that know what they are doing. They don't need advise about sandboxes either Wink
stop being cocky. I just trying to help plus the fact I have cex account and want to understand how its done. if I knew I have to deal with idiots I wouldn't wright anything at all.
Wassupia
Member
**
Offline Offline

Activity: 106
Merit: 10


View Profile
January 06, 2014, 12:46:51 PM
 #31

I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest if any one, to run it sundboxed.

I do not encourage anyone to download and open this file.

Files provided to analyse what contains that plugin and how they taking info from machine.

You can decompile with http://jd.benow.ca/

It's a regular java driveby, with a reg to disable uac and taskmanager (I think). I found 1 valid url inside, of which the domain expired on December 20.
http:**www.mundoonlinejava.com*cgi.bin*uploads*update2.jar

On http://web.archive.org  I see it was hosted by https://pt-br.facebook.com/KingHost.Brasil

whois:
http://whois.domaintools.com/mundoonlinejava.com
It's probably registered with the email-address of the hosting comp, not sure.

If someone could get the ip-adress the domain pointed to before it expired, you might be able to download the update2.jar to get more info.

I know there have been silent javadriveby's that would run without requiring permission.
You should disable the java plugin by default...
This way Jars won't even ask for permission, so you can't 'accidently' press 'run/allow', and silent driveby's don't have a chance.


My BTC-address: 1JtgnB6UC5j9gMYzLftVaCmwdPL4PrWeYB
pasikisu
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
January 06, 2014, 06:11:02 PM
 #32

you dont need a phone to use it.

https://github.com/gbraad/html5-google-authenticator

take care.
Just remember to not run that on the same computer. The point of 2fa is that the OTPs come from another source, so if your main computer is hacked all is not lost.
doltek
Newbie
*
Offline Offline

Activity: 12
Merit: 0



View Profile
January 08, 2014, 09:41:53 AM
 #33

My account was hacked too. Cex.io doesn't seem to care. Making me feel it my fault. Huh Shocked
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 08, 2014, 02:01:08 PM
 #34

My account was hacked too. Cex.io doesn't seem to care. Making me feel it my fault. Huh Shocked

Did you have 2fa on?
doltek
Newbie
*
Offline Offline

Activity: 12
Merit: 0



View Profile
January 09, 2014, 09:02:13 AM
 #35

My account was hacked too. Cex.io doesn't seem to care. Making me feel it my fault. Huh Shocked

Did you have 2fa on?

I do now. I have never been hacked before this.
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 09, 2014, 11:04:49 AM
 #36

My account was hacked too. Cex.io doesn't seem to care. Making me feel it my fault. Huh Shocked

Did you have 2fa on?

I do now. I have never been hacked before this.

I mean when you were hacked.
maverick528
Full Member
***
Offline Offline

Activity: 148
Merit: 100


View Profile WWW
January 29, 2014, 09:35:46 PM
 #37

Me too. Cry

https://bitcointalk.org/index.php?topic=365103.msg4821269#msg4821269

Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!