Bitcoin Forum
June 15, 2024, 03:49:24 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 »  All
  Print  
Author Topic: FreeBitco.in Appears Hacked - Monthly Prize Money Stolen From Multiple Users  (Read 1735 times)
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 05, 2024, 06:34:37 AM
Last edit: May 05, 2024, 06:59:27 AM by codergeek
 #41

I looked through the malicious JS code. It seems to be targetting user id 31898443 specifically (unless a different ID is loaded based on the url parameters used to load the js from the cashtravel site.

It appears then to hit https://bitwrecken.com/?action=new&id=31898443 to get the new / rogue deposit address. Presumably this is done so the attackers can cycle through various different rogue deposit addresses, or even randomise them.

There is a then a html element called main_deposit_address which is replaced by the value retrieved from the bitwrecken.com site

The script is actually rather simple in how it works, nothing complicated going on.

The worrying part, is how the attackers were able to embed this into the freebitco.in site and whether it has affected all users. It feels like those who clicked the advanced tracking button in the referral page may be the ones who were hit, but not seen any confirmation of this.


Thankyou for your analysis.

What do you make of this
https://cdn.jsdelivr.net/gh/feleryunfbc/js/jquery.min.js

It looks like something you'd expect to see on https://www.ioccc.org/

http://dripdropcoin.com/
GinnyBanzz
Newbie
*
Offline Offline

Activity: 43
Merit: 0


View Profile
May 05, 2024, 08:53:21 AM
 #42

That rogue jquery cdn include is some serious obfuscation. It doesn't look like that one is easy to unobfuscate, It is an enormous function built by lots of mini functions referencing memory addresses, very hard to follow. It would take me hours to decipher all that.
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 05, 2024, 11:50:39 AM
 #43

That rogue jquery cdn include is some serious obfuscation. It doesn't look like that one is easy to unobfuscate, It is an enormous function built by lots of mini functions referencing memory addresses, very hard to follow. It would take me hours to decipher all that.

It's gone!

http://dripdropcoin.com/
ixi1234
Newbie
*
Offline Offline

Activity: 50
Merit: 0


View Profile
May 05, 2024, 01:47:56 PM
 #44

The malicious code is gone. But the lost funds were not reimbursed to us and it seems they are not going to, they just threw us
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 06, 2024, 06:56:49 AM
 #45

The malicious code is gone. But the lost funds were not reimbursed to us and it seems they are not going to, they just threw us

We don't know if freebitco.in has done something or if it was the hackers who removed the malicious code to calm us down, but they will come back.
Seeing that Freebitco.in has neither responded to any email, nor has it given any explanation nor does it appear anywhere, I believe it was the second option and I also believe that there will be no refund. We have been robbed and have lost our funds.

trust in freebitco.in = 0%
Lucius
Legendary
*
Offline Offline

Activity: 3276
Merit: 5723


Blackjack.fun🎲


View Profile WWW
May 06, 2024, 09:12:32 AM
 #46

We don't know if freebitco.in has done something or if it was the hackers who removed the malicious code to calm us down, but they will come back.
Seeing that Freebitco.in has neither responded to any email, nor has it given any explanation nor does it appear anywhere, I believe it was the second option and I also believe that there will be no refund. We have been robbed and have lost our funds.
trust in freebitco.in = 0%


Your attitude and the attitude of all those who have suffered financial loss is completely logical and I agree that the reputation of this service is quite damaged after everything that happened. However, I think that they should be given a chance to show that they are still serious about what they are doing.

We recently had an example where one user received his deposit after 8 months if I am not mistaken, so although it is difficult to find justification for such a delay in solving the problem, we should not completely reject the possibility that freebitco will compensate all those who were victims of malicious scripts.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
NABiT
Sr. Member
****
Offline Offline

Activity: 329
Merit: 259



View Profile
May 06, 2024, 09:50:33 AM
 #47

We don't know if freebitco.in has done something or if it was the hackers who removed the malicious code to calm us down, but they will come back.
Seeing that Freebitco.in has neither responded to any email, nor has it given any explanation nor does it appear anywhere, I believe it was the second option and I also believe that there will be no refund. We have been robbed and have lost our funds.
trust in freebitco.in = 0%


Your attitude and the attitude of all those who have suffered financial loss is completely logical and I agree that the reputation of this service is quite damaged after everything that happened. However, I think that they should be given a chance to show that they are still serious about what they are doing.

We recently had an example where one user received his deposit after 8 months if I am not mistaken, so although it is difficult to find justification for such a delay in solving the problem, we should not completely reject the possibility that freebitco will compensate all those who were victims of malicious scripts.

I agree, it's early days in Freebitco time and I've never seen a case so far where the fault has been found to be with Freebitco and the affected user has not been recompensed.

You're not mistaken about the case you mention, it was a deposit issue, the poor guy really went through it and understandably came to a similar conclusion that his funds were lost.
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 06, 2024, 10:32:41 AM
 #48

We don't know if freebitco.in has done something or if it was the hackers who removed the malicious code to calm us down, but they will come back.
Seeing that Freebitco.in has neither responded to any email, nor has it given any explanation nor does it appear anywhere, I believe it was the second option and I also believe that there will be no refund. We have been robbed and have lost our funds.
trust in freebitco.in = 0%


Your attitude and the attitude of all those who have suffered financial loss is completely logical and I agree that the reputation of this service is quite damaged after everything that happened. However, I think that they should be given a chance to show that they are still serious about what they are doing.

We recently had an example where one user received his deposit after 8 months if I am not mistaken, so although it is difficult to find justification for such a delay in solving the problem, we should not completely reject the possibility that freebitco will compensate all those who were victims of malicious scripts.

I agree, it's early days in Freebitco time and I've never seen a case so far where the fault has been found to be with Freebitco and the affected user has not been recompensed.

You're not mistaken about the case you mention, it was a deposit issue, the poor guy really went through it and understandably came to a similar conclusion that his funds were lost.

If Freebitco.in returns me some of what I lost and if I see that everything is safe again, I will raise my confidence and write it for everyone here. I have been with Freebitco.in for years now and I want to continue...

...but this week Freebitco.in is not giving me reasons to do so.

Update: At least it seems FBC is making something. I have a new window i have never seen before (PENDING DEPOSITS) with a deposit from Kraken i have made some minutes ago.
blackmtl308
Newbie
*
Offline Offline

Activity: 137
Merit: 0


View Profile
May 06, 2024, 12:06:20 PM
 #49

I keep sending emails to support, to TheQuin, and waiting for someone responsible for Freebico.in to answer me something, TheQuin, Support, or whoever.

I won't stop until my stolen money is returned.

My Freebitco.in ID: 51895659
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 06, 2024, 12:45:26 PM
 #50

I keep sending emails to support, to TheQuin, and waiting for someone responsible for Freebico.in to answer me something, TheQuin, Support, or whoever.

I won't stop until my stolen money is returned.

My Freebitco.in ID: 51895659

Same to me but when you talk about support you mean the email in the FAQS menu into the page? Because i have sent many emails and they never answered.

I would love the my stolen money was returned and someone responsible for Freebico.in gave some explanations as well.

My Freebitco.in ID: 38757724
blackmtl308
Newbie
*
Offline Offline

Activity: 137
Merit: 0


View Profile
May 06, 2024, 01:45:45 PM
 #51

I keep sending emails to support, to TheQuin, and waiting for someone responsible for Freebico.in to answer me something, TheQuin, Support, or whoever.

I won't stop until my stolen money is returned.

My Freebitco.in ID: 51895659

Same to me but when you talk about support you mean the email in the FAQS menu into the page? Because i have sent many emails and they never answered.

I would love the my stolen money was returned and someone responsible for Freebico.in gave some explanations as well.

My Freebitco.in ID: 38757724

Hi Drazen2003,

Yes, e-mail:  support@freebitco.in
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 06, 2024, 06:28:59 PM
 #52

I keep sending emails to support, to TheQuin, and waiting for someone responsible for Freebico.in to answer me something, TheQuin, Support, or whoever.

I won't stop until my stolen money is returned.

My Freebitco.in ID: 51895659

Same to me but when you talk about support you mean the email in the FAQS menu into the page? Because i have sent many emails and they never answered.

I would love the my stolen money was returned and someone responsible for Freebico.in gave some explanations as well.

My Freebitco.in ID: 38757724

Hi Drazen2003,

Yes, e-mail:  support@freebitco.in

Thank you very much blackmtl308,

I have written with images and documentation but... have you got an answer? I have sent many emails these last days and I never get an answer.
BayAreaCoins (OP)
Legendary
*
Offline Offline

Activity: 3920
Merit: 1248


Owner at AltQuick.com & FreeBitcoins.com


View Profile WWW
May 08, 2024, 04:38:37 AM
 #53

Don't spam their support.  That just annoys and slows things down.

I am looking forward to hearing wtf happened.  I'm not worried about the tiny prize, it's just strange and a response would be cool.

Also, I don't use advanced links. 

Patching is a priority to talking.  We would like to keep a good affiliate relationship with FreeBitco.in, but know users are safe.   (I'm not feeling very safe atm Tongue)

https://AltQuick.com/exchange/ - Trade altcoins & Bitcoin Testnet coins with real Bitcoin. Fast, private, and easy!
https://FreeBitcoins.com/faucet/ - Load your AltQuick exchange account with free Bitcoins & Testnet every 10 minutes.
Cacenn@outlook.com
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
May 09, 2024, 09:04:52 AM
 #54

Anyway it seeems FBC is waking up, first Thequin has recently logged in, the script is of the page and the number 10 lambo winner has been announced even the outcome was already as expected.

Anyhow since the script was loaded from his website FBC is responsible, even you have injoyed our 12,5 BTC for your riant holiday.

So @thequin let me know when you are going to send me the 2000€ and 19300€ back.
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 09, 2024, 11:26:22 AM
 #55

Some days after causing the loss of all the funds of some users and having received emails with evidence of the hack, nobody from Freebitco.in has answered my emails or contact to me. We still don't know if the hackers can attack again when they wanted.

The user @TheQuin either responded to the private message I sent him.

I cannot trust in Freebitco.in by the moment.
ixi1234
Newbie
*
Offline Offline

Activity: 50
Merit: 0


View Profile
May 09, 2024, 03:32:31 PM
 #56

I also have no response from the support
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 09, 2024, 11:42:12 PM
Last edit: May 10, 2024, 10:37:08 AM by codergeek
 #57

No response from support.

This issue impacted a handful of wagering contest winners. As far as we know.


Malicious scripts gone (cashtravel js).

Attacker's website down (bitwrecken.com).

Complicit accounts disappeared (feleryunfbc: github, jsdelivr).

Evidence vanished.


We know the truth.

What happened can happen again. To us. To others.


Since the attack, I have made a successful withdrawal.

For now, I intend to withdraw everything. No wagering. No deposits.

Confidence remains low.


http://dripdropcoin.com/
ixi1234
Newbie
*
Offline Offline

Activity: 50
Merit: 0


View Profile
May 22, 2024, 03:06:24 PM
 #58

It all seems pointless. Support is inactive. I don't know what to do. We gathered people, we have evidence, but it's all useless
Drazen2003
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
May 23, 2024, 06:32:15 AM
 #59

Freebitco.in never responded to me and my money was stolen because of Freebitco.in

People have to be clear that if there is any problem there is no one in technical support so everything accumulated can be lost and no one will help us.
Cacenn@outlook.com
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
May 23, 2024, 08:34:46 AM
 #60

Did someone got paid back already?

I still havent got an answer about a missing 21300€ from our accounts.
Pages: « 1 2 [3] 4 5 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!