Hi all,
I'm with the BITCOMSEC (Bitcoin Community Security) Project and I've actually been writing a report on this situation to be released as soon as possible. We were hired by the MidasCoin staff to do a post-hack forensic report once I approached them with evidence that MidasCoin may have been compromised by the same attacker involved with the CryptoRush.in hack. Evident by FTP logs from attackers stash FTP server:
Thu Sep 18 23:18:21 2014 0 222.127.174.73 409 /home3/[redacted]/public_html/upload.php a _ o r [redacted] ftp 1 * c
Thu Sep 18 23:20:19 2014 0 222.127.174.73 1769 /home3/[redacted]/public_html/wall/redis.py b _ o r [redacted] ftp 1 * c
Thu Sep 18 23:23:55 2014 16 222.127.174.73 8069055 /home3/[redacted]/public_html/wall/ubuntu.tar.gz b _ o r [redacted] ftp 1 * c
Fri Sep 19 00:18:17 2014 111 222.127.174.73 55368374 /home3/[redacted]/public_html/wall/php-mpos.tar.gz b _ o r [redacted] ftp 1 * c
Fri Sep 19 01:03:34 2014 12 222.127.174.73 917504 /home3/[redacted]/public_html/wall/mpos.sql b _ o r [redacted] ftp 1 * c
Fri Sep 19 01:49:25 2014 9 222.127.174.73 2842624 /home3/[redacted]/public_html/wall/midaswallet.dat b _ o r [redacted] ftp 1 * c
Fri Sep 19 01:49:27 2014 0 222.127.174.73 22769 /home3/[redacted]/public_html/wall/history.txt a _ o r [redacted] ftp 1 * c
Sun Sep 21 18:48:47 2014 0 120.28.228.59 74 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 18:51:16 2014 0 120.28.228.59 225 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 18:51:59 2014 0 120.28.228.59 254 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 18:56:31 2014 0 120.28.228.59 254 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 18:56:49 2014 0 120.28.228.59 254 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 18:57:01 2014 0 120.28.228.59 255 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:02:14 2014 0 120.28.228.59 729 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:03:52 2014 0 120.28.228.59 874 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:06:32 2014 0 120.28.228.59 903 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:06:46 2014 0 120.28.228.59 903 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:07:43 2014 0 120.28.228.59 910 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:07:47 2014 0 120.28.228.59 910 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:08:08 2014 0 120.28.228.59 923 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:08:25 2014 1 120.28.228.59 929 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 19:08:57 2014 0 120.28.228.59 888 /home3/[redacted]/public_html/wall/sqltest.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 21:36:46 2014 0 120.28.228.59 922 /home3/[redacted]/public_html/wall/log.php a _ o r [redacted] ftp 1 * c
Sun Sep 21 21:37:48 2014 0 120.28.228.59 911 /home3/[redacted]/public_html/wall/log.php a _ i r [redacted] ftp 1 * c
Sun Sep 21 21:38:05 2014 0 120.28.228.59 919 /home3/[redacted]/public_html/wall/log.php a _ i r [redacted] ftp 1 * c
Tue Sep 23 17:58:58 2014 18 121.54.58.246 14647192 /home3/[redacted]/public_html/wall/web.gzip b _ o r [redacted] ftp 1 * c
Tue Sep 23 17:59:04 2014 4 121.54.58.246 2397961 /home3/[redacted]/public_html/wall/stratum-m.gzip b _ o r [redacted] ftp 1 * c
Tue Sep 23 17:59:06 2014 1 121.54.58.246 272205 /home3/[redacted]/public_html/wall/stratum.gzip b _ o r [redacted] ftp 1 * c
Tue Sep 23 17:59:17 2014 10 121.54.58.246 7132833 /home3/[redacted]/public_html/wall/midascoin.gzip b _ o r [redacted] ftp 1 * c
Wed Sep 24 01:54:38 2014 0 121.54.58.246 1 /home3/[redacted]/public_html/wall/ss.txt a _ i r [redacted] ftp 1 * c
Wed Sep 24 01:54:45 2014 0 121.54.58.246 108 /home3/[redacted]/public_html/wall/klss.php a _ i r [redacted] ftp 1 * c
Wed Sep 24 02:05:19 2014 0 121.54.58.246 114 /home3/[redacted]/public_html/wall/klss.php a _ o r [redacted] ftp 1 * c
Wed Sep 24 02:05:38 2014 0 121.54.58.246 137 /home3/[redacted]/public_html/wall/klss.php a _ i r [redacted] ftp 1 * c
Wed Sep 24 02:05:50 2014 0 121.54.58.246 3 /home3/[redacted]/public_html/wall/ss.txt a _ o r [redacted] ftp 1 * c
Wed Sep 24 02:06:19 2014 0 121.54.58.246 22 /home3/[redacted]/public_html/wall/ss.txt a _ o r [redacted] ftp 1 * c
Wed Sep 24 02:08:19 2014 0 121.54.58.246 108 /home3/[redacted]/public_html/wall/klss.php a _ i r [redacted] ftp 1 * c
Wed Sep 24 02:41:49 2014 0 121.54.58.246 450 /home3/[redacted]/public_html/wall/midas/ipsearch.php a _ i r [redacted] ftp 1 * c
Wed Sep 24 02:48:15 2014 0 121.54.58.246 138 /home3/[redacted]/public_html/wall/midas/error_log b _ o r [redacted] ftp 1 * c
Wed Sep 24 02:48:48 2014 0 121.54.58.246 138 /home3/[redacted]/public_html/wall/midas/error_log b _ o r [redacted] ftp 1 * c
You can read my CR hack report at:
https://bitcomsec.true.io/bitcomsec/tracking-a-bitcoin-thief-cryptorush-hack/Currently I'm finalizing my report on this entire hacking scandal with a conclusion, complete with logs and evidence, as to why MidasCoin shut down and who was involved in it shutting down.
But to give you a quick breakdown before my report goes live:
- CR hacker infiltrates MidasCoin
- CR hacker steals a chunk of MidasCoins and dumps on Bittrex
- I was brought in to do the live forensic research
- MidasCoin owner flees without paying me for my research, steals the remaining MidasCoin and dumps it all on Bittrex and has yet to return.
There's another member of the staff who got scammed in the process, as well as the coindev. All victims and two perpetrators (hacker, and owner). As far as I know the community, and staff got scammed by the Italian gentlemen listed elsewhere in this thread.
Hope this clears up some unanswered questions!
Cheers,
Mike