Bitcoin Forum
July 29, 2026, 11:34:43 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 [106]
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 53239 times)
Charcol
Full Member
***
Offline

Activity: 294
Merit: 239



View Profile
July 27, 2026, 05:21:48 AM
Last edit: July 27, 2026, 07:32:30 AM by Charcol
Merited by Lafu (1)
 #2101

User: lakmali123 <-----  Please Ban this User

Fake ANN thread:
[ANN] PYTHRAX - Welcome to the official thread!

Fake File:
Code:
https://github.com/PYTHRAX/PYTHRAX/releases/download/v1.0.0/PYTHRAX-v1.0.0-win-x64.zip

Edit: I would like to draw the attention of the moderator. I reported this thread a long time ago, but no action has been taken against it even though the wallet file associated with the thread contains the malicious trojan.yogi/geninflated. I am providing the proof below, please take action against the thread and the user.

Reference:
https://www.virustotal.com/gui/file/6131b5684f5b07c6213752bdde80a91d2554c43b757be09e550c0dad11cb78f6?nocache=1

P2PKH_dude
Copper Member
Newbie
*
Offline

Activity: 10
Merit: 4


View Profile
July 27, 2026, 08:59:09 PM
 #2102

I just compiled the source code from the GitHub repo, and the resulting Windows NSIS installer produces a similar VirusTotal report.

Given that the source code looks clean (as far as I can tell), I'd lean towards this being a false positive.

Nothing is certain in life, but VirusTotal is notorious for producing false positives when it comes to crypto software. I'd suggest also compiling from source to see if you get a similar report.
Yes it does but the attempts to spread malware through the forum are quite rampant which is why these folks are doing a good job to clean the forum off malware. False positives can be contested as the reports can never be 100% accurate but most of them at least are. I think I have seen it happen before, but the member hasn't bothered to come around and appeal.

Yeah, of course, I'd say it's better to have false positives rather than false negatives, given how many people just download and run stuff without a second thought. I'm also grateful for the screening these guys do!

I'll see if I can get a hold of the BitcoinIII dev about this malware report (assuming it's a false positive). I used to be in the Discord group, and he mentioned being banned from here but not knowing why. Anything I should mention to him regarding defending his case or appealing?
AakZaki
Legendary
*
Online Online

Activity: 2674
Merit: 2362


Lightning⚡zkNodes


View Profile
July 28, 2026, 01:03:48 AM
 #2103

According to what I understand about "Sysmon File Executable Creation Detected" is to be able to try new files that can be injected remotely.

Account: RGM-Core<= Please Banned
Fake ANN Thread: [ANN] RGMChain (RGM) — Dogecoin fork w/ native post-quantum (ML-DSA-44) addresse
archive

Code:
GitHub (node): https://github.com/rgmchain/rgm
Wallet: https://github.com/rgmchain/rgmwallet



VirusTotal Scan Result:https://www.virustotal.com/gui/file/ea8f1480a8fe837c0edebe122f4552722a585781cc40d4943c526f6305d516b0/behavior

Code:
Disable or Modify Tools:

Description
Tries to unhook or modify Windows functions monitored by CAPE
Match
Process rgmd.exe
{"unhook": "function_name: DnsQuery_UTF8, type: restored"}
{"unhook": "function_name: DnsQuery_W, type: restored"}
Show less
Description
Creates guard pages, often used to prevent reverse engineering and debugging
Match
page read and write | page guard
------------------------------------------------------

Data from Local System:

Description
Attempts to access Bitcoin/ALTCoin wallets
Match
C:\Users\Bruno\AppData\Roaming\RGM\wallet.dat
------------------------------------------------------

Application Layer Protocol:

Description
Starts servers listening on 127.0.0.1:0, ::1:22555, 127.0.0.1:22555, :::14030, 0.0.0.0:14030
Match
Process rgmd.exe
Description
Attempts to connect to a dead IP:Port
Match
Process rgmd.exe

According to an analysis:
  • Disable or Modify Tools - allows malware to bypass antivirus
  • Data from Local System - allows malware to access wallet.dat, Bitcoin/ALTCoin wallets
  • Application Layer Protocol - allows malware to communicate to the Command & Control (C2) server

The simple visuals are as follows:
Code:
User run file
      ↓
Anti-detection (unhook + anti-debug)
      ↓
Drop executable (payload)
      ↓
Access wallet.dat (target)
      ↓
Open port (listener)
      ↓
Connect to C2
      ↓
Exfiltrate data

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
lightbit
Member
**
Offline

Activity: 410
Merit: 83


View Profile WWW
July 28, 2026, 08:28:25 AM
Last edit: July 28, 2026, 11:07:13 AM by lightbit
 #2104

User: anon2806 <----- Please Ban this User

Fake ANN thread: [ANN] AXORION - Welcome to the official thread!

Fake File:
Quote from: anon2806 link=topic=5589640.msg66986580#msg66986580
Code:
https://github.com/AXORION/AXORION/releases/download/v1.0/AXORION-v1.0.0-win-x64.zip

Edit: New ANN Reported

User: xenobyte25 <----- Please Ban this User

Fake ANN thread: [ANN] QUORVEX - Welcome to the official thread!

Fake File:
Quote from: xenobyte25 link=topic=5589649.msg66986756#msg66986756
Code:
https://github.com/QUORVEX-dev/QUORVEX/releases/download/v1.0/QUORVEX-v1.0.0-win-x64.zip

Edit 2: New ANN Reported

User: jupz <----- Please Ban this User

Fake ANN thread: [ANN] DRAKYLON - Welcome to the official thread!

Fake File:
Quote from: jupz link=topic=5589661.msg66986928#msg66986928
Code:
https://github.com/DRAKYLON-core/DRAKYLON/releases/download/v1.0/DRAKYLON-v1.0.0-win-x64.zip

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
Charcol
Full Member
***
Offline

Activity: 294
Merit: 239



View Profile
July 28, 2026, 10:59:08 AM
Merited by Lafu (1)
 #2105

User: jupz <-----  Please Ban this User

Fake ANN thread: [ANN] DRAKYLON - Welcome to the official thread!

Fake File:
Code:
[b]Download - [/b] https://github.com/DRAKYLON-core/DRAKYLON/releases/download/v1.0/DRAKYLON-v1.0.0-win-x64.zip

lightbit
Member
**
Offline

Activity: 410
Merit: 83


View Profile WWW
July 28, 2026, 02:31:58 PM
 #2106

User: Rakesh4444 <----- Please Ban this User

Fake ANN thread: [ANN] OMNIVRA - Welcome to the official OMNIVRA thread!

Fake File:
Quote from: Rakesh4444 link=topic=5589686.msg66987506#msg66987506
Code:
https://github.com/OMNIVRA/OMNIVRA/releases/download/v1.0/OMNIVRA-v1.0.0-win-x64.zip

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
Pages: « 1 ... 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 [106]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!