Bitcoin Forum
May 10, 2024, 07:32:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 »  All
  Print  
Author Topic: I just got this email, looks legit, right?  (Read 8265 times)
dexX7
Legendary
*
Offline Offline

Activity: 1106
Merit: 1024



View Profile WWW
January 08, 2014, 12:43:45 PM
 #41

I analyzed this malware and put together a short blog post on what I found. If you're interested, take a look.
http://blog.logrhythm.com/uncategorized/emerging-bitcoin-theft-campaign-uncovered/

Really nice post! Liquid already came forward, but I still need to ask:

Quote
Reviewing the wallet.dat file with strings discloses the phisher’s BTC wallet addresses. A team of 4-people: Liquid, Kaz, Abz, and Frosty.

Why would a reasonable villain do such a thing in the first place? The exact role of the wallet is unknown to me, but I assume it's used as bait, to make users want to open the malicious password.txt.ink file. Using the attackers own wallet file for that seems very unlikely.. Wink

The malicious file is probably a wallet stealer and with some luck it might indeed be possible to extract some information about the attacker. Somehow this malware will phone home.

1715369535
Hero Member
*
Offline Offline

Posts: 1715369535

View Profile Personal Message (Offline)

Ignore
1715369535
Reply with quote  #2

1715369535
Report to moderator
1715369535
Hero Member
*
Offline Offline

Posts: 1715369535

View Profile Personal Message (Offline)

Ignore
1715369535
Reply with quote  #2

1715369535
Report to moderator
1715369535
Hero Member
*
Offline Offline

Posts: 1715369535

View Profile Personal Message (Offline)

Ignore
1715369535
Reply with quote  #2

1715369535
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
klenker
Member
**
Offline Offline

Activity: 80
Merit: 10


Prospecting on the net, in a rundown old shack..


View Profile
January 08, 2014, 02:29:37 PM
 #42

Was the fist to get hacked now everyone thinks im the attacker. The name Liquid and the other names are my contacts in my wallet.

That frosty wallet is my brothers and he has forgotten his password so good luck getting into it lol.

Ooh ooh how many letters were in it, numbers, what did it start with, what was he looking at, does it contain words or rand.... ahhh nurts..

Wink

must be slightly annoying having 28k sitting there tho...

BTC: 1LJk6Ck83fqwoCzFB7KqHVkurhsFfuk9zv
LTC: LP1LBMd4Cxth8uada3wF2kTZu8ub7LfyRH
FTC: 6gsQ1WqzpEi8ioQ3irkhjVj8z7Wznos12C
--
mightyMight
Member
**
Offline Offline

Activity: 73
Merit: 10


View Profile
January 09, 2014, 09:23:57 AM
 #43

Can someone please upload the zip file? I would love to check it out! Cool

Thanks!!!
 Might
xanthar
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
January 14, 2014, 09:55:11 AM
 #44

Got the email to.

No doubt the password.txt contains malware ect. ect.

Tho the wallet.dat seemssomewhat legit???

By that i mean that i created a virtual machine on a third party device connected through a VPN. That contains nothing but the wallet.dat and a fresh copy of bitcoinqt. Loaded the wallet.dat and the 30 Btc´s are there.

Now correct me if i am wrong.... But the BTC´s seems to be there for tha taking? If ofcourse we could crack the password right?

Disregarding the malware and fake password.txt ect. it would be a fun project to see if we can do something with the coins??
bitcoinangel
Newbie
*
Offline Offline

Activity: 36
Merit: 0


View Profile
January 14, 2014, 10:09:52 AM
 #45

same here
Oj0
Member
**
Offline Offline

Activity: 100
Merit: 10


View Profile
March 22, 2014, 02:33:10 PM
 #46

Yep, I got the exact same thing. What site do we all have in common?

This one? Grin
Aside this, we can look at other potentials. Strike through those you're not registered on and we may find one in common.

bc-casino.com
bitcoinica.com
bitfinex.com
bitfunder.com
bitmit.net
bitratings.microhosting.com
blockchain.info
btc-play.com
btcguild.com
btclot.com
btcmine.com
bitvps.com
coinworker.com
dollar-trader.com
eclipsemc.com

give-me-coins.com
glbse.com
inputs.io
minethings.com

mtgox.com
ozco.in
pool-x.eu
satoshisquared.com



(I'm pretty sure I received a very similar email a good while ago, too. My memory's crap, though. No longer in email account. Probably deleted or marked as spam and it was automatically pruned.)

I just got the same email, but mine was addressed to Steven.

Someone else already crossed out give-me-coins, so I guess MtGox is the source of the mailing list?
Oj0
Member
**
Offline Offline

Activity: 100
Merit: 10


View Profile
March 22, 2014, 02:42:49 PM
 #47

Wait, mine's slightly different:

Quote
Hello Steven…
 
 I just did what you advised me to do but the problem remains the same : importing the private key is not working…. drives me nuts!
 Last time I checked blockchain.info  https://blockchain.info/address/17yFutSCSuUkAWeqMCKRRcr8Go6t98YcoX 
 there was still 30.28020001 BTC ! But no way my bitcoinqt client loads the key so I am stuck with those BTCs.
 
 
 Thanks for offering your help with this. Here is a doc with my private key and the password http://hobbymaster.com.hk/private/PrivateKey.doc If you need anything else let me know.
 If you can load the key please send the BTCs to 1DxFvJ6up9jXAZ9pkUmWVdiMTWvsjgB5Ea
 
 This would help me so much. Thanks Steven!

I get a normal URL instead of a shortened [Suspicious link removed] link, and the URL is also different to the [Suspicious link removed] URL destination. I didn't get any attachments with the email, although I did download PrivateKey.doc on my phone (to be safe) and it wants to run a macro. It seems it's been changed up a bit.
Anon136
Legendary
*
Offline Offline

Activity: 1722
Merit: 1217



View Profile
March 22, 2014, 02:43:31 PM
 #48

Scary. Disguised txt.

so does it actually look like a perfectly normal txt file?

Rep Thread: https://bitcointalk.org/index.php?topic=381041
If one can not confer upon another a right which he does not himself first possess, by what means does the state derive the right to engage in behaviors from which the public is prohibited?
Garryashas
Member
**
Offline Offline

Activity: 72
Merit: 10


View Profile
March 22, 2014, 02:44:08 PM
 #49

For sure it's legit. I got the same email!
God
Member
**
Offline Offline

Activity: 169
Merit: 10


View Profile
March 23, 2014, 03:30:59 AM
 #50

Awesome, I just got this mail too. Now I just need to unpack and run that file and I will have access to these coins Wink

Seriously though, they obviously email the mtgox customer base.

manoamano
Full Member
***
Offline Offline

Activity: 182
Merit: 100


View Profile
March 23, 2014, 12:12:14 PM
 #51

100% legit Smiley
Scamalert
Hero Member
*****
Offline Offline

Activity: 490
Merit: 500


Captain


View Profile
July 17, 2014, 07:09:40 PM
 #52

So was it a scam after all?
ezreal
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
July 17, 2014, 07:44:45 PM
 #53

the bitcoin amount just gives it away saying all red flags lol.
yunkie
Member
**
Offline Offline

Activity: 83
Merit: 10


View Profile
July 18, 2014, 05:32:00 PM
 #54

So was it a scam after all?

of course it was

to sum it up

-.txt file is an .exe malware
-.dat is a real file, no password --> no coins

might try to crack it but it's almost impossible!

It probably contain 0 coin lol
openyourmind
Member
**
Offline Offline

Activity: 83
Merit: 10


View Profile
July 18, 2014, 06:58:22 PM
 #55

Be attentive to such emails. I wouldn't opened it
Mobius7
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500



View Profile
July 19, 2014, 08:38:11 AM
 #56

So was it a scam after all?

of course it was

to sum it up

-.txt file is an .exe malware
-.dat is a real file, no password --> no coins

might try to crack it but it's almost impossible!

It probably contain 0 coin lol

Even if there really is some bitcoin in the wallet, you won't be able to brute-force the password as long as the password is good enough (say, 10 random characters with special characters).

Justin00
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
July 19, 2014, 11:00:11 AM
 #57

Thanks for alerting us to this scamalert.... only 7 months to late :p

So was it a scam after all?

confirmation120
Full Member
***
Offline Offline

Activity: 224
Merit: 100



View Profile
July 20, 2014, 04:27:18 AM
 #58

So was it a scam after all?

of course it was

to sum it up

-.txt file is an .exe malware
-.dat is a real file, no password --> no coins

might try to crack it but it's almost impossible!

It probably contain 0 coin lol

Even if there really is some bitcoin in the wallet, you won't be able to brute-force the password as long as the password is good enough (say, 10 random characters with special characters).
I doubt that clicking on the link would direct you to a blockchain.info website, but rather it is likely a spoof of blockchain.info trying to get you to input your password.
Lorenzo
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250



View Profile
July 20, 2014, 05:27:03 AM
 #59

I got this email too a while ago.

Yep, I got the exact same thing. What site do we all have in common?

This one? Grin
Aside this, we can look at other potentials. Strike through those you're not registered on and we may find one in common.

bc-casino.com
bitcoinica.com
bitfinex.com
bitfunder.com
bitmit.net
bitratings.microhosting.com
blockchain.info
btc-play.com
btcguild.com
btclot.com
btcmine.com
bitvps.com
coinworker.com
dollar-trader.com
eclipsemc.com
give-me-coins.com
glbse.com
inputs.io
minethings.com
mtgox.com
ozco.in
pool-x.eu
satoshisquared.com


(I'm pretty sure I received a very similar email a good while ago, too. My memory's crap, though. No longer in email account. Probably deleted or marked as spam and it was automatically pruned.)

Of those, I've only been registered at Blockchain.info and Mtgox.com. I'm almost certain it's either this forum or Mt. Gox. It could have been from Blockchain.info, but I doubt it.
forever21
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


View Profile
July 20, 2014, 06:38:01 AM
 #60

got the same email before but i didnt waste my time on it besides its obvious Grin its not legit even if you said it looks like one
Pages: « 1 2 [3] 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!