Bitcoin Forum
September 18, 2026, 11:29:57 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 [108]
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 54708 times)
Crypto Library
Legendary
*
Offline

Activity: 1722
Merit: 1220


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 28, 2026, 07:17:57 PM
 #2141

Another  suspicious activity from an account that woke up recently and started an ANN thread with a malware URL, on the previous time he was active in the MeowCoin thread.

User Name: Meowmancer
User profile: https://bitcointalk.org/index.php?action=profile;u=3500629

ANN thread link: https://bitcointalk.org/index.php?topic=5592610.0

VirusTotal result show it cointained W32-Trojan-Gen malware, I don't know if it is a false positive result. But the ineresting part is he  create the files on github on very recent time

File URL:
Code:
https://github.com/JustAResearcher/CommonFoundry-Binaries/releases/download/v0.1.0-devnet.16/commonfoundry-miner-v0.1.0-devnet.16-windows-x86_64-wsl2.zip
Don't download this


Virus total result link: https://www.virustotal.com/gui/file/8cffc49d613d857a3ef770e87027e964e03983bfdd5f0880d98fa39346c09543/detection

Scanrepo report link: https://www.scanrepo.dev/scan/github/JustAResearcher/CommonFoundry-Binaries







..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
AakZaki
Legendary
*
Offline

Activity: 2730
Merit: 2541


Integrity Over Exploits 🦁


View Profile
August 30, 2026, 09:03:52 PM
 #2142

This wallet contains Malware 2/71 security vendors flagged this file as malicious

Account: Auroraborealiscoin<=Please Banned
Fake ANN Thread: [ANN] Aurora Borealis Coin (ABRS) | KAWPOW | GPU Mining | Launch 16 Sep 2026

Code:
[b]GitHub:[/b]
https://github.com/auroraborealiscoin/auroraborealis
https://github.com/auroraborealiscoin/auroraborealis/releases/download/v4.6.2-windows-release/AuroraBorealis-Core-v4.6.2-win64-setup.exe



VirusTotal Scan Result: https://www.virustotal.com/gui/file/c16a5377a0958e6504393e2e69e2f575956ac589a416ec11e19a0c75946159a0/detection
Scan Repo: https://www.scanrepo.dev/scan/github/auroraborealiscoin/auroraborealis

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?msockid=3147e887171468901092fed116816993&name=Trojan%3AWin32%2FWacatac.B%21ml

AakZaki
Legendary
*
Offline

Activity: 2730
Merit: 2541


Integrity Over Exploits 🦁


View Profile
September 02, 2026, 06:59:57 PM
 #2143

This wallet contains Malware 2/68 security vendors flagged this file as malicious

Account: pandacoin-official<=Please Banned
Fake ANN Thread: [ANN] Pandacoin — relaunching on Solana (phase 0)

Code:
[url=https://github.com/pandacoin-official]https://github.com/pandacoin-official[/url]
https://github.com/pandacoin-official/pandacoin/releases/download/v3.0.2/pandacoin-3.0.2.0-win32-setup.exe


VirusTotal Scan Result: https://www.virustotal.com/gui/file/36567244dd9f5c0c803ed557f442ba84cac42dee21040641e9613dbb0d9fab68
Scan Repo: https://www.scanrepo.dev/scan/github/pandacoin-official/pandacoin

albon
Legendary
*
Offline

Activity: 2562
Merit: 2454



View Profile
September 09, 2026, 11:09:46 PM
Merited by $crypto$ (1), AakZaki (1)
 #2144

The Newbie-ranked member @pars5555 created several ANN threads promoting PCoinWallet. After examining the ZIP archive and the extracted .exe file in an isolated environment and scanning it with VirusTotal, the file was identified as malicious and detected by multiple antivirus/security engines.

Popular threat label: trojan.anomalous/machinelearning

Threat categories: trojan

Family labels: anomalous | machinelearning | msil

Technical indicators detected: peexe | assembly | 64bits | detect-debug-environment | persistence | contains-pe | long-sleeps

File Information:
Code:
[+] File Name: PCoinWallet.exe
[+] SHA-256: 5d780264a28a5e329e593ef9e534a7f34a3799f8246ea193f4d23be888a2c7b7
[+] Size: 364.50 KB





Github : https_://github.com/pars5555/pcoin | https_://pc.am/download/

ANN threads:

[1] [ANN] PCoin (PCN) - RandomX CPU mining | Bitcoin economics | No premine, no ICO
[2] [WTS] PCoin (PCN) - RandomX CPU coin, no listing, small amounts for BTC/XMR, escrow, I go first

User: pars5555 <----- Please ban this user.

Archived ANN thread: https://ninjastic.space/post/67128223

VirusTotal Scan Results:
[1] pcoin-win64-wallet.zip (7/67)
[2] PCoinWallet.exe (6/70)

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
albon
Legendary
*
Offline

Activity: 2562
Merit: 2454



View Profile
September 14, 2026, 11:01:57 PM
Last edit: September 15, 2026, 11:39:16 PM by albon
 #2145

UPDATE – 16/09/2026:

I finished some more checks and I couldn't confirm my original statement that the wallet contains a Trojan.

The 6/70 VirusTotal detections alone were not enough to prove that the wallet was malicious and I checked the wallet/node processes, file activity, registry activity, startup, and network connections, but I didn't find any strong evidence to support the Trojan claim.

I posted the screenshots from my other test here --> https://bitcointalk.org/index.php?topic=5594203.msg67147871#msg67147871

Original report:

This Newbie member promoted [QDAY] The PoW Coin and uploaded the wallet to GitHub yesterday. After checking the wallet, I first suspected that it might contain a Trojan, based on the VirusTotal detections and what I saw in the sandbox.

VirusTotal results:

Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:

[1] QDAY-Wallet.exe (6/70)

[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

Correction: After the second round of checks I could not confirm that the wallet contains a Trojan, so I have therefore withdrawn my original conclusion.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
antialbon
Newbie
*
Offline

Activity: 13
Merit: 1


View Profile
September 15, 2026, 06:51:10 AM
Last edit: September 15, 2026, 09:32:13 AM by antialbon
 #2146

This Newbie member promoted [QDAY] The PoW Coin and uploaded the project's wallet to GitHub yesterday. After checking the wallet, I found that it contains a Trojan, and 6/70 security vendors flagged the file as malicious. Sandbox analysis also shows suspicious process, file, and registry activity.

https://www.talkimg.com/images/2026/09/14/UqTNQq.png |[ARCHIVED]

Popular threat label: trojan.

Threat categories: trojan

Family labels: trojan

File Information:
Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

https://www.talkimg.com/images/2026/09/14/UqTTT2.png

https://www.talkimg.com/images/2026/09/14/UqTt1c.png

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev <----- Please ban this user.

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:
[1] (6/70)
[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

What kind of shitshow is this?

Unsupported malware accusation requesting a ban. The reported EXE is byte-for-byte reproducible from the public v0.8.0 source with Go 1.26.0, producing the same SHA-256. The post shows only generic/ML detections and provides no malicious code, payload, C2, persistence mechanism or concrete IOC. Please review.

You did not find a Trojan. You found six generic heuristic labels and wrote the conclusion yourself.

VirusTotal explicitly says that it “simply aggregates the output of different antivirus vendors” and does not produce its own verdict:

https://docs.virustotal.com/docs/false-positive

Your screenshot contains six unrelated generic or machine-learning labels:

W32.Malware.952F1165
Win/malicious_confidence_70% (D)
Trojan.Malware.300983.susgen
Ti!F0FE37FAD410
Trojan:Win32/Wacatac.B!ml
ML.Attribute.HighConfidence

No common malware family. No payload. No C2. No persistence mechanism. No malicious source line.

A detection is a reason to investigate. It is not permission to invent the result.

The one useful thing in your post is the executable hash:

f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

That exact executable is reproducible byte for byte from the public v0.8.0 source:

git clone --depth 1 --branch v0.8.0 https://github.com/petoshi/qday.git qday-v0.8.0
cd qday-v0.8.0
GOTOOLCHAIN=go1.26.0 GOOS=windows GOARCH=amd64 GOAMD64=v1 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o QDAY-Wallet.exe ./node/cmd/qday-wallet
sha256sum QDAY-Wallet.exe

Result:

f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61  QDAY-Wallet.exe

I repeated the build from a clean clone and inside the stock golang:1.26.0 Docker image. Both produced the exact executable you called a Trojan.

The executable also contains Go build metadata identifying the source revision:

vcs.revision=0a15e202d8caa00c954974f46a132004b667aa6c
vcs.modified=false

Build source:
https://github.com/petoshi/qday/blob/v0.8.0/scripts/package.py#L33-L57

Successful public Windows build:
https://github.com/petoshi/qday/actions/runs/34772964790

The behavior is also public. QDAY-Wallet.exe creates its application directory, starts the bundled qday-node.exe, binds its authenticated API to 127.0.0.1, opens the wallet in the default browser and lets the node connect to the QDAY peer network:

https://github.com/petoshi/qday/blob/v0.8.0/node/cmd/qday-wallet/main.go#L210-L305
https://github.com/petoshi/qday/blob/v0.8.0/node/cmd/qday-wallet/platform_windows.go#L18-L35

The Windows-specific launcher code contains no autostart registry key, scheduled task, service installation, process injection or executable downloader.

If your sandbox found malware, publish the evidence:

the exact registry key and operation;
the complete process command line;
the dropped file and its hash;
the external destination and responsible process;
the persistence mechanism;
or the malicious source line.

“Process, file and registry activity” without any of those details is a list of nouns, not malware analysis.

There is another problem with your report. Your QDAY ZIP link points to SHA-256:

5d780264a28a5e329e593ef9e534a7f34a3799f8246ea193f4d23be888a2c7b7

That is PCoinWallet.exe from your previous report. It is not the QDAY archive. The actual QDAY ZIP shown in your own text and screenshot is:

75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

You copy-pasted the accusation and forgot to replace the evidence.

So either publish an actual indicator of compromise or correct the claim and the request to ban the developer. Six red pixels wearing a lab coat are still not reverse engineering.

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
joker_josue
Legendary
*
Offline

Activity: 2520
Merit: 7494


**In BTC since 2013**


View Profile WWW
September 15, 2026, 07:02:51 AM
 #2147

~~

Why did you create an account just to say that?

I may not fully agree with the method used, but I'm even less likely to trust you, who created an alt account just to make this kind of observation.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
antialbon
Newbie
*
Offline

Activity: 13
Merit: 1


View Profile
September 15, 2026, 07:21:12 AM
Last edit: September 15, 2026, 08:18:02 AM by antialbon
 #2148

~~

Why did you create an account just to say that?

I may not fully agree with the method used, but I'm even less likely to trust you, who created an alt account just to make this kind of observation.

My account DollarDev was banned following that report. I created this account only to provide reproducible-build evidence and request a review.

P.s.

I don’t know when Bitcointalk, the best Bitcoin forum on the internet, stopped thinking for itself. Even Legendary members are doing Newbie-tier analysis now. Maybe it happened when somebody handed everyone AI tools and forgot to explain that copying output is not the same thing as understanding it. I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
antialbon
Newbie
*
Offline

Activity: 13
Merit: 1


View Profile
September 15, 2026, 09:09:48 AM
 #2149

And I never asked anyone to trust me. The code is open. Verify it. That is the source of truth. Or is a Bitcointalk rank badge what your generation uses instead of evidence?
JeromeTash
Legendary
*
Offline

Activity: 3010
Merit: 1599


Heisenberg


View Profile
September 15, 2026, 11:17:23 AM
 #2150

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
It's better to create a new thread in Meta appealing against the ban, and then in that thread you explain why the detections were false. The mods will look into it and then do the necessary. There is no need to start trolling right from your username.

I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
You have been in the forum for 11 years... Test your theory. Try copy and paste and see what will happen

antialbon
Newbie
*
Offline

Activity: 13
Merit: 1


View Profile
September 15, 2026, 02:14:35 PM
Last edit: September 15, 2026, 03:00:18 PM by antialbon
 #2151

UNBAN DOLLARDEV AND QDAY ANNOUNCE TOPIC. CORRECT THE ACCUSATION OR PUBLISH THE EVIDENCE.
It's better to create a new thread in Meta appealing against the ban, and then in that thread you explain why the detections were false. The mods will look into it and then do the necessary. There is no need to start trolling right from your username.

I’ve been around this forum since 2011. Watching it degrade into copy-paste paranoia is fucking embarrassing.
You have been in the forum for 11 years... Test your theory. Try copy and paste and see what will happen

Created. This whole situation just pissed me off. now I have to prove something to someone. Why? If you found something, then prove it! Why should I waste my time on this?
antialbon
Newbie
*
Offline

Activity: 13
Merit: 1


View Profile
September 16, 2026, 08:12:36 AM
 #2152

UPDATE – 16/09/2026:

I finished some more checks and I couldn't confirm my original statement that the wallet contains a Trojan.

The 6/70 VirusTotal detections alone were not enough to prove that the wallet was malicious and I checked the wallet/node processes, file activity, registry activity, startup, and network connections, but I didn't find any strong evidence to support the Trojan claim.

I posted the screenshots from my other test here --> https://bitcointalk.org/index.php?topic=5594203.msg67147871#msg67147871

Original report:

This Newbie member promoted [QDAY] The PoW Coin and uploaded the wallet to GitHub yesterday. After checking the wallet, I first suspected that it might contain a Trojan, based on the VirusTotal detections and what I saw in the sandbox.

VirusTotal results:

Code:
[+] File Name: QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip
[+] SHA-256: 75b67811d1adc8abce53e2a906eff3562432bf003a9ad1711f8b257911afddd2

[+] File Name: QDAY-Wallet.exe
[+] SHA-256: f0fe37fad41052849df5fca627af33198bb86f1275d31474dced206831bf5b61

Github : https_://github.com/petoshi/qday/releases | https_://pqday.com

ANN threads:

[1] [QDAY] The PoW coin that outlives crypto.

User: DollarDev

Archived ANN thread: https://ninjastic.space/post/67132568

VirusTotal Scan Results:

[1] (6/70)

[2] QDAY-Wallet-0.8.0-mainnet-windows-amd64.zip (2/67)

Correction: After the second round of checks I could not confirm that the wallet contains a Trojan, so I have therefore withdrawn my original conclusion.

Thank you for taking time to verify wallet and correct the original report. I respect that. However, my DollarDev account is still banned, and the QDAY announcement topic is still removed:=)

Moderators, Please review the case, unban DollarDev, and restore the QDAY announcement topic.
ABRSofficial
Newbie
*
Online Online

Activity: 4
Merit: 0


View Profile
September 17, 2026, 01:24:04 PM
 #2153


Thank you for reporting this.

The screenshot in this post refers to the old Aurora Borealis Core v4.6.2 Windows installer. That is not the current release.

The current Windows release is Aurora Borealis Core v4.6.3, and we have performed a new VirusTotal check on the current auroraborealis-qt.exe binary.

Current release: Aurora Borealis Core v4.6.3
File: auroraborealis-qt.exe
SHA-256:
1efab44a235b63d4b43c4081e9cce721bec2e7a587e4ba05629a84abd4c17e88

VirusTotal result: 1/70 security vendors flagged the file. The single detection is from Trapmine ("Malicious.moderate.ml.score"), while the other 69 engines did not flag it.

We also investigated WmiApSrv.exe, which appeared in the VirusTotal sandbox behavioral report.

SHA-256:
1ac267ac73670bea5f3785c9ad9db146f8e993a862c843742b21fdb90d102b2a

VirusTotal identifies this file as distributed by Microsoft and Dell and displays the tags "known-distributor" and "trusted".

For comparison, Ravencoin's raven-qt.exe also produced a 1/71 VirusTotal result in our comparison test. A single heuristic/ML detection should therefore not, by itself, be treated as conclusive evidence of malware.

We are not claiming that any executable can be guaranteed 100% safe. We are providing the hashes and scan results so that the findings can be independently verified.

The ABRS Core source code is publicly available for independent inspection:
https://github.com/auroraborealiscoin/auroraborealis

If anyone identifies a specific security issue in the current v4.6.3 release, please provide the affected file hash, detection details, or other reproducible technical evidence and we will investigate it.
Xal0lex
Staff
Legendary
*
Offline

Activity: 3318
Merit: 3171


View Profile WWW
September 17, 2026, 01:38:54 PM
 #2154


That's strange, I just clicked on your link, and it says, "No security vendors flagged this file as malicious." Where did that image showing two detections come from?
AakZaki
Legendary
*
Offline

Activity: 2730
Merit: 2541


Integrity Over Exploits 🦁


View Profile
September 17, 2026, 02:14:46 PM
Merited by Lafu (1)
 #2155

That's strange, I just clicked on your link, and it says, "No security vendors flagged this file as malicious." Where did that image showing two detections come from?
Yes that's very strange, on August 30 I checked on version v4.6.2-windows-release. As I quoted here
Code:
[b]GitHub:[/b]
https://github.com/auroraborealiscoin/auroraborealis
https://github.com/auroraborealiscoin/auroraborealis/releases/download/v4.6.2-windows-release/AuroraBorealis-Core-v4.6.2-win64-setup.exe

I don't know why the version is no longer detected by the security vendor, is it possible because the version has been updated to this version 
Code:
auroraborealis-4.6.3-win64-setup.exe
Because after I tried to check on the latest version the result was like this.


I hope you see the results of this VirusTotal soon: https://www.virustotal.com/gui/file/2912a530a5194cd1cf5f2088560d7e09e44b8c6ebf488502fe43dfa432122d27

ABRSofficial
Newbie
*
Online Online

Activity: 4
Merit: 0


View Profile
September 17, 2026, 06:59:13 PM
 #2156

That's strange, I just clicked on your link, and it says, "No security vendors flagged this file as malicious." Where did that image showing two detections come from?
Yes that's very strange, on August 30 I checked on version v4.6.2-windows-release. As I quoted here
Code:
[b]GitHub:[/b]
https[Suspicious link removed]

I don't know why the version is no longer detected by the security vendor, is it possible because the version has been updated to this version 
Code:
auroraborealis-4.6.3-win64-setup.exe
Because after I tried to check on the latest version the result was like this.
https://i.bitlist.co/BdU2oFONBWUq.png

I hope you see the results of this VirusTotal soon: https://www.virustotal.com/gui/file/2912a530a5194cd1cf5f2088560d7e09e44b8c6ebf488502fe43dfa432122d27

Thank you for reporting the Windows installer detection.

We investigated the issue and confirmed that the previously published installer with SHA256 2912a530a5194cd1cf5f2088560d7e09e44b8c6ebf488502fe43dfa432122d27 was indeed the installer available in the v4.6.3-final2 release at the time of the report.

We have now repackaged the Windows installer using the same three v4.6.3-final2 binaries already distributed in the official Windows ZIP. No Core binaries, consensus rules, network parameters or blockchain functionality were changed.

The binaries embedded in the new installer were verified against the v4.6.3-final2 ZIP:

auroraborealis-qt.exe
SHA256: 998345a448b3d686e74d766657605bc28cb1ca61c989b4f3893b4a313cc35bcf

auroraborealisd.exe
SHA256: d463de94cd399c46226455a2e2cc0f65fcc96ab8e27ab103c7e183c33332cb15

auroraborealis-cli.exe
SHA256: 75cbac824c66be9ddbf5b45e1f691107b637576c31fdb575d1d4891f5761727c

The repackaged installer is now available in the official v4.6.3-final2 GitHub release:

auroraborealis-4.6.3-win64-setup.exe

New installer SHA256:
5164f9548852636f9f1d476ce7a2233d160b41a69fd9967f7add617359940892

At the time of our verification on 17 September 2026, VirusTotal reported 0/69 security vendors flagging the repackaged installer. Antivirus results can change over time, so users are encouraged to independently verify the file and its SHA256 checksum.

The release notes and SHA256SUMS have also been updated to document the packaging change and provide the current checksum.

Thank you again for bringing the detection to our attention and allowing us to investigate it.
Lafu (OP)
Legendary
*
Offline

Activity: 3640
Merit: 4623



View Profile
Today at 12:51:54 PM
 #2157

Its a fucking Trojan ,  ABRSofficial is just another Account that represent false hope when you get on the Dark Side in cost of other people !
I guess you will be getting banned soon as you to circumvent the rules  Kiss Cool

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
ABRSofficial
Newbie
*
Online Online

Activity: 4
Merit: 0


View Profile
Today at 04:52:25 PM
 #2158

Its a fucking Trojan ,  ABRSofficial is just another Account that represent false hope when you get on the Dark Side in cost of other people !
I guess you will be getting banned soon as you to circumvent the rules  Kiss Cool

The VirusTotal result you quoted is from our 29 August 2026 post and refers to a previous installer. It is not the current installer documented in the technical update immediately above your reply.

The current repackaged v4.6.3-final2 installer is a different file and has a different SHA256:

5164f9548852636f9f1d476ce7a2233d160b41a69fd9967f7add617359940892

When this specific file was verified on 17 September 2026, VirusTotal reported 0/69 detections.

We have never attempted to hide the previous result. We publicly acknowledged the report, investigated it, rebuilt/repackaged the installer, published the new checksum and documented the updated verification. We also explicitly stated that antivirus detections can change over time.

Therefore, please distinguish between the old file and the current file.

Calling the current ABRS installer a “Trojan” while citing a VirusTotal result belonging to an older file with a different SHA256 does not constitute technical evidence against the current installer.

If you believe the current v4.6.3-final2 installer contains a Trojan or other malicious code, please analyze the current file and provide:

the SHA256 you tested;
the current VirusTotal report;
or a reproducible technical analysis demonstrating the malicious behavior.

We will take any such evidence seriously and investigate it.

If the discussion concerns the current ABRS binaries, then the evidence should concern the current ABRS binaries. Repeating an old scan for a different file does not change the verification result of the current file.

Regarding account moderation or bans, those decisions belong exclusively to the Bitcointalk moderators. We will respect their decisions and will not turn a malware-report thread into an argument about moderation.

We welcome technical scrutiny of ABRS. We simply ask that claims about the current software be supported by current, verifiable and reproducible evidence.
Pages: « 1 ... 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 [108]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!