Bitcoin Forum
November 19, 2024, 02:05:32 PM *
News: Check out the artwork 1Dq created to commemorate this forum's 15th anniversary
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Beware: Another type of hacker's trap  (Read 312 times)
Imran232 (OP)
Full Member
***
Offline Offline

Activity: 700
Merit: 182


View Profile
August 18, 2021, 05:49:10 PM
 #1


As a crypto currency worker we always need to be alert and always Should known the update news about security.  So that we known about type of online trap to hack us.

As a beginner or Newbie or every member i think this post will be an alarm. As a bounty hunter or airdrop hunter or to creat account on different online platform we shares our mail address and we got lots of mail though google clarify and send suspicious mail on spam folder but can clarify all. Hackers are also intelligent they also find more techniques to hack you.

One of my favourite Indian youtuber today shares an alarming message with us that he recieve mail where has a file to download. Where maybe they can contact as a brand or some other things but beaware before dowbload or opening any file. He mention to check mail and domain. Because if we download that file our system will be that hackers control. He suggest to not open those type of mail just delet it guys. Do not fall any trap they can find more ways because they are only thinking about this so beaware of this.

Source: Genuine Airdrop Thanks for your alarm.
Fivestar4everMVP
Legendary
*
Offline Offline

Activity: 2450
Merit: 1086


Leading Crypto Sports Betting & Casino Platform


View Profile
August 18, 2021, 06:14:43 PM
 #2

Well, I don't know about you @op but this is absolutely nothing new if you ask me, I've come across people who lost access to their computers due to downloading a virus infected software, some are Ransome ware where your computer will be locked and you are asked to send a certain amount of bitcoin to a provided address, failure to comply means you never have access to your computer and every file stored in it again.

It is highly recommended that every computer user have a good anti virus software installed and also, only download software from known sources to minimize the risk of ever installing a bad or virus infected softwares.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
bitmover
Legendary
*
Offline Offline

Activity: 2492
Merit: 6330


bitcoindata.science


View Profile WWW
August 18, 2021, 06:28:41 PM
Last edit: August 18, 2021, 07:14:05 PM by bitmover
 #3

As a crypto currency worker we always need to be alert and always Should known the update news about security.  So that we known about type of online trap to hack us.

As a beginner or Newbie or every member i think this post will be an alarm. As a bounty hunter or airdrop hunter or to creat account on different online platform we shares our mail address and we got lots of mail though google clarify and send suspicious mail on spam folder but can clarify all. Hackers are also intelligent they also find more techniques to hack you.

One of my favourite Indian youtuber today shares an alarming message with us that he recieve mail where has a file to download. Where maybe they can contact as a brand or some other things but beaware before dowbload or opening any file. He mention to check mail and domain. Because if we download that file our system will be that hackers control. He suggest to not open those type of mail just delet it guys. Do not fall any trap they can find more ways because they are only thinking about this so beaware of this.

Source: Genuine Airdrop Thanks for your alarm.

This is a so silly attack.

Ofc you shouldn't open any file from unknown senders that are spamming the network.

Even if you use the safest anti-virus, have the best hardware wallet, you need "healthy" internet habits. If you just open any file from shady websites or every file an unknown sender send you, you will never be safe.

On the other hand, if you do not download stuff from shady websites, you are careful with what emails you open, etc, and follow some basic security tips, you will be safe most of the time.

Imran232 (OP)
Full Member
***
Offline Offline

Activity: 700
Merit: 182


View Profile
August 18, 2021, 06:40:52 PM
 #4





You both are right but 1 thing that we always aren't aware about mail if we get main just open it in a rare case we might click it. Which is risky we should aware on this what i want to say. Because we know hackers are smart they are trying new new method to trap us. And i also want to say that lots of time they creat biggest companis name mail through system generate there has a domain and some extra capital or small letter different what we didn't check care fully if we seen mail from brand we just click but before that we have think first why i click this? Is this mail fof me but why i didn't do anything that i might get a mail from them then why they send me? Then check their mail, domain and match it with their official site or documents then take action on it.

That is the message i want to delivered.
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3318
Merit: 4116


View Profile
August 18, 2021, 06:55:45 PM
Merited by pooya87 (2), ABCbits (1)
 #5

Seems to be a low level attack, and by that I mean nothing new, and likely is a script kiddie without actually having any in depth knowledge about coding.

It is highly recommended that every computer user have a good anti virus software installed and also, only download software from known sources to minimize the risk of ever installing a bad or virus infected softwares.
I'd only recommend a antivirus if you have no clue about computers, and don't know how to stay safe using them. Even then, I'd consider the very software which calls itself antivirus, a virus itself. They usually come bundled with a ton of stuff that you don't want, or they hog up your computer resources for no benefit to the end user. You can effectively safeguard your computer from most attacks, if you are careful, and use it with security in mind.

Seriously, Anti Viruses suck. They also give a false sense of security, because as soon as a user installs them, they assume they are safe. Any malicious user, that is at least competent, i.e the ones that are actually a threat know how to avoid detection from anti viruses, simply because they are effectively reading from a database of known code or patterns which indicate a virus. Plus, you get a ton of false positives, which can be problematic in itself.

If you verify each download that you download, assure the signature is correct, and then you safe guard yourself against some of the common attacks on the internet, such as script attacks then you'll likely be fine in the most part. The more advanced precaution you could take is either physical isolation or virtual compartmentalizing with an operating system like QubesOS. I've talked about this in the past, so I won't go into detail about it here, but most users can safe guard themselves without actually needing a anti virus.
TryNinja
Legendary
*
Offline Offline

Activity: 3024
Merit: 7444


Top Crypto Casino


View Profile WWW
August 18, 2021, 07:00:03 PM
Merited by Welsh (3), vapourminer (1), ABCbits (1), hosseinimr93 (1), tranthidung (1)
 #6

I just got this email. Downloaded the file and this is all it has inside:

Quote
<frameset onload="document.location.replace(window.atob('aHR0cDovL2RvbmF0ZXJiaXRjb2luZS54eXovPzMzNDYyNzY2NDY4ODA3ODQg'));" />

This leads you to a website that appears to be a crypto MLM ("donate X BTC and put your address, someone else will donate to you")...

TLDR: You won't get hacked if you click this file.

███████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████

███████████████████████
.
BC.GAME
▄▄▀▀▀▀▀▀▀▄▄
▄▀▀░▄██▀░▀██▄░▀▀▄
▄▀░▐▀▄░▀░░▀░░▀░▄▀▌░▀▄
▄▀▄█▐░▀▄▀▀▀▀▀▄▀░▌█▄▀▄
▄▀░▀░░█░▄███████▄░█░░▀░▀▄
█░█░▀░█████████████░▀░█░█
█░██░▀█▀▀█▄▄█▀▀█▀░██░█
█░█▀██░█▀▀██▀▀█░██▀█░█
▀▄▀██░░░▀▀▄▌▐▄▀▀░░░██▀▄▀
▀▄▀██░░▄░▀▄█▄▀░▄░░██▀▄▀
▀▄░▀█░▄▄▄░▀░▄▄▄░█▀░▄▀
▀▄▄▀▀███▄███▀▀▄▄▀
██████▄▄▄▄▄▄▄██████
.
..CASINO....SPORTS....RACING..


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
pakhitheboss
Hero Member
*****
Offline Offline

Activity: 2310
Merit: 845


Top Crypto Casino


View Profile WWW
August 19, 2021, 01:17:07 AM
 #7

If you recieve a zip file or a .rar file as an attachment then never download it and immediately delete that mail. In general, if you receive an attachment from an unknown sender then always block that sender. This is applicable to any platform from where you can receive attachments.

OP this is not new it is a very old and effective instrument that hackers and scammers to date still use it. People do fall for such mail and then lose everything.

███████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████

███████████████████████
.
BC.GAME
▄▄▀▀▀▀▀▀▀▄▄
▄▀▀░▄██▀░▀██▄░▀▀▄
▄▀░▐▀▄░▀░░▀░░▀░▄▀▌░▀▄
▄▀▄█▐░▀▄▀▀▀▀▀▄▀░▌█▄▀▄
▄▀░▀░░█░▄███████▄░█░░▀░▀▄
█░█░▀░█████████████░▀░█░█
█░██░▀█▀▀█▄▄█▀▀█▀░██░█
█░█▀██░█▀▀██▀▀█░██▀█░█
▀▄▀██░░░▀▀▄▌▐▄▀▀░░░██▀▄▀
▀▄▀██░░▄░▀▄█▄▀░▄░░██▀▄▀
▀▄░▀█░▄▄▄░▀░▄▄▄░█▀░▄▀
▀▄▄▀▀███▄███▀▀▄▄▀
██████▄▄▄▄▄▄▄██████
.
..CASINO....SPORTS....RACING..


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Luffygroove
Member
**
Offline Offline

Activity: 966
Merit: 25

Ton Together | Save Smart & Win Big


View Profile
August 19, 2021, 09:11:51 AM
 #8

Well, I have the same story from YouTubers here in my country. The scammers take control of the YouTuber's youtube by pretending to offer them a partnership and send some documents to be downloaded. Unfortunately, turns out it was a phishing trial. Although the story came from a YouTuber, technically it's also applied to us, the crypto community. Always be aware, don't click links easily, don't respond to unknown people, Re-check a couple of times, don't get lured easily by a big amount of money (usually from airdrops), and so on. I hope we all be safe from any kind of scam trial

|     T o n T o g e t h e r     |     Saving Empowers Winning     |
Join Launchpool  >  Jan 10th - Feb 10th
●    T W I T T E R    ●    T E L E G R A M    ●    M E D I U M    ●
Mkmanik
Hero Member
*****
Offline Offline

Activity: 986
Merit: 516


View Profile
August 20, 2021, 06:46:37 AM
 #9

almost every day I receive this kind of Email. But I don't try to open those Emails. I know a hacker trying to hack my PC every time. So I am very aware of it. A few months ago somehow my PC got hacked, and hackers can able to get access to my browser. I remember I download a zip file from Mega. When I tried to extract the file, My windows defender warned me but my computer was already infected.




Hacker tried to log in to my Gmail account, But Gamil warned me that someone tried to log in to my Gmail. After that, I format my whole computer hard disk and set up new windows. Also changed all of my passwords for computer and mobile.


Now every time when I need to download any file, I use https://www.virustotal.com/gui/home/upload to scan those files or websites. This website is the best.
I also suggest everyone, Before downloading any file from the unknown source/internet trying to use Virustotal. It is very helpful for you.


Welsh
Staff
Legendary
*
Offline Offline

Activity: 3318
Merit: 4116


View Profile
August 20, 2021, 02:18:48 PM
 #10

Now every time when I need to download any file, I use https://www.virustotal.com/gui/home/upload to scan those files or websites. This website is the best.
I also suggest everyone, Before downloading any file from the unknown source/internet trying to use Virustotal. It is very helpful for you.
VirusTotal is okay. It's good for some quick checking, without having to actually install any software on your device. However, it's not entirely accurate, and shouldn't be relied on. You shouldn't be downloading any attachment that you aren't expecting, and can't verify with the person sending it. Also, you shouldn't be downloading any software on the internet without verifying it came from the official source. Even then, you have to ask yourself if you actually trust the vendor serving you that file.  

Any sophisticated hacker would likely be able to code around TotalVirus detection though. Though, most of them don't target the likes of me, and you. Instead, we are mainly targeted by script kiddies i.e people using other peoples scripts, which are generally known among anti virus software, and TotalVirus.
decodx
Hero Member
*****
Offline Offline

Activity: 1456
Merit: 940

🇺🇦 Glory to Ukraine!


View Profile
August 20, 2021, 02:30:02 PM
 #11

Computer viruses or worms that spread using electronic mail have been known since the 90s. I don't know what is new here, but people seem to have become too dependent on the mail service filters. Common sense should be everyone's best protection from such attacks.
isaac_clarke22
Sr. Member
****
Offline Offline

Activity: 1610
Merit: 264


View Profile
August 20, 2021, 07:26:43 PM
 #12

~
That is the message i want to delivered.
Well sure, OP, but this is too obvious and I don't know the reasoning of someone just going straight up and download these kinds of files. This is even lower level than phishing.

Would you download a randomly named executable file when someone told you that you can generate Bitcoin with it?

~
There were some reports of false positives, and from that I wouldn't really rely on it as I am not even sure if they keep their virus database up-to-date.
Woodie
Hero Member
*****
Offline Offline

Activity: 2002
Merit: 902


The #1 Solana Casino


View Profile WWW
August 20, 2021, 08:43:15 PM
 #13

I also feel Google isn't doing much to protect its users from data theft...you might say it's not their responsibility but it's one way of protecting its business. And they can sort this out stopping or blocking these domains from further spreading their malware.

I have have found myself receiving 100s of emails in a week from different  domains even after reporting these as spam but it just never stops, I have resorted to not using my email address and jumped onto a newly created one.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
BIT-BENDER
Hero Member
*****
Offline Offline

Activity: 1680
Merit: 717


View Profile
August 20, 2021, 09:32:34 PM
 #14

Why open an attachment from someone or something you didn't apply/subscribe for or enquiry about, there is an option on Gmail when signing up an address, which is for personal use, business or sometimes child, I think this directive is enough for -Newbies- and experts to know that they can earmark addresses for distinct purposes have one address can increase your curiousness or maybe mixed up to open an attachment you can't understand where the source got your address from.
Munir575
Member
**
Offline Offline

Activity: 546
Merit: 10


View Profile
August 30, 2021, 12:02:33 AM
 #15

I just noticed the rate at which people are just trying to have access to our funds is really increasing rapidly there are lot's of cryptocurrency scam patterns now which we all have to be very careful so that we wont lose our money there are lots of fake apps, fake links, fake websites and fake airdrop and giveaway currently which they are just trying to drain. So we all have to be very careful the kind of and and where we inpute our details to avoid been scammed.
posi
Hero Member
*****
Offline Offline

Activity: 2254
Merit: 579


DGbet.fun - Crypto Sportsbook


View Profile
August 30, 2021, 12:08:39 AM
 #16

This totally a spam message and only a silly person will believe the content of the message but I dont know what the OP was thinking to even open such message which could expose him.

pooya87
Legendary
*
Offline Offline

Activity: 3640
Merit: 11041


Crypto Swap Exchange


View Profile
August 30, 2021, 03:49:05 AM
 #17

Plus, you get a ton of false positives, which can be problematic in itself.
This is the worst. The other day I compiled my own code and my AV detected it as a virus and removed the compiled binaries!!! It was funny and infuriating at the same time. Suffice it to say that I had to exclude my  entire dev folder. The only reason I have an AV is its firewall because it gives me a lot of control over what applications can access to the internet.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
n0nce
Hero Member
*****
Offline Offline

Activity: 896
Merit: 5919


not your keys, not your coins!


View Profile WWW
August 30, 2021, 10:10:38 AM
 #18

Plus, you get a ton of false positives, which can be problematic in itself.
This is the worst. The other day I compiled my own code and my AV detected it as a virus and removed the compiled binaries!!! It was funny and infuriating at the same time. Suffice it to say that I had to exclude my  entire dev folder. The only reason I have an AV is its firewall because it gives me a lot of control over what applications can access to the internet.

Tbh I wouldn't install an AV (which imho is also a virus, as Welsh said) just for the firewall.

For example, to simply restrict some binaries access to internet, something lightweight, small and open source as ufw (https://launchpad.net/ufw) should do the trick.

As a very strong and effective firewall, you'll also (additionally) want something separate from the device you're trying to protect, a physically separate piece of hardware in your network that filters packets and everything.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Peanutswar
Legendary
*
Online Online

Activity: 1736
Merit: 1321


Top Crypto Casino


View Profile WWW
August 30, 2021, 10:29:51 AM
 #19

This kind of email attack or also called a Smishing this kind attack are letting their users to click the click or any suspicious file and of course today if you click a file it might automatically download unless there's another layer of security you have to prevent this might happen, if you remember there's a trending of email virus before which is the I love you virus this is one of the most notorious kinds of message that damage a lot of assets of the organizations. Smishing is nothing new in the internet because there are uneducated people keep exploring even though its came from a suspicious sender. It is better to prevent clicking anything, think before you execute.

Kontibruno
Jr. Member
*
Offline Offline

Activity: 54
Merit: 4


View Profile
August 30, 2021, 10:52:27 AM
 #20

I think the safest way to keep your system protected from hackers is to avoid opening links you are not sure of. And do not depend on your anti-virus, some viruses are more sophisticated than these anti-viruses.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!