Bitcoin Forum
April 24, 2024, 12:27:11 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: New Virus/Malware!  (Read 1869 times)
handmade in CTA (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
September 11, 2014, 12:15:07 PM
 #1

If you receive an bogus email from CoinTerra with an attachament (.jar) do not open. Its a bogus email with a virus. CoinTerra do not send emails like this.


Invoice Payment Confirmation

Kind regards

Mobile: +1 (410) 963-0061
Phone: +1 (430) 487-5488
Fax: +1 (410) 543-1761

Invoice_9985.jar

cointerra Technology IQ Ltd.1140 Jollyville Rd. Ste. 354 Austin TX 78659

1713961631
Hero Member
*
Offline Offline

Posts: 1713961631

View Profile Personal Message (Offline)

Ignore
1713961631
Reply with quote  #2

1713961631
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713961631
Hero Member
*
Offline Offline

Posts: 1713961631

View Profile Personal Message (Offline)

Ignore
1713961631
Reply with quote  #2

1713961631
Report to moderator
1713961631
Hero Member
*
Offline Offline

Posts: 1713961631

View Profile Personal Message (Offline)

Ignore
1713961631
Reply with quote  #2

1713961631
Report to moderator
MTJ151
Full Member
***
Offline Offline

Activity: 221
Merit: 100


View Profile
September 11, 2014, 12:35:53 PM
 #2

I believe that I received this e-mail a few weeks ago. Although it was from a different random company.

The .jar file contained an exe which I did not dare to click/extract.
Jamie_Boulder
Sr. Member
****
Offline Offline

Activity: 378
Merit: 250


View Profile WWW
September 11, 2014, 01:43:40 PM
 #3

There's also one for Robyn Williams "tribute video" going around, just a FYI

arieq
Sr. Member
****
Offline Offline

Activity: 364
Merit: 254


View Profile
September 12, 2014, 02:49:15 AM
 #4

I got an email titled "OKCoin Invoice" today with the same malware (jar file) attached. It seems the malware is being widely spread.

More information can be found here www.reddit.com/r/ReverseEngineering/comments/2291z8/how_badly_did_i_get_owned/

Xiaoxiao
Legendary
*
Offline Offline

Activity: 1274
Merit: 1000

The Golden Rule Rules


View Profile
September 12, 2014, 06:52:43 AM
 #5

If you receive an bogus email from CoinTerra with an attachament (.jar) do not open. Its a bogus email with a virus. CoinTerra do not send emails like this.


Invoice Payment Confirmation

Kind regards

Mobile: +1 (410) 963-0061
Phone: +1 (430) 487-5488
Fax: +1 (410) 543-1761

Invoice_9985.jar

cointerra Technology IQ Ltd.1140 Jollyville Rd. Ste. 354 Austin TX 78659



This happend to me in fact.  Since I was with gmail, gmail even offered to open the file within gmail.  similar to how you can open pdf's and other documents by gmail without having to download 1st.
handmade in CTA (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
September 13, 2014, 08:28:38 AM
 #6

One more... Smiley This bastards never stops.

Dear Users

we make program Google Authenticator security For Cloud Hashing .

you need to setup the program in computer then make Google Code

we attach Google Authenticator Program

Sincerely,

Cloud Hashing

google@cloudhashing.com

Google Authenticator.jar
xcapator
Sr. Member
****
Offline Offline

Activity: 322
Merit: 252

Here I Am !!


View Profile
September 14, 2014, 03:07:12 AM
 #7

Jar files should have been blocked and
One more... Smiley This bastards never stops.

Dear Users

we make program Google Authenticator security For Cloud Hashing .

you need to setup the program in computer then make Google Code

we attach Google Authenticator Program

Sincerely,

Cloud Hashing

google@cloudhashing.com

Google Authenticator.jar

I also got an email that appeared to be sent from Cloudhashing :

Quote
Subject: Invoice 764
Date: Wed, 10 Sep 2014 02:19:01 +1100
From: CloudHashing <no_reply@cloudhashing.com>

Invoice Payment Confirmation

Kind regards

Mobile: +1 (510) 973-1050
Phone: +1 (530) cloudhashing
Fax: +1 (510) 573-2760
Technology IQ Ltd. 11130 Jollyville Rd. Ste. 304 Austin TX 78759

The email contained a so-called invoice payment confirmation (Invoice_764.jar) as an attachment. I immediately deleted the email before my system getting infected

giveBTCpls
Sr. Member
****
Offline Offline

Activity: 322
Merit: 250


View Profile
September 14, 2014, 11:05:28 PM
 #8

I always double check the email addreses for something suspicious, but this one seems pretty well done. In any case, I would contact the original source about them sending jar files with executables first... suspicious.

phantomcircuit
Sr. Member
****
Offline Offline

Activity: 463
Merit: 252


View Profile
September 15, 2014, 02:10:23 AM
 #9

Jar files should have been blocked and
One more... Smiley This bastards never stops.

Dear Users

we make program Google Authenticator security For Cloud Hashing .

you need to setup the program in computer then make Google Code

we attach Google Authenticator Program

Sincerely,

Cloud Hashing

google@cloudhashing.com

Google Authenticator.jar

I also got an email that appeared to be sent from Cloudhashing :

Quote
Subject: Invoice 764
Date: Wed, 10 Sep 2014 02:19:01 +1100
From: CloudHashing <no_reply@cloudhashing.com>

Invoice Payment Confirmation

Kind regards

Mobile: +1 (510) 973-1050
Phone: +1 (530) cloudhashing
Fax: +1 (510) 573-2760
Technology IQ Ltd. 11130 Jollyville Rd. Ste. 304 Austin TX 78759

The email contained a so-called invoice payment confirmation (Invoice_764.jar) as an attachment. I immediately deleted the email before my system getting infected


If you check the headers you'll find that the email was sent from smtp.com.

The email does NOT come from cloudhashing.

Please forward the email with a complaint to abuse@smtp.com
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!