Bitcoin Forum
May 04, 2024, 05:53:39 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Flag] - "broke_tradah" installing hidden backdoor.  (Read 333 times)
Rickey Ray (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 6


View Profile
December 30, 2019, 03:03:47 AM
Last edit: December 30, 2019, 03:24:50 AM by Rickey Ray
Merited by DarkStar_ (5), o_e_l_e_o (1)
 #1

Flag against user: broke_tradah

Service thread: https://bitcointalk.org/index.php?topic=3876292.0

Website: freebitcobot.dynu.net

After running his freebitco.exe, his bot goes to https://freebitcobot.dynu.net/update.txt after that, his bot opens https://freebitcobot.dynu.net/safe.php (he forgot to add < ? php tag originally, code below) this script downloads vncserver.exe and looks for *. DAT bitcoin wallet files in parallel he is collecting usernames, passwords and cookie files he is trying to wager user btc by reusing their cookie files to increase his referral commission.

Flag against user: broke_tradah

Service thread: https://bitcointalk.org/index.php?topic=3876292.0

Website: freebitcobot.dynu.net

After running his freebitco.exe, his bot goes to https://freebitcobot.dynu.net/update.txt after that, his bot opens https://freebitcobot.dynu.net/safe.php (he forgot to add < ? php tag originally, code below) this script downloads vncserver.exe and looks for *. DAT bitcoin wallet files in parallel he is collecting usernames, passwords and cookie files he is trying to wager user btc by reusing their cookie files to increase his referral commission.


* For some reason I can't post the code below.
edit: Code at https://pastebin.com/QmTdh12p
1714845219
Hero Member
*
Offline Offline

Posts: 1714845219

View Profile Personal Message (Offline)

Ignore
1714845219
Reply with quote  #2

1714845219
Report to moderator
1714845219
Hero Member
*
Offline Offline

Posts: 1714845219

View Profile Personal Message (Offline)

Ignore
1714845219
Reply with quote  #2

1714845219
Report to moderator
1714845219
Hero Member
*
Offline Offline

Posts: 1714845219

View Profile Personal Message (Offline)

Ignore
1714845219
Reply with quote  #2

1714845219
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714845219
Hero Member
*
Offline Offline

Posts: 1714845219

View Profile Personal Message (Offline)

Ignore
1714845219
Reply with quote  #2

1714845219
Report to moderator
1714845219
Hero Member
*
Offline Offline

Posts: 1714845219

View Profile Personal Message (Offline)

Ignore
1714845219
Reply with quote  #2

1714845219
Report to moderator
willy2streams
Jr. Member
*
Offline Offline

Activity: 32
Merit: 8


View Profile
December 30, 2019, 03:10:11 AM
 #2

Is there an echo in here?
Aveatrex
Sr. Member
****
Offline Offline

Activity: 840
Merit: 375



View Profile
December 30, 2019, 03:13:18 AM
 #3

So if I understood, he is hijacking an user's session cookies in order to gamble with their BTC? You should really post the code otherwise there is no proof of what you are claiming.Maybe you can't post the code because you have a brand new account,if you still struggle with it send me a pm with the code I'll try to post it on your behalf.






░░░▄▀█░░░▄░▄▄░▄░░░█▀▄
▄▄▄▀▀██▀░█▐▌█ ▀██▀▀▄▄▄
▐▌░░░▐▀░▄▀░▐▌░▀▄░▀▌░░░▐▌
▐▌░░░█░░▄▀▄▐▌▄▀▄░░█░░░▐▌
▐▌░░░█░░▀▄░▀▀░▄▀░░█░░░▐▌
▐▌░░▄░█▄░▀▄▐▌▄▀░▄█░▄░░▐▌
▐▌░█▄█░░▀▀▀██▀▀▀░░█▄█░▐▌
▐▌░░░░░░░░░░░░░░░░░░░░▐▌
▐█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█▌
▀▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀▀
░░░░░░░▀▀▀▀▀▀▀▀▀▀
.
░░░░░░░░░░░░░▄█▄░░░░░░░▄█▄
░░░░░░░░░░░░░░░░░▄█▄░░░
░░░░▄▄▄▄▄░░░░░░░░░░░░░
░░█▀▄▄▀▄▄▀█░░░▐▌▐▌
░░░░░░░▐▌▐▌
░░░░░░░░█▄░░░░▄█
█▄█▄▄▄▄▄█▄█░░░░▄▄▀▀▀▄▄
░░░░▄▄▄░░░░░▄▀▄██▀█▌▀▄
░░░██▄██▄▄█▀█▌█▐█▄█▌█▐█
░░░░█▄▄▄▄▄█▄█▌█▐█▄█▌█▐█
░░░░█▄█░░░░░█▄▄█▄█▄█▄█
▀▄▄▄▄▄▄▄▄▄▄▀░░░▀▀▄█▄█▄▀▀
.


░░░██▄▄░░██░██
▄▄░░░░░▀█░█▄▐▌░░░░░▄▄▄
▀▀▀▀▀▀▀█▐▌▄█▐▌░░░░█░▀▀
░░░░░░█▀▄▄▄▄▄▄▀▀▀▀░░▄▄
░░░░░░█░▀▀▀▀▀▀▄█▀▀▀▀▀▀
░░▄▄▄▄▄░▄▄▄▄▄▄▀▄
░░▀▀░░█▄▀▀▀▀▀█▄▀
░░░░░░░█▐▌▀█░█
██▀▀▀▀▀▀▐▌░█░░▀▀▀▀▀▀█
░░░░░░░░██░░▀▀▀▀▀██░██
.
Rickey Ray (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 6


View Profile
December 30, 2019, 03:33:24 AM
 #4

So if I understood, he is hijacking an user's session cookies in order to gamble with their BTC? You should really post the code otherwise there is no proof of what you are claiming.Maybe you can't post the code because you have a brand new account,if you still struggle with it send me a pm with the code I'll try to post it on your behalf.

I might be a new account restriction or might just be getting blocked because it is malicious code. I put it on pastebin.
hacker1001101001
Sr. Member
****
Offline Offline

Activity: 1288
Merit: 415


View Profile
December 30, 2019, 04:46:16 AM
 #5

As per I see, broke_tradah is trying to sell his bot from a year now, but he has not put forward any solid proof of his winning. Even with the help of his bot he is violating the casino terms which can lead to the ban of the account using his script. His script even seem to be sending all the data about the saved usernames and password to https://freebitcobot.dynu.net/safe.php according to the script, which he uses for his own referral profits from the site.

Below statement from TheQuin (moderator or support person on Freebitco.in), makes it more obvious that the bot doesn't work as it is stated by broke_tradah and he never actually won large amounts.

I do monitor accounts that win but I never have spotted the OP's account that runs the live stream.

By looking at all this, I think the bot is pretty much risky for any new user and even to there privacy, hence supporting the flag.



I don't see the link to the flag in the OP, so putting it up here.

https://bitcointalk.org/index.php?action=trust;flag=1121
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1787


฿itcoin for all, All for ฿itcoin.


View Profile
December 30, 2019, 11:02:48 AM
 #6

I don't see the link to the flag in the OP, so putting it up here.

https://bitcointalk.org/index.php?action=trust;flag=1121
Flag supported.
This serves as a reminder that this so called bots are in most cases created for malicious intent. If someone actually managed to create a legit working bot out there. There are 99% chances that the person would just decide to keep quiet and make profits in silence...


.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
December 30, 2019, 10:36:59 PM
 #7

I have supported this flag, and it is now active... peddling a bot with claims of "guaranteed" winning is one thing... peddling malware designed to steal usernames/passwords and wallet files is a completely different level of scum. Undecided

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3528
Merit: 9544


#1 VIP Crypto Casino


View Profile
December 30, 2019, 10:58:02 PM
 #8

Flag supported (DT1)

There is now enough support on this flag (the required 3 DT members) for it to be active.

.
.BITCASINO.. 
.
#1 VIP CRYPTO CASINO

▄██████████████▄
█▄████████████▄▀▄▄▄
█████████████████▄▄▄
█████▄▄▄▄▄▄██████████████▄
███████████████████████████████
████▀█████████████▄▄██████████
██████▀██████████████████████
████████████████▀██████▌████
███████████████▀▀▄█▄▀▀█████▀
███████████████████▀▀█████▀
 ▀▀▀▀▀▀▀██████████████
          ▀▀▀████████
                ▀▀▀███

.
......PLAY......
LTU_btc
Legendary
*
Offline Offline

Activity: 3052
Merit: 1330


Slava Ukraini!


View Profile WWW
December 31, 2019, 12:31:57 AM
 #9

I thought that he is just annoying troll who promote his not working bot and post nonsense on Freebitco.in threads... But seems that he is much more malicious...
Do I understand correctly that if I would use his script, he would have access to my Freebitco.in account and my desktop wallet files?
Doesn't he deserves to be banned? Because:
Quote
6. No linking to phishing or malware, without a warning and a valid reason. [e]

LeGaulois
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 4095


Top Crypto Casino


View Profile
December 31, 2019, 01:10:30 AM
 #10

I thought that he is just annoying troll who promote his not working bot and post nonsense on Freebitco.in threads... But seems that he is much more malicious...
Do I understand correctly that if I would use his script, he would have access to my Freebitco.in account and my desktop wallet files?
Doesn't he deserves to be banned? Because:
Quote
6. No linking to phishing or malware, without a warning and a valid reason. [e]

Yes but you need to create an account using his referral link before, he developed it to only work on accounts that joined under his referral link
I see in the code, briefly,  it uses vnc, bypass the UAC and it scans your PC to look for .dat file

Quote
/Common Dirs
//       $dirs[1][] = 'D:/';
//       $dirs[1][] = '/';
//       $dirs[3][] = '/Users/*/Desktop';
//       $dirs[3][] = '/Users/*/Documents';
//       $dirs[3][] = '/Users/*/Downloads';
//       $dirs[3][] = '/Users/*/OneDrive';
//       $dirs[2][] = '/Users/*/AppData/Roaming';
I also saw there are people using the bot, (so infected), on their Samsung TV Cheesy What the hell are they doing with faucets on TV?  Cheesy

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
hacker1001101001
Sr. Member
****
Offline Offline

Activity: 1288
Merit: 415


View Profile
December 31, 2019, 03:51:25 AM
 #11

Doesn't he deserves to be banned? Because:
Quote
6. No linking to phishing or malware, without a warning and a valid reason. [e]

This doesn't apply here as he is not posting any links to steal your money or info, rather his costumers already know they are risking there account to him by using his bot just by looking at the script.

He is more or less violating the facuets rules on Freebitco.in and other such website and should be banned there.



I also saw there are people using the bot, (so infected), on their Samsung TV Cheesy What the hell are they doing with faucets on TV?  Cheesy

Pretty Cheap LOL !  Shocked
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!