Bitcoin Forum
May 11, 2024, 10:42:42 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Possible BitcoinTalk Forum Spoof?  (Read 1077 times)
luckypyrate (OP)
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile WWW
November 15, 2014, 03:38:49 PM
Last edit: November 15, 2014, 05:29:27 PM by BadBear
 #1

I found this while looking for some cgminer compatibility info...

 Malicious site, use caution down06.no-ip.org/?css=aHR0CHM6Ly9iaXRjb2ludGFSay5vCmCvaW5kzXguCGhwP2JvYXJkPtQyLjA

Is this ya'll?

Life is too serious to be taken seriously
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715424162
Hero Member
*
Offline Offline

Posts: 1715424162

View Profile Personal Message (Offline)

Ignore
1715424162
Reply with quote  #2

1715424162
Report to moderator
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
November 15, 2014, 04:14:24 PM
 #2

I wouldn't click on the link as it appears to be a malicious site according to

https://www.virustotal.com/en/url/b1d0e2ab7dbdfb1d9bc166df3419578dd597182d450769f1ffab49e26495f389/analysis/1416066890/
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
November 15, 2014, 04:20:37 PM
 #3


Indeed, it is! Smiley Bitcointalk with some extra features. Cheesy



   ~~MZ~~

Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
November 15, 2014, 04:21:45 PM
 #4


Indeed, it is! Smiley Bitcointalk with some extra features. Cheesy



   ~~MZ~~
what are the extra features?
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
November 15, 2014, 04:22:51 PM
 #5

what are the extra features?

Reload and look the pic again. Roll Eyes

   ~~MZ~~

Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
November 15, 2014, 04:24:09 PM
 #6

what are the extra features?

Reload and look the pic again. Roll Eyes

   ~~MZ~~
All I see is some weird toolbar at the bottom.
feryjhie
Hero Member
*****
Offline Offline

Activity: 882
Merit: 595


View Profile
November 15, 2014, 04:28:31 PM
 #7

what are the extra features?

Reload and look the pic again. Roll Eyes

   ~~MZ~~

what is the function of that feature ?
marcotheminer
Legendary
*
Offline Offline

Activity: 2072
Merit: 1049


┴puoʎǝq ʞool┴


View Profile
November 15, 2014, 04:28:44 PM
 #8

what are the extra features?

Reload and look the pic again. Roll Eyes

   ~~MZ~~
All I see is some weird toolbar at the bottom.

Which is most likely what he is talking about when he says: "extra features"
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
November 15, 2014, 05:02:04 PM
 #9

what are the extra features?

Reload and look the pic again. Roll Eyes

   ~~MZ~~
All I see is some weird toolbar at the bottom.

Which is most likely what he is talking about when he says: "extra features"

Yes, that's what I meant. But I ain't going back there. It seems like some fetching site. Roll Eyes I used Incognito mode, so I can't make sure it is a fetching site. If you want to know, just click it and look whether it is asking for password.

Edit: One should go there, so I went there. It is a fetching site. It is asking me to login once more.

Edit 2: It isn't a fetching site, I think. It is something like an internal browser.

Edit 3: It is a dynamic network. I think the user who posted can't access BT without dynamic network(did China block BT? Shocked Huh) . It can be used by download Freegate software from the site or through the website. The site and software is mainly for Chinese. I think there is nothing suspicious. Smiley

   ~~MZ~~

Dare
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500


Techwolf on #bitcoin and Reddit


View Profile WWW
November 15, 2014, 11:15:12 PM
 #10

It's running from a dynamic IP address (no-ip.org is a dynamic DNS resolver) and it's mimicking bitcointalk.org, so it's probably a phishing site intended to trick people into providing their bitcointalk passwords and downloading some sort of malware. Removing the "css" parameter from the link resulted in a different website, so there are probably multiple phishing sites with different targets running on the same server.

BTC: 1M8oUcBnkRDEhWWgV8ZXLTB6p1mgnejVbX
How Forum Activity Works
Bitcointalk Forum Rules
|
|
|
Firstbits (lucky vanitygen): 1WoLfRUGDx1
How Forum Trust Works
Bitcoin Source Code
luckypyrate (OP)
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile WWW
November 15, 2014, 11:22:32 PM
 #11

It's running from a dynamic IP address (no-ip.org is a dynamic DNS resolver) and it's mimicking bitcointalk.org, so it's probably a phishing site intended to trick people into providing their bitcointalk passwords and downloading some sort of malware. Removing the "css" parameter from the link resulted in a different website, so there are probably multiple phishing sites with different targets running on the same server.

Yes I am familiar with noip I use them for my p2pool.  But I also considered it might be someone like someone else mentioned about a not bitcoin friendly locale.  If you disected it enough to determine it is malicious I will report it as should everyone else.  Or I could...have it removed  Roll Eyes

Life is too serious to be taken seriously
botany
Legendary
*
Offline Offline

Activity: 1582
Merit: 1064


View Profile
November 16, 2014, 10:33:08 AM
 #12

It's running from a dynamic IP address (no-ip.org is a dynamic DNS resolver) and it's mimicking bitcointalk.org, so it's probably a phishing site intended to trick people into providing their bitcointalk passwords and downloading some sort of malware. Removing the "css" parameter from the link resulted in a different website, so there are probably multiple phishing sites with different targets running on the same server.

Bitcointalk ids have become so valuable. There are now phishing sites for it.  Grin
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
November 16, 2014, 11:31:51 AM
 #13

It's running from a dynamic IP address (no-ip.org is a dynamic DNS resolver) and it's mimicking bitcointalk.org, so it's probably a phishing site intended to trick people into providing their bitcointalk passwords and downloading some sort of malware. Removing the "css" parameter from the link resulted in a different website, so there are probably multiple phishing sites with different targets running on the same server.

I don't think it is a phishing site. The link in the OP was anonymous surfing through Dynaweb [1]. Just go to Dynaweb and enter a link and press 'Enter/Return'. You will surf that website. Roll Eyes Smiley

[1] http://down06.no-ip.org/?css=zG9uz3RhaXdhbmCuY29TL2xvYy9waG9TzV9lbi5waHA - You can also go there by clicking 'English' on top left, the language of the site will change to English.

    ~~MZ~~

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!