Bitcoin Forum
October 05, 2026, 08:39:34 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 [109]
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 55003 times)
$crypto$
Legendary
*
Offline

Activity: 3248
Merit: 1263


Smart is not enough, there must be skills


View Profile WWW
September 27, 2026, 01:37:25 PM
 #2161

Fake Freezium thread --- possible hacked account then spreading danger Github link.

Account: AleScamHole This user recently woke up from a long period of inactivity. please ban
Fake ANN: [ANN] Freezium | POW

Code:
[size=12pt]https://github.com/perlmine1/Frizium-dev/releases/download/1.1.0/Freezium-win64-v.1.1.0.zip[/size]

Virustotal: https://www.virustotal.com/gui/file/87c93233925ec133cfd749a058e8f255e9ed7955d9e90ee63afd7e5d79fec3d8/detection

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄▄░░▄█░██░█▄░░▄▄
▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄
▀▄█░███▄█▄▄█▄███░█▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
█░░██████░░█
█░░░░▀▀░░░░█
█▀▄▀▄▀▄▀▄▀▄█
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
████████████░███████▀▄▀
████████████░██▀▄▄▄▄▀
████████████░▀▄▀
████████████▄▀
███████████▀
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
AakZaki
Legendary
*
Online Online

Activity: 2744
Merit: 2592


Integrity Over Exploits 🦁


View Profile
October 01, 2026, 07:38:46 PM
 #2162

Data from VirusTotal and Hybrid Analysis state that this .exe file is malicious:


Account: ArqTras<= Please Banned
Fake ANN Thread: [ANN][PDC] Privacy Data Coin — confidential transfers by default

Code:
[size=14pt][b]Wallets and source[/b][/size]
Desktop wallet, daemon, and simplewallet are published as the latest GitHub release. GUI archives are the desktop wallet. CLI archives are the daemon and simplewallet.

https://github.com/PrivacyDataCoin-Project/PDC/releases/latest
https://github.com/PrivacyDataCoin-Project/PDC/releases/download/v2.3.0/Pdc-Gui-v2.3.0-windows.exe

VirusTotal: 3/62 security vendors flagged this file as malicious, and there is a Potential Raspberry Robin

VirusTotal Scan Result: https://www.virustotal.com/gui/file/1235174c2a233e7d1d9bba079af8ff66fda471eb4e2fd85549452776c10c7ad5/detection

Raspberry Robin : https://redcanary.com/threat-detection-report/threats/raspberry-robin/


Hybrid Analysis: 1/23 security vendors flagged this file as malicious, and there are several malicious indicators


Code:
Anti-Detection/Stealthiness (1)
Creates a process in suspended mode (likely for process injection)

Details "Pdc-Gui-v2.3.0-windows.tmp" called "CreateProcessW" with parameter ""%PROGRAMFILES%\Pdc\Pdc.exe"" - (UID: 00000000-00002416)
Source API Call
Relevance 10/10
-------------------------------------------------------------------

Installation/Persistence (1)
Writes data to a remote process

Details "Pdc-Gui-v2.3.0-windows.exe" wrote 000011C0 bytes to a remote process "C:\Users\%OSUSER%\AppData\Local\Temp\is-4IWQ1RG74B.tmp\Pdc-Gui-v2.3.0-windows.tmp" (Handle: 600)
"Pdc-Gui-v2.3.0-windows.exe" wrote 00000008 bytes to a remote process "C:\Users\%OSUSER%\AppData\Local\Temp\is-4IWQ1RG74B.tmp\Pdc-Gui-v2.3.0-windows.tmp" (Handle: 600)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 000011C0 bytes to a remote process "C:\Program Files\Pdc\vc_redist.x64.exe" (Handle: 1724)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 00000008 bytes to a remote process "C:\Program Files\Pdc\vc_redist.x64.exe" (Handle: 1724)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 000011C0 bytes to a remote process "C:\Program Files\Pdc\Pdc.exe" (Handle: 1620)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 00000008 bytes to a remote process "C:\Program Files\Pdc\Pdc.exe" (Handle: 1620)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 000011C0 bytes to a remote process "C:\Program Files\Pdc\Pdc.exe" (Handle: 1992)
"Pdc-Gui-v2.3.0-windows.tmp" wrote 00000008 bytes to a remote process "C:\Program Files\Pdc\Pdc.exe" (Handle: 1992)
"vc_redist.x64.exe" wrote 000011C0 bytes to a remote process "C:\Windows\Temp\{705BD475-C14C-4D38-B852-F84CFF9BF8EB}\.cr\vc_redist.x64.exe" (Handle: 684)
"vc_redist.x64.exe" wrote 00000008 bytes to a remote process "C:\Windows\Temp\{705BD475-C14C-4D38-B852-F84CFF9BF8EB}\.cr\vc_redist.x64.exe" (Handle: 684)
Source API Call
Relevance 6/10
-------------------------------------------------------------------

Unusual Characteristics (1)
Spawns many processes

Details Spawned process "Pdc-Gui-v2.3.0-windows.exe" (UID: 00000000-00007280)
Spawned process "Pdc-Gui-v2.3.0-windows.tmp" with commandline "/SL5="$50308
100915460
893952
C:\\Pdc-Gui-v2.3.0-windows.exe"" (UID: 00000000-00002416)
Spawned process "vc_redist.x64.exe" with commandline "/install /quiet /norestart" (UID: 00000000-00008044)
Spawned process "vc_redist.x64.exe" with commandline "-burn.clean.room="%PROGRAMFILES%\\Pdc\\vc_redist.x64.exe" -burn.filehandle.attached=680 -burn.filehandle.self=672 /install /quiet /norestart" (UID: 00000000-00004080)
Spawned process "Pdc.exe" (UID: 00000000-00005488)
Spawned process "Pdc.exe" (UID: 00000000-00001768)
Source Monitored Target
Relevance 8/10

Hybrid Analysis Scan Result: https://hybrid-analysis.com/sample/1235174c2a233e7d1d9bba079af8ff66fda471eb4e2fd85549452776c10c7ad5

AakZaki
Legendary
*
Online Online

Activity: 2744
Merit: 2592


Integrity Over Exploits 🦁


View Profile
October 03, 2026, 06:17:12 AM
 #2163

Data from VirusTotal and Hybrid Analysis state that this .exe file is Suspicious:


Account: feelcoin-dev<= Please Banned
Fake ANN Thread: [ANN] [FEEL] Feelcoin | RandomX PoW | CPU Mining | Independent Blockchain

Code:
[b]Feelcoin v0.2.0[/b]

[url=https://github.com/feelcoin-org/feelcoin/releases/tag/v0.2.0]Download Feelcoin v0.2.0[/url]

https://github.com/feelcoin-org/feelcoin/releases/download/v0.2.0/feelcoin-v0.2.0-windows-x64.zip

VirusTotal: 21/71 security vendors flagged this file as malicious


VirusTotal Scan Result: https://www.virustotal.com/gui/file/44c73fb4a5411065cc6686b903a804ae25fe85e7c5a1931577251f773b345521/detection


Hybrid Analysis: 3/27 security vendors flagged this file as malicious


Suspicious Indicators:
Code:
Anti-Detection/Stealthiness (1)
File exhibits characteristics of junk code obfuscation

DetailsSection ".text" unusually large (16999136 bytes)
possible junk padding
Source Static Parser
Relevance 3/10
---------------------------------------------------
Anti-Reverse Engineering (1)
Section contains high entropy

Details "feelcoind.exe" has section name .rodata with entropy "7.755655339919864"
Source Static Parser
Relevance 1/10
---------------------------------------------------
Network Related (1)
Process binds to unusual ports

Details Process "C:\feelcoind.exe" binds to port 35780
Process "C:\feelcoind.exe" binds to port 35781
Process "C:\feelcoind.exe" binds to port 35782
Source Network Traffic
Relevance 10/10
---------------------------------------------------
Pattern Matching (3)
YARA signature match – Detect ransom note

Details YARA signature for detecting ransom note matched on process "00000000-00000916"
YARA signature for detecting ransom note matched on file "sample.bin"
Source YARA Signature
Relevance 10/10

YARA signature match - ChaCha20 encryption algorithm

Details YARA signature for ChaCha20 256-bit key algorithm matched on file "sample.bin"
YARA signature for ChaCha20 128-bit key algorithm matched on file "sample.bin"
Source YARA Signature
Relevance 9/10

YARA signature match – cryptographic algorithms

Details YARA signature matched on Chacha20 instruction used in file "sample.bin"
Source YARA Signature
Relevance 1/10
---------------------------------------------------
Spyware/Information Retrieval (1)
Tries to read/open stored key files

Details
"feelcoind.exe" opens a file C:\ProgramData\feelcoin\rpc_ssl.key (UID: 00000000-00000916)
"feelcoind.exe" opens a file %ALLUSERSPROFILE%\feelcoin\rpc_ssl.key (UID: 00000000-00000916)
Source API Call
Relevance 3/10
--------------------------------------------------
Found TLS callbacks

Details
"feelcoind.exe" has a TLS callback with entrypoint at 0x1404c9d40
"feelcoind.exe" has a TLS callback with entrypoint at 0x140b36d40
"feelcoind.exe" has a TLS callback with entrypoint at 0x140b63d80
Source Static Parser
Relevance 10/10

PE file contains unusual section name

Details
"feelcoind.exe" has a section named "text_env"
Source Static Parser
Relevance 10/10

Imports suspicious APIs

Details
RegCloseKey
SetSecurityDescriptorDacl
CreateServiceA
OpenProcessToken
RegOpenKeyExA
StartServiceCtrlDispatcherA
StartServiceA
IsDebuggerPresent
DeviceIoControl
FindFirstFileW
CreateDirectoryW
Sleep
VirtualProtect
CreateFileMappingA
LoadLibraryW
DeleteFileW
GetModuleHandleExA
GetModuleFileNameA
GetFileSizeEx
CreateFileW
GetProcAddress
GetFileSize
GetSystemInfo
GetVersionExA
CreateFileA
SleepConditionVariableCS
GetModuleHandleExW
GetModuleHandleW
SleepEx
OpenProcess
GetThreadContext
CreateDirectoryExW
CreateProcessA
CopyFileExW
TerminateProcess
GetTickCount
WriteFile
GetFileAttributesW
CreateThread
GetModuleFileNameW
VirtualAlloc
MapViewOfFileEx
FindNextFileW
GetFileAttributesA
GetSystemDirectoryA
OutputDebugStringA
LoadLibraryA
GetModuleHandleA
ShellExecuteExA
bind
send
WSASend
sendto
WSAStartup
accept
recvfrom
socket
WSASocketA
listen
closesocket
connect
WSASocketW
recv
Source Static Parser
Relevance 1/10

Hybrid Analysis Scan Result: https://hybrid-analysis.com/sample/44c73fb4a5411065cc6686b903a804ae25fe85e7c5a1931577251f773b345521

AakZaki
Legendary
*
Online Online

Activity: 2744
Merit: 2592


Integrity Over Exploits 🦁


View Profile
October 04, 2026, 03:09:15 PM
 #2164

Data from Hybrid Analysis state that this .exe file is Malicious:


Account: MioziM<= Please Banned
Fake ANN Thread: [ANN] DogKong v8 - cryptocurrency (CPU miner)

Code:
## 📥 Download

Latest version: [Releases](https://github.com/marquesslim-hue/DOGKONG/releases)

Hybrid Analysis: 2/24 security vendors flagged this file as malicious


Malicious Indicators:
Code:
Network Related (2)
Contacts multiple hosts

Details Contacted 14 (or more) hosts in at least 0 different cls.countries
Source Network Traffic
Relevance 9/10

Attempts to identify external IP address

Details "api.ipify.org"
Source Network Traffic
Relevance 6/10
----------------------------------------
System Security (1)
Modifies firewall settings

Details Process "netsh.exe" with commandline "netsh advfirewall firewall add rule name="DogKong P2P" dir=in action=allow protocol=TCP localport=18555" (UID: 00000000-00003628)
Source Monitored Target
Relevance 8/10
----------------------------------------
Unusual Characteristics (1)
Spawns many processes

Details Spawned process "DogKong_v8.exe" (UID: 00000000-00002252)
Spawned process "DogKong_v8.exe" (UID: 00000000-00002164)
Spawned process "cmd.exe" with commandline "/c "ver"" (UID: 00000000-00007836)
Spawned process "cmd.exe" with commandline "/c netsh advfirewall firewall add rule name="DogKong P2P" dir=in action=allow protocol=TCP localport=18555 >nul 2>&1" (UID: 00000000-00005996)
Spawned process "netsh.exe" with commandline "netsh advfirewall firewall add rule name="DogKong P2P" dir=in action=allow protocol=TCP localport=18555" (UID: 00000000-00003628)
Source Monitored Target
Relevance 8/10
----------------------------------------
Ransomware/Banking (1)
The analysis extracted a file with a known ransomware suffix

Details Found dropped filename "cp936.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "cp949.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "cns11643.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "euc-kr.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "ksc5601.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "big5.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "cp950.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "gb12345.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "gb2312.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "gb2312-raw.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "euc-jp.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "jis0208.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "jis0212.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "cp932.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macJapan.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "shiftjis.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macCentEuro.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macDingbats.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macCroatian.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macCyrillic.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "iso8859-16.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macRomania.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "macIceland.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "iso8859-13.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Found dropped filename "iso8859-10.enc" which has been seen in the context of ransomware (Indicator: .ENC)
Source Binary File
Relevance 10/10

Hybrid Analysis Scan Result: https://hybrid-analysis.com/sample/7f78a8d844a37f085766551a4d3ad9c31fe3c5edc5b66e73e16297f7ceb6de74

Pages: « 1 ... 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 [109]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!