Bitcoin Forum
November 02, 2024, 06:46:34 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: MtGox remedy worse than the disease says Kaspersky researcher  (Read 1641 times)
LostDutchman (OP)
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile WWW
March 18, 2014, 07:42:46 AM
 #1

http://www.theregister.co.uk/2014/03/17/mtgox_blog_hackers_malware_bitcoin_stealers/

"Leaked database' offering details of Bitcoin heists contained Trojan"

"A 700MB file that hackers claimed contains valuable database information on bankrupted MtGox is actually hiding Bitcoin wallet file-stealing malware, researchers have warned.

Kaspersky Lab’s Sergey Lozhkin claimed in a blog post last Friday that the entire data leak story, which emerged after MtGox CEO Mark Karpeles had his blog hacked, was invented to lure users into unwittingly downloading the malware.

Although the 716MB file features trades.zip, the file actually contains nothing but publically available data on MtGox trades, he said.

The real purpose of the file is Trojan malware designed to “search and steal” Bitcoin wallet files from the victim.

He continued:

    We detect the Windows Trojan (MD5:c4e99fdcd40bee6eb6ce85167969348d), a 4.3MB PE32 executable, as Trojan.Win32.CoinStealer.i and OSX variant as Trojan.OSX.Coinstealer.a. Both have been created with the Livecode programming language – an open-source and cross-platform application development language. When the victim executes the application, it looks like the back-office software for accessing the databases of Mt. Gox’s owning company, Tibanne Co. Ltd.

The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.

If the attackers find the latter, and they have been stored unencrypted, they will “gain access to all the Bitcoins the user has in his possession for that specific account”, Lozkhin warned.

A week ago, hackers hijacked MtGox CEO Karpeles’ blog and posted a file which they claimed had been nabbed from the company’s servers.

They said the file proved that the exchange, once the world’s largest, still controlled almost one million Bitcoins despite having just declared bankruptcy.

As interest in the exchange grows following its bankruptcy filing, MtGox has already released a notice warning former users not to fall for phishing emails piggy-backing on the case."

My $.02.

Wink

Corporations For Crypto
Protect Your Assets and Reduce Your Tax Liability With A Kansas Corporation!
We Demand Justice From BFL
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 18, 2014, 07:49:17 AM
 #2

The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.
I just remembered I need to better protect my LTC wallet before I start using it again.

S4VV4S
Hero Member
*****
Offline Offline

Activity: 1582
Merit: 502


View Profile
March 18, 2014, 07:50:04 AM
 #3

MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?

LostDutchman (OP)
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile WWW
March 18, 2014, 07:50:45 AM
 #4

The malware executes TibanneSocket.exe and then goes on the prowl for bitcoin.conf and wallet.dat files.
I just remembered I need to better protect my LTC wallet before I start using it again.

Good idea!

My $.02.

Wink

Corporations For Crypto
Protect Your Assets and Reduce Your Tax Liability With A Kansas Corporation!
We Demand Justice From BFL
LostDutchman (OP)
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile WWW
March 18, 2014, 07:51:17 AM
 #5

MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?



I dunno but what does it look like?

My $.02.

Wink

Corporations For Crypto
Protect Your Assets and Reduce Your Tax Liability With A Kansas Corporation!
We Demand Justice From BFL
devt
Newbie
*
Offline Offline

Activity: 25
Merit: 0


View Profile
March 18, 2014, 07:53:46 AM
 #6

MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?


Is the site legit? I don't want to give my password to any hackers.
likehiro
Sr. Member
****
Offline Offline

Activity: 427
Merit: 511



View Profile
March 18, 2014, 08:46:19 AM
 #7

MtGox is allowing users to check their balance now.

Seriously is Mark really trying peoples patience?


Is the site legit? I don't want to give my password to any hackers.

Gox database was hacked so your passwords already are on hackers hands. Anyways, what will they do with that information? steal your bitcoins from mtgox? trololol

Please, follow our studio page on instagram   Hard Fork Studio 
LiteCoinGuy
Legendary
*
Offline Offline

Activity: 1148
Merit: 1014


In Satoshi I Trust


View Profile WWW
March 18, 2014, 11:03:05 AM
 #8

i guess Mark did it  - you get GOXXED AGAIN   Tongue

BitOnyx
Member
**
Offline Offline

Activity: 112
Merit: 10

Cryptocurrencies Exchange


View Profile WWW
March 18, 2014, 11:46:54 AM
 #9

Well all of drama is starting again.

People should just move on and start lawsuits.

Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 29, 2014, 01:30:39 AM
 #10

i guess Mark did it  - you get GOXXED AGAIN   Tongue

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  Huh

LostDutchman (OP)
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile WWW
March 29, 2014, 01:33:23 AM
 #11

i guess Mark did it  - you get GOXXED AGAIN   Tongue

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  Huh

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

Wink

Corporations For Crypto
Protect Your Assets and Reduce Your Tax Liability With A Kansas Corporation!
We Demand Justice From BFL
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 29, 2014, 01:42:38 AM
 #12

i guess Mark did it  - you get GOXXED AGAIN   Tongue

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  Huh

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

Wink

Is Mark also the "Werewolf Of MtGox?"
Warren Z had another song I remember....Yes.....Mark's favorite:
"Send Lawyers Guns and Money, daddy get me out of this"

LostDutchman (OP)
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile WWW
March 29, 2014, 02:32:09 AM
 #13

i guess Mark did it  - you get GOXXED AGAIN   Tongue

OK, so Mark is nervous about his huge pile of stolen BTC and looking to steal more, just in case.
Always good to have a back up plan?  Huh

I think maybe Mark is like this guy!:

http://www.youtube.com/watch?v=b0NlXKPaqZg

My $.02.

Wink

Is Mark also the "Werewolf Of MtGox?"
Warren Z had another song I remember....Yes.....Mark's favorite:
"Send Lawyers Guns and Money, daddy get me out of this"

Mmmmmmmmmmmmmmmm............

Warren Zevon may well have been God On Earth.

I bootlegged a recording of one of his Kansas City concerts.

My $.02.

Wink

Corporations For Crypto
Protect Your Assets and Reduce Your Tax Liability With A Kansas Corporation!
We Demand Justice From BFL
Bit_Happy
Legendary
*
Offline Offline

Activity: 2114
Merit: 1040


A Great Time to Start Something!


View Profile
March 29, 2014, 04:20:25 AM
 #14

Too many of the great live acts are old or dead now.
Lady goo-goo ain't no lady, she's just a bunch of ga-ga.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!