Bitcoin Forum
April 02, 2026, 12:39:03 PM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 [83] 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 »
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 49272 times)
Ambatman
Legendary
*
Online Online

Activity: 966
Merit: 1266


Don't tell anyone


View Profile WWW
February 03, 2025, 07:53:09 AM
Merited by Lafu (1)
 #1641

They are back again.

https://bitcointalk.org/index.php?topic=5528647.0
https://bitcointalk.org/index.php?topic=5528647.msg65021190#msg65021190


Opening thread and locking them, while posting suspicious drive link.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Ambatman
Legendary
*
Online Online

Activity: 966
Merit: 1266


Don't tell anyone


View Profile WWW
February 04, 2025, 06:37:03 AM
Merited by Lafu (1)
 #1642


https://bitcointalk.org/index.php?topic=5528795.0

Even the addresses are been changed.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Ambatman
Legendary
*
Online Online

Activity: 966
Merit: 1266


Don't tell anyone


View Profile WWW
February 09, 2025, 10:07:17 PM
Merited by Mitchell (1), Lafu (1)
 #1643

https://bitcointalk.org/index.php?topic=5529655.msg65045232#msg65045232





They are now using double spending help?

The thread is titled Double spending help
Though the Moderators have done a great job eliminating them
More are still coming with same title and strategy of locking the thread.
Since it's not the Amazons malware, I think Mitchell
 could still find this here

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
MiningCoinsPool
Member
**
Offline Offline

Activity: 565
Merit: 27


View Profile
February 10, 2025, 02:19:11 PM
Merited by Lafu (1)
 #1644

Same guy again with trojans in windows Binaries:

https://cooldinoo.com/#download

https://bitcointalk.org/index.php?topic=5529693.0

https://www.virustotal.com/gui/file/68cf6f31e2d3f23948d71df9dba8697654965fdfca07ca42f6595cb81f1c9a92/detection
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
February 10, 2025, 04:40:28 PM
 #1645

Yeb , thanks for the Virustotal file , and basicly answer my thoughts that i have got already about it.
For some reason it wasnt possible to download the file from the Webpage and check the Wallet File.
I was to 90% sure that it is the same sheme aat we got in the past with all that Malware Shit Links.

Its the same Malware and trojan shit.

The Githug Account is also Fake here and was just created 2 days ago !

Fake Github : github.com/CoolDinoo

Zenbox flags this file as: MALWARE TROJAN EVADER RAT
Code:
Drops script at startup location
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Dot net compiler compiles file from suspicious location
Suspicious DNS Query for IP Lookup Service API
PowerShell Script Run in AppData
Startup Folder File Write

ET MALWARE Observed Malicious SSL Cert (Quasar CnC)
ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert
SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)
ET INFO External IP Lookup Domain in DNS Lookup (ipwho .is)
Source : https://www.virustotal.com/gui/file/68cf6f31e2d3f23948d71df9dba8697654965fdfca07ca42f6595cb81f1c9a92/behavior

Please Report the Fake Github Account and also the User CoolDino here
Ambatman
Legendary
*
Online Online

Activity: 966
Merit: 1266


Don't tell anyone


View Profile WWW
February 15, 2025, 06:44:55 PM
Merited by Mitchell (1)
 #1646



https://bitcointalk.org/index.php?topic=5531138.msg65066573#msg65066573

New Title: One confirmation Spending

They are now targeting the gambling board, though Mods have dealt with it promptly
There's a likelihood more would sprang up with the same name.

I'm going to tag @Mitchell to add the title to his Bot.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Ambatman
Legendary
*
Online Online

Activity: 966
Merit: 1266


Don't tell anyone


View Profile WWW
February 16, 2025, 06:38:48 AM
Last edit: February 16, 2025, 04:22:40 PM by Ambatman
Merited by Mitchell (1), Lafu (1)
 #1647



New Title: G2A METHOD

https://bitcointalk.org/index.php?topic=5531211.msg65068116#msg65068116

If I'm not mistaken, by their history the subsequent posts would have G2A in it with continuous changes to try and bypass the spam Bot.

I'm quite surprised they have left Bitcoin discussion and beginners and help board
I guess it wasn't working out well for them.




Edit :
New Title : Get anything from G2A for FREE

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
MiningCoinsPool
Member
**
Offline Offline

Activity: 565
Merit: 27


View Profile
February 18, 2025, 03:22:17 PM
Merited by Lafu (1)
 #1648

Looks like same guy again, same pattern, self-moderated topic, same warnings in virustotal, same explorer etc.

https://bitcointalk.org/index.php?topic=5532447.0
https://www.virustotal.com/gui/file/f0fbc56a389469681d98400a84ca0895dc4b332fd3242ebcc11bd0a996765f8e/details
https://drakoworld.com
https://github.com/Drako-World/Core
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
February 18, 2025, 04:52:32 PM
 #1649

Looks like same guy again, same pattern, self-moderated topic, same warnings in virustotal, same explorer etc.
https://www.virustotal.com/gui/file/f0fbc56a389469681d98400a84ca0895dc4b332fd3242ebcc11bd0a996765f8e/details
Code:
https://drakoworld.com
https://github.com/Drako-World/Core
Yeb now thanks to you as i got the evidence now with the Virustotal Link !
I was earlier on it and also on the Webpage and tried a few times to download the Wallet file from there , but i dont know why i cant download that Wallet.7z !
I also was sure that it is a Fake Ann to 80% as all the patterns are the same as from the other Fake Anns.

Code:
The sandbox Zenbox flags this file as: MALWARE TROJAN EVADER RAT
Source : https://www.virustotal.com/gui/file/f0fbc56a389469681d98400a84ca0895dc4b332fd3242ebcc11bd0a996765f8e/behavior

The Fake Github was just created 5 days ago.

Hacker Account : DrakoMoon <--- Please ban or Lock that Account and delete the Thread
Account was just registered today.
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
February 22, 2025, 03:59:56 AM
 #1650

And we have again some Fake Ann with an Fake Webpage , Fake Github and an Malware download Wallet from the Webpage this time for Omnixium !

The Fake Github was created just 2 days ago.
Fake Github : github.com/omnixium-network

Fake Website:
Code:
https://www.omnixium.org

When you download the Wallet File from the Webpage its the same as we got for all the other Fake Anns in the last weeks.

The sandbox Zenbox flags this file as: MALWARE TROJAN EVADER RAT
Code:
Win64:Evo-gen [Trj]

Drops script at startup location
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Dot net compiler compiles file from suspicious location
Suspicious DNS Query for IP Lookup Service APIs
PowerShell Script Run in AppData
Startup Folder File Write

ET MALWARE Observed Malicious SSL Cert (Quasar CnC)
ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert
ET INFO External IP Lookup Domain in DNS Lookup (ipwho .is)
SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)
Source : https://www.virustotal.com/gui/file/a7d398f4fd29d64bd163555ea1186e63d8bf5acf866a2c11ebbcc7c9ac3af1b2/behavior

Account : omnixium  <--- Please ban or Lock that Account and delete the Thread
Just a new registered Account a few days ago , maybe the Account hacked in the last days.

Fake Ann Thread :  🚀 [ANN] Omnixium - Hybrid PoW/PoS | Secure, Scalable & Community-Driven

Omnixium (OMNX)
Code:
https://omnixium.org
https://www.omnixium.org/#wallet

This post is also a reference for the Github Report !
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
February 27, 2025, 03:11:38 AM
Merited by $crypto$ (1), mole0104 (1)
 #1651

And we have the next Fake Ann with an Fake Webpage and Fake Github Account with Malware download Link , this time for Frimo !

The Fake Github was only created 6 Hours ago.
Fake Github : github.com/Frimooo

Fake Webpage and Wallet download:
Code:
https://frimooo.org/
https://slategray-bison-852952.hostingersite.com/wp-content/uploads/2025/02/frimo-qt-windows.7z

And its the same here as all the other Fake Anns got with the Fake Wallet File:
Code:
Win64:Evo-gen [Trj]

Drops script at startup location
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Dot net compiler compiles file from suspicious location
Suspicious DNS Query for IP Lookup Service APIs
PowerShell Script Run in AppData
Startup Folder File Write

ET MALWARE Observed Malicious SSL Cert (Quasar CnC)
ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert
ET INFO External IP Lookup Domain in DNS Lookup (ipwho .is)
SLBL: Malicious SSL certificate detected (QuasarRAT C&C)
Source : https://www.virustotal.com/gui/file/01851e9d270383ddb8a9994269f7168bb057612707ddbc607462356136085ae3/behavior

Account : FRIMOOO  <--- Please ban or Lock that Account and delete the Thread
That Account just joined the Forum yesterday and is new.
 
Fake Ann Thread :  [ANN] 🌿 Frimo: Redefining Social Networking with Blockchain Privacy 🌿

Frimo
Code:
https://frimooo.org
https://github.com/Frimooo

This post is also a reference for the Github Report !
$crypto$
Legendary
*
Offline Offline

Activity: 3052
Merit: 1233


Smart is not enough, there must be skills


View Profile WWW
March 06, 2025, 08:04:39 AM
Last edit: March 06, 2025, 10:06:05 AM by $crypto$
Merited by albon (1)
 #1652

I also found a fake Ann and a fake webpage as well as a possibly fake Github account.

Account: J-1
Fake ANN: Re: VEC0 Crypto Currency: A New Chapter For Our Community BY The Community
Archived Post: https://ninjastic.space/post/65135322

Code:
Find the updated GUI easy to use Miner at GitHub = [url=https://github.com/vecocoin/GUI-miner/releases/tag/v1.1.0]https://github.com/vecocoin/GUI-miner/releases/tag/v1.1.0[/url]

Test results from virustotal:
https://www.virustotal.com/gui/file/7992bea3ddda240c28a2a06a11fec726f5e379edb3c9e4141af4aab6cbb433e1/detection


R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
albon
Legendary
*
Online Online

Activity: 2394
Merit: 2177



View Profile
March 06, 2025, 02:47:30 PM
Merited by Lafu (1), $crypto$ (1)
 #1653

Account: solugbemi <--- Please ban this account and delete the three topics he posted:

Topic [1]: https://bitcointalk.org/index.php?topic=5534117.0
Topic [2]: https://bitcointalk.org/index.php?topic=5528580.0
Topic [3]: https://bitcointalk.org/index.php?topic=5534070.0

This user has shared a tool related to Solana AI Trader that contains a trojan. He uploaded the tool to MediaFire, locked with a password. After extracting the RAR file, the following files are found: Solana Panel.exe, dxcompiler.dll, d3dcompiler_47.dll, and dxil.dll

This is the download link for the malicious tool:
Code:
www[.]mediafire.com/file/meimlxh7hdl4ts7/Solana_MEME_Panel.zip/file

After uploading the files to VirusTotal for analysis, the scan results were as follows:



Source: https://www.virustotal.com/gui/file/1bb6cd723bba420e84edc9d2072ea31f457543bd03b385779e06e8b612485187

Dynamic Analysis Sandbox Detections:

The sandbox CAPE Sandbox flags this file as: MALWARE STEALER
The sandbox Zenbox flags this file as: MALWARE STEALER TROJAN EVADER RAT

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
March 06, 2025, 05:15:33 PM
Merited by albon (1)
 #1654

This user has shared a tool related to Solana AI Trader that contains a trojan. He uploaded the tool to MediaFire, locked with a password.
Source: https://www.virustotal.com/gui/file/1bb6cd723bba420e84edc9d2072ea31f457543bd03b385779e06e8b612485187
Nice catch and find and for sure a very shady Link with all that detections.
Really appreciate that and that you reported it.

I also found a fake Ann and a fake webpage as well as a possibly fake Github account.
I dont know or can say that its to 100% a Fake Ann or an Fake Webpage.
About the Github Account also as there are many other things that looks legit.


Code:
Find the updated GUI easy to use Miner at GitHub = [url=https://github.com/vecocoin/GUI-miner/releases/tag/v1.1.0]https://github.com/vecocoin/GUI-miner/releases/tag/v1.1.0[/url]
Test results from virustotal:
https://www.virustotal.com/gui/file/7992bea3ddda240c28a2a06a11fec726f5e379edb3c9e4141af4aab6cbb433e1/detection
About the Virustotal detections there are many false positiv detections as it is an Miner Software.
But there are for sure some Trojan and Malwareshit in it so i guess its good when it gets deleted and the User banned.
Code:
Trojan.Malware.121218.susgen
Trojan.Agent
Trojan.Win32.Save.a
Adware.GenericKD.61026810
Trojan.Disco.Win32.12840
Static AI - Malicious Archive
Generic.Malware.AI.DDS
Malicious (high Confidence)
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
March 07, 2025, 05:38:51 PM
Merited by N.O (1)
 #1655

And we got another new Fake Ann with an Fake Webpage and Fake Github Account with Malware this time for BRIMSTONE (BRM) !

The Fake Github Account is already deleted.
Fake Github : github.com/brimstonecore

Also its the same sheme as for the other last Fake Anns and Webpages with there Wallet download there.
Mostly the Wallet download Files are a Wallet.7z file .

Fake Webpage and Wallet download File:
Code:
https://brimstonecoin.com
https://download.brimstonecoin.com/files/brimstone-qt-windows.7z

Virustotal Flaggs the Wallet File as an Malware even there are no detecions.
Code:
 CAPE Sandbox flags this file as: MALWARE

If you look closer in it there are a lot of changes going on in the Windows and User Folders when you install it.
You can read and look all here : https://www.virustotal.com/gui/file/6dab46cb3812dac186c194aa9dedb10e59dcb195011721c13b274a8a7cb49d4c/behavior

On top of that the User MiningCoinsPool that runs an Mining Pool als found some Trojan in the Windows binaries.
https://ninjastic.space/post/65142123

Hacker Account :  _BRIMSTONE_  <--- Please ban or Lock that Account and delete the Thread
The Account was just created today.

Fake Ann Thread :  🔥[ANN] BRIMSTONE (BRM) | Hybrid PoW+PoS Scrypt | Mine, Stake & Earn Rewards!🔥

Code:
https://brimstonecoin.com
https://github.com/brimstonecore/brimstonecoin
https://brimstonecoin.com/#downloads

This post is also a reference for the Github Report !
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
March 12, 2025, 04:18:07 PM
 #1656

This post is for now only for Information and the records as in my opions it is an Fake Ann as it is flagged as Malware on  Virustotal !
This time its about DynastyCoin.

The Github is only an week old and created.
Github Account : github.com/Dynasty-Chain

There was already an Coin back in the days that was called DynastyCoin from 2018 [ANN]DINASTYCOIN✅ENJOY ITALY✅MANDATORY UPDATE⚡NEW THREAD⚡SINCE 2015⚡

The sheme of the Wepage and the download of the Wallet is nearly the same as we got in the past from other Fake Anns.
Also the Wallet download File from the Webpage is flagged as an Malware from Virustotal.

Quote
The sandbox CAPE Sandbox flags this file as: MALWARE
Source : https://www.virustotal.com/gui/file/f6f01a7511eb47cb9b64fd9d9865cc7cea9d8d347e610541981ca78f9417b37c/behavior

It has the same sheme as the last Fake Ann.
Also when i download the File from the Webpage Microsoft Defender gives me a warning that this File is Malware.

Account : Dynasty_Chain  <--- Please ban or Lock that Account and delete the Thread
The Account was just created on March 05, 2025 and the last Fake Anns was also created from Accounts that got a Copper Member.
There is not much proof about it but i know from my experience that its an Fake Ann.

Fake Ann Thread :   [ANN] DynastyCoin | Build Your Crypto Dynasty | Scrypt PoW |

Code:
https://github.com/Dynasty-Chain]
https://dynastychain.org/

I am 100% sure that it is an Fake Ann and the sheme is mostly the same as we got in the past.


This post is also a reference for the Github Report !
$crypto$
Legendary
*
Offline Offline

Activity: 3052
Merit: 1233


Smart is not enough, there must be skills


View Profile WWW
March 14, 2025, 09:43:16 AM
Last edit: March 14, 2025, 12:35:01 PM by $crypto$
Merited by Lafu (1)
 #1657

Reporting fake threads from farcaster Mining.

Account: Dogecaucus Please ban
FAKE Ann: [ANN] farcaster Mining

Code:
For detailed instructions and mining setup, visit our official https://github.com/farcaster-development

Virus Total: https://www.virustotal.com/gui/file/3c709c7187db368f630d979b52e737cbb39dd7d8ab648ac56ef291a736f048a1/detection

Farcaster official Github = https://github.com/farcasterxyz

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
N.O
Sr. Member
****
Offline Offline

Activity: 686
Merit: 407



View Profile
March 17, 2025, 10:44:16 PM
 #1658

We have found a new Fake Ann topic with virus wallet hacked/sold account was posted

Account link : galaxywars <<<<Please Ban this account

Fake Ann topic: DARK Galaxy Wars Equihash Heavy (192,7) **70%** and PoS of **30%** please remove this topic

Code:
Wallets:
https://github.com/galaxywarscoin/GalaxywarsOcean/releases/download/v0.9.0/dark-gui-linux.zip
https://github.com/galaxywarscoin/GalaxywarsOcean/releases/download/v0.9.0/dark-gui-macos.zip
https://github.com/galaxywarscoin/GalaxywarsOcean/releases/download/v0.9.0/dark-gui-windows.zip

VirusTool:

https://www.virustotal.com/gui/file/1de7c450f9a4a4f12c1360f3e4c4caf6a4fec10391094560f5c4ef4b70d64381

https://www.virustotal.com/gui/file/6ce3bad05ee7fd891dd96a12fe49d104fd6c3610015df4db227173751981695c

https://www.virustotal.com/gui/file/45016e4d15eef40819fac159c2528482c0de563ca17fa4f8bed5e137486a129f

This post is used as reference to report GitHub Account











██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
N.O
Sr. Member
****
Offline Offline

Activity: 686
Merit: 407



View Profile
March 18, 2025, 02:35:53 AM
Merited by Lafu (1)
 #1659

Another fake phoenix miner topic was posted by newbie with Torjan Virus

Account link: OggyDev <<<< Please Ban this account

Fake Topic Link: PhoenixMiner 6.3c: fastest Ethereum/Ethash miner with lowest devfee (Win/Linux) please delete this topic

 
Code:
https://store4.gofile.io/download/web/85b1f041-911e-4e40-9b55-49d172b50982/PhoenixMiner_6.3c_Windows.rar

This post is used as reference to report GitHub Account











██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Lafu (OP)
Legendary
*
Offline Offline

Activity: 3542
Merit: 4501



View Profile
March 19, 2025, 04:51:02 PM
Merited by N.O (1)
 #1660

You should be careful when you reporting and accusing other Accounts for posting Fake Malware things and maybe pay attention to the details.

I also checked that Ann that you mentioned in your post , when it was created as i was not sure about it.
From all the Links you posted the results from Virustotal and about the detections most of them are flagged as Coinminer software integrated in the wallet.

Even there are more detections as other Wallets have you should be looking more into the behavior on Virustotal.
Here you can see whats going on with all the Files and what they are doing.

I respect a lot that you reporting things and write here and its worth a lot of getting possible things deleted that looks like some Fake things.
But from what i can see is that the User is not banned and have already done another Ann here : 🌌 DARK: Mining, Gaming, Profit! Build Your Cosmic Empire in DARK Galaxy Wars!
So i guess the Moderators have been coming to the same conclusion as i.

But i will be watching that Topic for sure.
Pages: « 1 ... 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 [83] 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!