Bitcoin Forum
May 05, 2024, 09:34:26 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Another scam/phishing attempt - blockchain users beware  (Read 2274 times)
Super T (OP)
Full Member
***
Offline Offline

Activity: 124
Merit: 100


View Profile
June 29, 2014, 09:48:53 PM
Last edit: June 29, 2014, 09:59:56 PM by Super T
 #1

OK...

These tweets: https://twitter.com/search?f=realtime&q=follow%20%40shodandice%20for%20latest%20news&src=typd

Suggest a bitcoin exchange has been hacked.

They lead to this pastebin dump: http://pastebin.com/zxj24E6p

Which in turn provides a link to the front page of the "exchange" [link not posted - proceed with caution].

http://imgur.com/QIyHlGJ

A rather shoddy site, and strange, it isn't in the press, but I'm far too curious, surprise surprise, all of the compromised accounts contain funds, and not only that but the option to withdraw them is practically jumping out of the same page at me!

http://imgur.com/oNZ2OOk,pkvY0Q4#0

Clearly my luck is in, hackers have gained access to all user accounts and have benevolently opted to leave the money contained in them to anyone who wants it.

Immediately attempting to withdraw my new found wealth leads to a quick confirmation message "Transaction processed, please check wallet" (or something like that), followed by auto-redirect to a "blockchain" page.

http://imgur.com/oNZ2OOk,pkvY0Q4#1

The blockchain page is not a blockchain page (see URL), and so I assume the plan is to target blockchain users (only?), I am asked to enter my account id and password - and presumably my account gets emptied as soon as details are entered.

They also threw in a malicious file auto-download somewhere along the way (quarantined immediately) - so treat with extreme caution if investigating (I used a local client with NO wallet data anywhere near it, and with restricted permissions).

http://imgur.com/iJaJDcQ

PS - to pre-empt the inevitable accusations that I was attempting to steal these, it just isn't worth the argument, for everyone's sake please humor me with the assumption that I am honest.

1714901666
Hero Member
*
Offline Offline

Posts: 1714901666

View Profile Personal Message (Offline)

Ignore
1714901666
Reply with quote  #2

1714901666
Report to moderator
1714901666
Hero Member
*
Offline Offline

Posts: 1714901666

View Profile Personal Message (Offline)

Ignore
1714901666
Reply with quote  #2

1714901666
Report to moderator
1714901666
Hero Member
*
Offline Offline

Posts: 1714901666

View Profile Personal Message (Offline)

Ignore
1714901666
Reply with quote  #2

1714901666
Report to moderator
Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714901666
Hero Member
*
Offline Offline

Posts: 1714901666

View Profile Personal Message (Offline)

Ignore
1714901666
Reply with quote  #2

1714901666
Report to moderator
1714901666
Hero Member
*
Offline Offline

Posts: 1714901666

View Profile Personal Message (Offline)

Ignore
1714901666
Reply with quote  #2

1714901666
Report to moderator
franky1
Legendary
*
Online Online

Activity: 4214
Merit: 4465



View Profile
June 29, 2014, 09:54:13 PM
 #2

well your only linking imgur and twitter, and not the site. so its not like you can phish information from the images, but thanks for the warning..

people need to stop being so sheepish about websites and start to use proper bitcoin wallets.

only ever put disposable income/pocket-money amounts in online services

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Super T (OP)
Full Member
***
Offline Offline

Activity: 124
Merit: 100


View Profile
June 29, 2014, 10:06:26 PM
 #3

well your only linking imgur and twitter, and not the site. so its not like you can phish information from the images, but thanks for the warning..

Yeah - i was going to put the site link in but thought better of it, anyone keen can get it from the images - hence caution warning.

JBullFrog
Newbie
*
Offline Offline

Activity: 39
Merit: 0


View Profile WWW
June 29, 2014, 10:29:07 PM
 #4

I was about to post something about this here. I will be adding your part about possible phishing when telling others about this.
KSGuy
Sr. Member
****
Offline Offline

Activity: 429
Merit: 250



View Profile
June 30, 2014, 07:21:35 PM
 #5

I saw the tweet as well, seems real fishy

Also what was the file that was downloaded?
Super T (OP)
Full Member
***
Offline Offline

Activity: 124
Merit: 100


View Profile
July 04, 2014, 07:21:32 AM
 #6

Looks like more of the same... these started appearing a few mins ago.



http://m.imgur.com/Bmuxtcc
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!