Bitcoin Forum
May 03, 2024, 06:54:28 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Received an email and have no idea what it is.  (Read 1401 times)
Phinnaeus Gage (OP)
Legendary
*
Offline Offline

Activity: 1918
Merit: 1570


Bitcoin: An Idea Worth Spending


View Profile WWW
December 30, 2013, 02:48:14 PM
Last edit: December 30, 2013, 04:49:44 PM by grue
 #1

First off, I've never started a thread in this section before, and pretty sure I haven't posted in it, but now I seek advice as to what the following pertains to.

CAUTION: Don't click that URL unless it's somehow opened safely, for I don't know how to do such, hence seeking info.

Quote
Payment Notification Received !

Username: dabitcoinguy@gmail.com
Password: XXXXXXXXX
Current Balance: 1.XXXXXXXX BTC


It was in the spam folder, hence the concern.

Thank you in advance,

~Bruno Kucinskas

moderator action: made link into an image to prevent accidental copy/pasting and auto-hyperlinking scripts.
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
BitcoinCleanup.com: Learn why Bitcoin isn't bad for the environment
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
1714762468
Hero Member
*
Offline Offline

Posts: 1714762468

View Profile Personal Message (Offline)

Ignore
1714762468
Reply with quote  #2

1714762468
Report to moderator
Colin Miner
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile WWW
December 30, 2013, 02:59:08 PM
 #2

First off, I've never started a thread in this section before, and pretty sure I haven't posted in it, but now I seek advice as to what the following pertains to.

CAUTION: Don't click that URL unless it's somehow opened safely, for I don't know how to do such, hence seeking info.

Quote
Payment Notification Received !

Username: dabitcoinguy@gmail.com
Password: XXXXXXXXX
Current Balance: 1.XXXXXXXX BTC
URL : http://www,11verde.com/AdesSnewds

It was in the spam folder, hence the concern.

Thank you in advance,

~Bruno Kucinskas
Its a phishing attempt to get you to click the link  Cry

Don't click the link, there is probably a virus at the end of it


FREE Namecoins (NMC), Devcoins (DVC) and IxCoins (iXC) while you mine Bitcoins (BTC) on the pool, in the cloud or both. Free to join, click here to Sign Up and mine your free coins.
Cheap VPS Hosting here or budget conscious Free cPanel hosting here. Buy BTC the safe and easy way at Localbitcoins.com (US and UK).
 "I'm no longer as confident as I was this morning." - xkeyscore89.  My Addie.cc.
more Free: BTC, LTC, FTC, TIPS, WDC, EAC & IFC
Seccour
Legendary
*
Offline Offline

Activity: 1619
Merit: 1004


Bitcoiner, Crypto-anarchist and Cypherpunk.


View Profile
December 30, 2013, 03:14:39 PM
 #3

First off, I've never started a thread in this section before, and pretty sure I haven't posted in it, but now I seek advice as to what the following pertains to.

CAUTION: Don't click that URL unless it's somehow opened safely, for I don't know how to do such, hence seeking info.

Quote
Payment Notification Received !

Username: dabitcoinguy@gmail.com
Password: XXXXXXXXX
Current Balance: 1.XXXXXXXX BTC
URL : http://www,11verde.com/AdesSnewds

It was in the spam folder, hence the concern.

Thank you in advance,

~Bruno Kucinskas
Its a phishing attempt to get you to click the link  Cry

Don't click the link, there is probably a virus at the end of it



So OP, remove the link ^^

grue
Legendary
*
Offline Offline

Activity: 2058
Merit: 1431



View Profile
December 30, 2013, 04:34:26 PM
Last edit: December 30, 2013, 04:46:15 PM by grue
 #4

the link leads to a page with a java applet. very likely a drive-by download page.

edit: confirmed drive-by applet. launches regedit to disable UAC.

It is pitch black. You are likely to be eaten by a grue.

Adblock for annoying signature ads | Enhanced Merit UI
Phinnaeus Gage (OP)
Legendary
*
Offline Offline

Activity: 1918
Merit: 1570


Bitcoin: An Idea Worth Spending


View Profile WWW
December 30, 2013, 09:29:26 PM
 #5

the link leads to a page with a java applet. very likely a drive-by download page.

edit: confirmed drive-by applet. launches regedit to disable UAC.

Thanks, grue, assuming you disabled the link. I was toying with breaking it up so that it wouldn't work, but for some reason opted to give the warning in red instead.

Seldom do I click links in my email, and this one definitely didn't smell right.

Thanks to all that replied.

~TMIBTCITW
deepceleron
Legendary
*
Offline Offline

Activity: 1512
Merit: 1028



View Profile WWW
December 31, 2013, 05:01:05 AM
 #6

the link leads to a page with a java applet. very likely a drive-by download page.

edit: confirmed drive-by applet. launches regedit to disable UAC.
Is it able to do this on Java v45? If so, that's what we call zero-day, and it should be captured and sent to Oracle and virus companies.

Java has proved it can never be secure though, in that there has NEVER been a version where your computer couldn't get infected through it just by visiting a web page. Kill with fire.
Caiapfas
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
January 01, 2014, 01:40:53 AM
 #7

best policy never ever open anything or click any link unless you are expecting it and/or know who sent it. even if it's from someone/some business/some account you know or have and have doubt go directly to the website and login there and delete the email

If you liked my post or found anything I said useful send some coffee change to
BTC = 3LxtsmCjRDPD6oYYwz31dwFJW9ktUy1Yuz
rarkenin
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
January 01, 2014, 03:08:02 AM
 #8

NASTY VIRUS

Did a decompile and  analysis in a VM, looks very nasty. Disables UAC, downloads a remote access tool, and even crashes my decompiler due to obfuscation. Obviously very complex but also not too polished, debug statements printing to console remain.

PM me to get details about all of the source and a copy of the decompiled/original files, some of which are not directly accessible. I'll send it in a passworded ZIP, but once I send it to you it's YOUR responsibility not to run it.
gweedo
Legendary
*
Offline Offline

Activity: 1498
Merit: 1000


View Profile
January 01, 2014, 03:25:42 AM
 #9

I got this same email of course I didn't click it.
U1TRA_L0RD
Full Member
***
Offline Offline

Activity: 126
Merit: 100

CAUTION: Angry Man with Attitude.


View Profile
January 01, 2014, 03:31:34 AM
 #10

I opened this on my old virus tester laptop and its very nasty, now to go reinstall windows XP.
NixZiZ
Member
**
Offline Offline

Activity: 64
Merit: 10


View Profile
January 28, 2014, 02:07:08 PM
 #11

Ouch... Happy I googled this first!


Now to hook up a nice, shiny XP VM, shut off the network after the nasty installs... and see what happens! No patches, of course.

I guess I'll post a video of it later too, just for shits. Smiley
U1TRA_L0RD
Full Member
***
Offline Offline

Activity: 126
Merit: 100

CAUTION: Angry Man with Attitude.


View Profile
January 28, 2014, 02:22:53 PM
 #12

I got this same email of course I didn't click it.
I guess this iswhy we dont show our emails to the community.
Caesium
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


View Profile
January 28, 2014, 05:16:08 PM
 #13

I got this same email of course I didn't click it.
I guess this iswhy we dont show our emails to the community.
No cause for everyone of those emails I get, I get 100 emails to do business Wink

That's an impressive ratio. Mine is more like for every 1 legit email, I get 100 of these phishing/spams.

Tired of annoying signature ads? Ad block for signatures
Caiapfas
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
January 28, 2014, 05:42:00 PM
 #14

I opened it and it gave me 3 BTC....OMG they are lying to you. open it open it.


 Wink

If you liked my post or found anything I said useful send some coffee change to
BTC = 3LxtsmCjRDPD6oYYwz31dwFJW9ktUy1Yuz
U1TRA_L0RD
Full Member
***
Offline Offline

Activity: 126
Merit: 100

CAUTION: Angry Man with Attitude.


View Profile
January 28, 2014, 06:16:21 PM
 #15

I opened it and it gave me 3 BTC....OMG they are lying to you. open it open it.


 Wink
You owe me a new laptop.
Sonny
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
January 30, 2014, 10:25:44 AM
 #16

I opened it and it gave me 3 BTC....OMG they are lying to you. open it open it.


 Wink
You owe me a new laptop.

lol Tongue
Caiapfas
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
January 30, 2014, 08:09:50 PM
 #17

No need to ask this every again Smiley. If the email is from unknown or even know sources and has links go directly to the site and login and see it there.

Delete the email...

problem solved.

No matter how good antivirus, firewall or other protection you have it only takes one stupid user to fuck it all up.


To the rest of us, this is why spam and viruses exist ...stupid users. If everyone deleted spam, spamming would dry up in a month.

If you liked my post or found anything I said useful send some coffee change to
BTC = 3LxtsmCjRDPD6oYYwz31dwFJW9ktUy1Yuz
roslinpl
Legendary
*
Offline Offline

Activity: 2212
Merit: 1199


View Profile WWW
January 30, 2014, 08:47:42 PM
 #18

First off, I've never started a thread in this section before, and pretty sure I haven't posted in it, but now I seek advice as to what the following pertains to.

CAUTION: Don't click that URL unless it's somehow opened safely, for I don't know how to do such, hence seeking info.

Quote
Payment Notification Received !

Username: dabitcoinguy@gmail.com
Password: XXXXXXXXX
Current Balance: 1.XXXXXXXX BTC


It was in the spam folder, hence the concern.

Thank you in advance,

~Bruno Kucinskas

moderator action: made link into an image to prevent accidental copy/pasting and auto-hyperlinking scripts.

looks scam for me.
But Smiley maybe you re 1 btc reacher :"P
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!