Bitcoin Forum
May 11, 2024, 05:16:43 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Trading Bot - Malware  (Read 557 times)
Bitcoin_Arena (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1788


฿itcoin for all, All for ฿itcoin.


View Profile
April 07, 2019, 10:32:00 PM
 #1

What happened: User is sharing and encouraging people to download a file containing malware claiming it's a trading bot

Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=1967920

ANN: https://bitcointalk.org/index.php?topic=3218780.
[Archived]: http://archive.is/phikj

Website: https://github.com/CryptoProfitTeam/tradelab
[Archived]: http://archive.is/nDbaU

Virustotal had 25 Engines detect the so called bot as malware

https://www.virustotal.com/#/file/f62cbe39ba844361f08f91edf59ca8c098d4a85218cf84f67880616d9ef743e4/detection



Additional Notes
The github profile which is hosting the file; https://github.com/CryptoProfitTeam, is only 5 days old.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Bitcoin mining is now a specialized and very risky industry, just like gold mining. Amateur miners are unlikely to make much money, and may even lose money. Bitcoin is much more than just mining, though!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715447803
Hero Member
*
Offline Offline

Posts: 1715447803

View Profile Personal Message (Offline)

Ignore
1715447803
Reply with quote  #2

1715447803
Report to moderator
1715447803
Hero Member
*
Offline Offline

Posts: 1715447803

View Profile Personal Message (Offline)

Ignore
1715447803
Reply with quote  #2

1715447803
Report to moderator
Bitcoin_Arena (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1788


฿itcoin for all, All for ฿itcoin.


View Profile
April 08, 2019, 07:18:19 PM
 #2

The user even woke up after along period of inactivity



Can we have atleast one DT member look into this and tag the culprit before the damage is done?  Wink

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3528
Merit: 9556


#1 VIP Crypto Casino


View Profile
April 08, 2019, 07:53:43 PM
 #3

Painted red Wink

It’s done.

.
.BITCASINO.. 
.
#1 VIP CRYPTO CASINO

▄██████████████▄
█▄████████████▄▀▄▄▄
█████████████████▄▄▄
█████▄▄▄▄▄▄██████████████▄
███████████████████████████████
████▀█████████████▄▄██████████
██████▀██████████████████████
████████████████▀██████▌████
███████████████▀▀▄█▄▀▀█████▀
███████████████████▀▀█████▀
 ▀▀▀▀▀▀▀██████████████
          ▀▀▀████████
                ▀▀▀███

.
......PLAY......
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
April 09, 2019, 11:16:46 PM
 #4

Github repo and entire account look like they have been removed as well... nice work Wink

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
timerland
Hero Member
*****
Offline Offline

Activity: 1526
Merit: 596


View Profile
April 10, 2019, 09:52:02 AM
 #5

What happened: User is sharing and encouraging people to download a file containing malware claiming it's a trading bot

Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=1967920

ANN: https://bitcointalk.org/index.php?topic=3218780.
[Archived]: http://archive.is/phikj

Website: https://github.com/CryptoProfitTeam/tradelab
[Archived]: http://archive.is/nDbaU

Virustotal had 25 Engines detect the so called bot as malware

https://www.virustotal.com/#/file/f62cbe39ba844361f08f91edf59ca8c098d4a85218cf84f67880616d9ef743e4/detection



Additional Notes
The github profile which is hosting the file; https://github.com/CryptoProfitTeam, is only 5 days old.

Great find. Can't believe though that it took over a year for someone to finally notice.  Undecided

Always verify with multiple sources what you are downloading onto your computer. And if a user is offering such software for free and posting public links it's probably nothing good. Think about it, the scammer's posting it in public to make a profit, and can only do so because of people downloading will be paying the price. So common sense alone tells us that either the software contains viruses, or will do something malicious with your exchange account.

Remember that legitimate trading bots are sold at a price, not offered for free. And always take what users without reputation is offering with a huge grain of salt, especially newbies that are offering some sort of get rich quick method. There is no such thing.

Smiley
Bitcoin_Arena (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1788


฿itcoin for all, All for ฿itcoin.


View Profile
April 11, 2019, 03:14:43 AM
 #6


Great find. Can't believe though that it took over a year for someone to finally notice.  Undecided

Always verify with multiple sources what you are downloading onto your computer.
Yep, I was also surprised that nobody who responded to the thread ever bothered to check the file let alone verify the sources of the file. All they made were replies and kept bumping the scammers thread which could have easily picked up the attention of a clueless victim.
This shows you how vulnerable people continue to be in this community so whenever I see search a thing, first step is to warn people and hopefully a couple of them learn.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!