Bitcoin Forum
September 16, 2026, 01:25:17 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 [108]
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 54580 times)
Crypto Library
Legendary
*
Offline

Activity: 1708
Merit: 1220


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 28, 2026, 07:17:57 PM
 #2141

Another  suspicious activity from an account that woke up recently and started an ANN thread with a malware URL, on the previous time he was active in the MeowCoin thread.

User Name: Meowmancer
User profile: https://bitcointalk.org/index.php?action=profile;u=3500629

ANN thread link: https://bitcointalk.org/index.php?topic=5592610.0

VirusTotal result show it cointained W32-Trojan-Gen malware, I don't know if it is a false positive result. But the ineresting part is he  create the files on github on very recent time

File URL:
Code:
https://github.com/JustAResearcher/CommonFoundry-Binaries/releases/download/v0.1.0-devnet.16/commonfoundry-miner-v0.1.0-devnet.16-windows-x86_64-wsl2.zip
Don't download this


Virus total result link: https://www.virustotal.com/gui/file/8cffc49d613d857a3ef770e87027e964e03983bfdd5f0880d98fa39346c09543/detection

Scanrepo report link: https://www.scanrepo.dev/scan/github/JustAResearcher/CommonFoundry-Binaries







..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
AakZaki
Legendary
*
Offline

Activity: 2716
Merit: 2539


Integrity Over Exploits 🦁


View Profile
August 30, 2026, 09:03:52 PM
 #2142

This wallet contains Malware 2/71 security vendors flagged this file as malicious

Account: Auroraborealiscoin<=Please Banned
Fake ANN Thread: [ANN] Aurora Borealis Coin (ABRS) | KAWPOW | GPU Mining | Launch 16 Sep 2026

Code:
[b]GitHub:[/b]
https://github.com/auroraborealiscoin/auroraborealis
https://github.com/auroraborealiscoin/auroraborealis/releases/download/v4.6.2-windows-release/AuroraBorealis-Core-v4.6.2-win64-setup.exe



VirusTotal Scan Result: https://www.virustotal.com/gui/file/c16a5377a0958e6504393e2e69e2f575956ac589a416ec11e19a0c75946159a0/detection
Scan Repo: https://www.scanrepo.dev/scan/github/auroraborealiscoin/auroraborealis

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?msockid=3147e887171468901092fed116816993&name=Trojan%3AWin32%2FWacatac.B%21ml

AakZaki
Legendary
*
Offline

Activity: 2716
Merit: 2539


Integrity Over Exploits 🦁


View Profile
September 02, 2026, 06:59:57 PM
 #2143

This wallet contains Malware 2/68 security vendors flagged this file as malicious

Account: pandacoin-official<=Please Banned
Fake ANN Thread: [ANN] Pandacoin — relaunching on Solana (phase 0)

Code:
[url=https://github.com/pandacoin-official]https://github.com/pandacoin-official[/url]
https://github.com/pandacoin-official/pandacoin/releases/download/v3.0.2/pandacoin-3.0.2.0-win32-setup.exe


VirusTotal Scan Result: https://www.virustotal.com/gui/file/36567244dd9f5c0c803ed557f442ba84cac42dee21040641e9613dbb0d9fab68
Scan Repo: https://www.scanrepo.dev/scan/github/pandacoin-official/pandacoin

albon
Legendary
*
Offline

Activity: 2548
Merit: 2453



View Profile
September 09, 2026, 11:09:46 PM
Merited by $crypto$ (1), AakZaki (1)
 #2144

The Newbie-ranked member @pars5555 created several ANN threads promoting PCoinWallet. After examining the ZIP archive and the extracted .exe file in an isolated environment and scanning it with VirusTotal, the file was identified as malicious and detected by multiple antivirus/security engines.

Popular threat label: trojan.anomalous/machinelearning

Threat categories: trojan

Family labels: anomalous | machinelearning | msil

Technical indicators detected: peexe | assembly | 64bits | detect-debug-environment | persistence | contains-pe | long-sleeps

File Information:
Code:
[+] File Name: PCoinWallet.exe
[+] SHA-256: 5d780264a28a5e329e593ef9e534a7f34a3799f8246ea193f4d23be888a2c7b7
[+] Size: 364.50 KB





Github : https_://github.com/pars5555/pcoin | https_://pc.am/download/

ANN threads:

[1] [ANN] PCoin (PCN) - RandomX CPU mining | Bitcoin economics | No premine, no ICO
[2] [WTS] PCoin (PCN) - RandomX CPU coin, no listing, small amounts for BTC/XMR, escrow, I go first

User: pars5555 <----- Please ban this user.

Archived ANN thread: https://ninjastic.space/post/67128223

VirusTotal Scan Results:
[1] pcoin-win64-wallet.zip (7/67)
[2] PCoinWallet.exe (6/70)

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
albon
Legendary
*
Offline

Activity: 2548
Merit: 2453



View Profile
September 14, 2026, 11:01:57 PM
Last edit: September 15, 2026, 11:39:16 PM by albon
 #2145

UPDATE – 16/09/2026:

I finished some more checks and I couldn't confirm my original statement that the wallet contains a Trojan.

The 6/70 VirusTotal detections alone were not enough to prove that the wallet was malicious and I checked the wallet/node processes, file activity, registry activity, startup, and network connections, but I didn't find any strong evidence to support the Trojan claim.

I posted the screenshots from my other test here --> https://bitcointalk.org/index.php?topic=5594203.msg67147871#msg67147871

Original report:

This Newbie member promoted [QDAY] The PoW Coin and uploaded the wallet to GitHub yesterday. After checking the wallet, I first suspected that it might contain a Trojan, based on the VirusTotal detections and what I saw in the sandbox.

VirusTotal results:

Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:

[1] QDAY-Wallet.exe (6/70)

[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

Correction: After the second round of checks I could not confirm that the wallet contains a Trojan, so I have therefore withdrawn my original conclusion.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
antialbon
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
September 15, 2026, 06:51:10 AM
Last edit: September 15, 2026, 09:32:13 AM by antialbon
 #2146

This Newbie member promoted [QDAY] The PoW Coin and uploaded the project's wallet to GitHub yesterday. After checking the wallet, I found that it contains a Trojan, and 6/70 security vendors flagged the file as malicious. Sandbox analysis also shows suspicious process, file, and registry activity.

https://www.talkimg.com/images/2026/09/14/UqTNQq.png |[ARCHIVED]

Popular threat label: trojan.

Threat categories: trojan

Family labels: trojan

File Information:
Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

https://www.talkimg.com/images/2026/09/14/UqTTT2.png

https://www.talkimg.com/images/2026/09/14/UqTt1c.png

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev <----- Please ban this user.

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:
[1] (6/70)
[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

What kind of shitshow is this?

Unsupported malware accusation requesting a ban. The reported EXE is byte-for-byte reproducible from the public v0.8.0 source with Go 1.26.0, producing the same SHA-256. The post shows only generic/ML detections and provides no malicious code, payload, C2, persistence mechanism or concrete IOC. Please review.

You did not find a Trojan. You found six generic heuristic labels and wrote the conclusion yourself.

VirusTotal explicitly says that it “simply aggregates the output of different antivirus vendors” and does not produce its own verdict:

https://docs.virustotal.com/docs/false-positive

Your screenshot contains six unrelated generic or machine-learning labels:

W32.Malware.952F1165
Win/malicious_confidence_70% (D)
Trojan.Malware.300983.susgen
Ti!F0FE37FAD410
Trojan:Win32/Wacatac.B!ml
ML.Attribute.HighConfidence

No common malware family. No payload. No C2. No persistence mechanism. No malicious source line.

A detection is a reason to investigate. It is not permission to invent the result.

The one useful thing in your post is the executable hash:

f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

That exact executable is reproducible byte for byte from the public v0.8.0 source:

git clone --depth 1 --branch v0.8.0 https://github.com/petoshi/qday.git qday-v0.8.0
cd qday-v0.8.0
GOTOOLCHAIN=go1.26.0 GOOS=windows GOARCH=amd64 GOAMD64=v1 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o QDAY-Wallet.exe ./node/cmd/qday-wallet
sha256sum QDAY-Wallet.exe

Result:

f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61  QDAY-Wallet.exe

I repeated the build from a clean clone and inside the stock golang:1.26.0 Docker image. Both produced the exact executable you called a Trojan.

The executable also contains Go build metadata identifying the source revision:

vcs.revision=0a15e202d8caa00c954974f46a132004b667aa6c
vcs.modified=false

Build source:
https://github.com/petoshi/qday/blob/v0.8.0/scripts/package.py#L33-L57

Successful public Windows build:
https://github.com/petoshi/qday/actions/runs/34772964790

The behavior is also public. QDAY-Wallet.exe creates its application directory, starts the bundled qday-node.exe, binds its authenticated API to 127.0.0.1, opens the wallet in the default browser and lets the node connect to the QDAY peer network:

https://github.com/petoshi/qday/blob/v0.8.0/node/cmd/qday-wallet/main.go#L210-L305
https://github.com/petoshi/qday/blob/v0.8.0/node/cmd/qday-wallet/platform_windows.go#L18-L35

The Windows-specific launcher code contains no autostart registry key, scheduled task, service installation, process injection or executable downloader.

If your sandbox found malware, publish the evidence:

the exact registry key and operation;
the complete process command line;
the dropped file and its hash;
the external destination and responsible process;
the persistence mechanism;
or the malicious source line.

“Process, file and registry activity” without any of those details is a list of nouns, not malware analysis.

There is another problem with your report. Your QDAY ZIP link points to SHA-256:

5d780264a28a5e329e593ef9e534a7f34a3799f8246ea193f4d23be888a2c7b7

That is PCoinWallet.exe from your previous report. It is not the QDAY archive. The actual QDAY ZIP shown in your own text and screenshot is:

75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

You copy-pasted the accusation and forgot to replace the evidence.

So either publish an actual indicator of compromise or correct the claim and the request to ban the developer. Six red pixels wearing a lab coat are still not reverse engineering.

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
joker_josue
Legendary
*
Offline

Activity: 2506
Merit: 7491


**In BTC since 2013**


View Profile WWW
September 15, 2026, 07:02:51 AM
 #2147

~~

Why did you create an account just to say that?

I may not fully agree with the method used, but I'm even less likely to trust you, who created an alt account just to make this kind of observation.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
antialbon
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
September 15, 2026, 07:21:12 AM
Last edit: September 15, 2026, 08:18:02 AM by antialbon
 #2148

~~

Why did you create an account just to say that?

I may not fully agree with the method used, but I'm even less likely to trust you, who created an alt account just to make this kind of observation.

My account DollarDev was banned following that report. I created this account only to provide reproducible-build evidence and request a review.

P.s.

I don’t know when Bitcointalk, the best Bitcoin forum on the internet, stopped thinking for itself. Even Legendary members are doing Newbie-tier analysis now. Maybe it happened when somebody handed everyone AI tools and forgot to explain that copying output is not the same thing as understanding it. I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
antialbon
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
September 15, 2026, 09:09:48 AM
 #2149

And I never asked anyone to trust me. The code is open. Verify it. That is the source of truth. Or is a Bitcointalk rank badge what your generation uses instead of evidence?
JeromeTash
Legendary
*
Offline

Activity: 2996
Merit: 1599


Heisenberg


View Profile
September 15, 2026, 11:17:23 AM
 #2150

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
It's better to create a new thread in Meta appealing against the ban, and then in that thread you explain why the detections were false. The mods will look into it and then do the necessary. There is no need to start trolling right from your username.

I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
You have been in the forum for 11 years... Test your theory. Try copy and paste and see what will happen

antialbon
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
September 15, 2026, 02:14:35 PM
Last edit: September 15, 2026, 03:00:18 PM by antialbon
 #2151

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
It's better to create a new thread in Meta appealing against the ban, and then in that thread you explain why the detections were false. The mods will look into it and then do the necessary. There is no need to start trolling right from your username.

I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
You have been in the forum for 11 years... Test your theory. Try copy and paste and see what will happen

Created. This whole situation just pissed me off. now I have to prove something to someone. Why? If you found something, then prove it! Why should I waste my time on this?
antialbon
Newbie
*
Offline

Activity: 9
Merit: 1


View Profile
Today at 08:12:36 AM
 #2152

UPDATE – 16/09/2026:

I finished some more checks and I couldn't confirm my original statement that the wallet contains a Trojan.

The 6/70 VirusTotal detections alone were not enough to prove that the wallet was malicious and I checked the wallet/node processes, file activity, registry activity, startup, and network connections, but I didn't find any strong evidence to support the Trojan claim.

I posted the screenshots from my other test here --> https://bitcointalk.org/index.php?topic=5594203.msg67147871#msg67147871

Original report:

This Newbie member promoted [QDAY] The PoW Coin and uploaded the wallet to GitHub yesterday. After checking the wallet, I first suspected that it might contain a Trojan, based on the VirusTotal detections and what I saw in the sandbox.

VirusTotal results:

Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:

[1] (6/70)

[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

Correction: After the second round of checks I could not confirm that the wallet contains a Trojan, so I have therefore withdrawn my original conclusion.

Thank you for taking time to verify wallet and correct the original report. I respect that. However, my DollarDev account is still banned, and the QDAY announcement topic is still removed:=)

Moderators, Please review the case, unban DollarDev, and restore the QDAY announcement topic.
Pages: « 1 ... 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 [108]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!