Bitcoin Forum
May 10, 2024, 04:43:53 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: New Fake Electrum Wallet BEWARE!  (Read 2208 times)
yampi (OP)
Sr. Member
****
Offline Offline

Activity: 433
Merit: 250


View Profile
March 06, 2015, 05:43:22 PM
Last edit: March 07, 2015, 02:34:55 PM by yampi
 #1

Recently there is an ad to a fake Electrum wallet which installs DarkComet TROJAN onto your computer.
The official electrum wallet site has https, the fake one does not.
Oh and the domain is OBVIOUSLY different than the official's.
Please validate file signatures.
Here's a virustotal anlysis report of the fake wallet file: here
1715316233
Hero Member
*
Offline Offline

Posts: 1715316233

View Profile Personal Message (Offline)

Ignore
1715316233
Reply with quote  #2

1715316233
Report to moderator
1715316233
Hero Member
*
Offline Offline

Posts: 1715316233

View Profile Personal Message (Offline)

Ignore
1715316233
Reply with quote  #2

1715316233
Report to moderator
1715316233
Hero Member
*
Offline Offline

Posts: 1715316233

View Profile Personal Message (Offline)

Ignore
1715316233
Reply with quote  #2

1715316233
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715316233
Hero Member
*
Offline Offline

Posts: 1715316233

View Profile Personal Message (Offline)

Ignore
1715316233
Reply with quote  #2

1715316233
Report to moderator
DarkHyudrA
Legendary
*
Offline Offline

Activity: 1386
Merit: 1000


English <-> Portuguese translations


View Profile
March 06, 2015, 06:06:00 PM
 #2

And where you got the fake electrum?
You mean an ad here on the forum?

English <-> Brazilian Portuguese translations
abyrnes81
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500



View Profile
March 06, 2015, 06:07:31 PM
 #3

And where you got the fake electrum?
You mean an ad here on the forum?


I am interested to know the same thing, where do you downloaded the "fake" one? Can you give use the link between the (code) (/code) tag for security.
jbrnt
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500



View Profile
March 06, 2015, 06:21:52 PM
 #4

Thank you for the warning. Where is the fake Electrum? Is it from a thread here on the forum?


dezoel
Legendary
*
Offline Offline

Activity: 2016
Merit: 1072


Leading Crypto Sports Betting & Casino Platform


View Profile
March 07, 2015, 04:50:19 AM
 #5

ehm, where is you find it?
can us see the link?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
niktitan132
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000



View Profile
March 07, 2015, 09:00:30 AM
 #6

Recently there is an ad to a fake Electrum wallet which installs DarkComet TROJAN onto your computer.
The official electrum wallet site has https, the fake one does not.
Please validate file signatures.
Here's a virustotal anlysis report of the fake wallet file: here
Report the domain and they will hopefully take it down.

Also, he must share the domain name here so we can report it too (the website will be faster taken down by host).
lacomepollos
Full Member
***
Offline Offline

Activity: 168
Merit: 100

..... ..... ..... .....


View Profile
March 07, 2015, 09:02:28 AM
 #7

Thanks for this

------------------------------------------------------------------------------------------------------------------------------------------------------
LiteCoinGuy
Legendary
*
Offline Offline

Activity: 1148
Merit: 1010


In Satoshi I Trust


View Profile WWW
March 07, 2015, 09:05:35 AM
 #8

thx for the warning. download the original here:

https://electrum.org/#home

avatar_kiyoshi
Legendary
*
Offline Offline

Activity: 1106
Merit: 1000



View Profile
March 07, 2015, 10:07:54 AM
 #9

Thanks for the warning us.
This official thread https://bitcointalk.org/index.php?topic=973768.0 by ThomasV
How to report that fake electrum wallet?
abyrnes81
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500



View Profile
March 07, 2015, 10:47:32 AM
 #10

Thanks for the warning, I always download the official software from the real site and not from an unknown thread or site. Beware !
innocent93
Legendary
*
Offline Offline

Activity: 896
Merit: 1000



View Profile
March 07, 2015, 11:07:57 AM
 #11

Never download any kind of wallet beyond their official website if you don't want to lose your money.
koelen3
Legendary
*
Offline Offline

Activity: 1022
Merit: 1007


Sooner or later, a man who wears two faces forgets


View Profile
March 07, 2015, 11:23:35 AM
 #12

This should rather be share on the Beginners Section too , just to make them aware of it!
THank you for sharing it
9000
Full Member
***
Offline Offline

Activity: 255
Merit: 100


View Profile
March 07, 2015, 11:48:28 AM
 #13

Thanks for the warning, one is never too careful online...
luv2drnkbr
Hero Member
*****
Offline Offline

Activity: 793
Merit: 1016



View Profile
March 07, 2015, 12:09:17 PM
 #14

Verify PGP sigs!!!

A10010
Newbie
*
Offline Offline

Activity: 31
Merit: 0


View Profile
March 07, 2015, 01:28:08 PM
 #15

Just another reminder why we need to be extra careful online, scams everywhere!
Bralex
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250



View Profile
March 07, 2015, 01:31:48 PM
 #16

Was only yesterday i downloaded electrum for the first time believe it or not, i checked the signature though so all was good. If everyone done this then the fake wallet would be useless but of course not everyone pays attention to what they download, which is crap because then the hackers will keep going while there are people to steal from.

cloudthink.io   



 



 



 



 



 



Truly Profitable Investment Packages
Custom-Built ASIC Miners ● #1 Self-Sustainable Bitcoin Mining Service in the World ●
twister
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile WWW
March 07, 2015, 02:34:09 PM
 #17


The official electrum wallet site has https, the fake one does not.


Is that possible, can a hacker host files to someone else's domain with http?

Verify PGP sigs!!!

Sorry for the stupid ques but how does one exactly do that with the downloads?

 

██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
 
Get Free Bitcoin Now!
  ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦   
0.8%-1% House Edge
[/
DarkHyudrA
Legendary
*
Offline Offline

Activity: 1386
Merit: 1000


English <-> Portuguese translations


View Profile
March 09, 2015, 11:07:34 AM
 #18


The official electrum wallet site has https, the fake one does not.


Is that possible, can a hacker host files to someone else's domain with http?

Verify PGP sigs!!!

Sorry for the stupid ques but how does one exactly do that with the downloads?

First question: nope, with or without SSL/TSL, you're connecting to the same website. He probably confused with a phishing someting like el3ctrum or electrun.

Second question, he probably meant the md5 hash for checksum, it's always said on the official website so that you can guarantee that you're downloading the right version.

English <-> Brazilian Portuguese translations
mistercoin
Legendary
*
Offline Offline

Activity: 1042
Merit: 1000


https://r.honeygain.me/XEDDM2B07C


View Profile WWW
March 09, 2015, 12:13:04 PM
 #19

Recently there is an ad to a fake Electrum wallet which installs DarkComet TROJAN onto your computer.
The official electrum wallet site has https, the fake one does not.
Oh and the domain is OBVIOUSLY different than the official's.
Please validate file signatures.
Here's a virustotal anlysis report of the fake wallet file: here

Thanks for the heads up. I will send a newsletter out to my subscribers about it.

Bizmark13
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


WikiScams.org - Information about Bitcoin Scams


View Profile
March 09, 2015, 12:16:12 PM
 #20


The official electrum wallet site has https, the fake one does not.


Is that possible, can a hacker host files to someone else's domain with http?

Verify PGP sigs!!!

Sorry for the stupid ques but how does one exactly do that with the downloads?

First question: nope, with or without SSL/TSL, you're connecting to the same website. He probably confused with a phishing someting like el3ctrum or electrun.

Second question, he probably meant the md5 hash for checksum, it's always said on the official website so that you can guarantee that you're downloading the right version.

If you go to the official download page for Electrum, next to each download link you will see a PGP signed signature from one of the devs.

As for the MD5 hash, you can get it by right clicking on the file and choosing "properties". A window should appear with some tabs on the top. Click on the "checksums" tab to see the MD5 hash:



Note however that the encryption behind MD5 hashes isn't completely resistant to forgeries, i.e. it is possible to construct collisions that result in two different files having the same MD5 hash.
kolloh
Legendary
*
Offline Offline

Activity: 1736
Merit: 1023


View Profile
March 09, 2015, 12:31:12 PM
 #21

Thanks for the warning. I would definitely report this to the webhost so they can take it offline.
tss
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
March 09, 2015, 12:40:21 PM
 #22

thanks for the warning but i don't see any info.  no link to fake site to report and no confirmation on where the malicious file is being advertised.
twister
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile WWW
March 09, 2015, 03:28:18 PM
 #23

First question: nope, with or without SSL/TSL, you're connecting to the same website. He probably confused with a phishing someting like el3ctrum or electrun.

Yeah, I wasn't really sure that that could happen but I thought maybe some hackers developed something new. Thanks for clearing it up. He added in the OP now that the site is different.

Second question, he probably meant the md5 hash for checksum, it's always said on the official website so that you can guarantee that you're downloading the right version.

If you go to the official download page for Electrum, next to each download link you will see a PGP signed signature from one of the devs.

As for the MD5 hash, you can get it by right clicking on the file and choosing "properties". A window should appear with some tabs on the top. Click on the "checksums" tab to see the MD5 hash:



Note however that the encryption behind MD5 hashes isn't completely resistant to forgeries, i.e. it is possible to construct collisions that result in two different files having the same MD5 hash.

I see, so the only way to be safe while downloading Electrum is to make sure to download from the original site because the hacker can't possibly upload the forged MD5 hashed version at the original site.

And the PGP signature contains the MD5 Hash, so one can verify that even that is from the original site owner.

 

██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
 
Get Free Bitcoin Now!
  ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦   
0.8%-1% House Edge
[/
luv2drnkbr
Hero Member
*****
Offline Offline

Activity: 793
Merit: 1016



View Profile
March 09, 2015, 07:52:31 PM
 #24


The official electrum wallet site has https, the fake one does not.


Is that possible, can a hacker host files to someone else's domain with http?

Verify PGP sigs!!!

Sorry for the stupid ques but how does one exactly do that with the downloads?

First question: nope, with or without SSL/TSL, you're connecting to the same website. He probably confused with a phishing someting like el3ctrum or electrun.

Second question, he probably meant the md5 hash for checksum, it's always said on the official website so that you can guarantee that you're downloading the right version.

NO, no no!!!  I did NOT mean the md5.  That can be written on the forged website.

I meant the PGP signature.  The PGP signature *HAD* to have come from the actual Electrum developers.  THAT'S what you need to verify.

To the right of the link to download, you'll see another link that says "sig" or "signature", which will lead you to either a .asc file or a .sig  file.

You then use PGP software (usually in the form of GPG) to verify that the signature is correct and from either the key:

9914864DFC33499C6CA2BEEA22453004695506FD

or the key

6694D8DE7BE8EE5631BED9502BD5824B7F9470E6

You need to learn how to use GPG for that.  It's a pain in the ass to learn, but once you learn it, it is extremely useful.  It's that same software people use to encrypt their e-mail.  Google and find Youtube videos about setting it up.  It takes time to learn, and that sucks, but you'll be glad you know it once you do.

The PGP signature, unlike a hash, can only be created by the developers.  So even if the website is hacked and the hackers put up new md5's for their evil files, they still can't make fake PGP signatures.

twister
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile WWW
March 10, 2015, 09:45:20 AM
 #25


NO, no no!!!  I did NOT mean the md5.  That can be written on the forged website.

I meant the PGP signature.  The PGP signature *HAD* to have come from the actual Electrum developers.  THAT'S what you need to verify.

To the right of the link to download, you'll see another link that says "sig" or "signature", which will lead you to either a .asc file or a .sig  file.

You then use PGP software (usually in the form of GPG) to verify that the signature is correct and from either the key:

9914864DFC33499C6CA2BEEA22453004695506FD

or the key

6694D8DE7BE8EE5631BED9502BD5824B7F9470E6

You need to learn how to use GPG for that.  It's a pain in the ass to learn, but once you learn it, it is extremely useful.  It's that same software people use to encrypt their e-mail.  Google and find Youtube videos about setting it up.  It takes time to learn, and that sucks, but you'll be glad you know it once you do.

The PGP signature, unlike a hash, can only be created by the developers.  So even if the website is hacked and the hackers put up new md5's for their evil files, they still can't make fake PGP signatures.

Yeah, I get it now. I still don't know how to use PGP, I once tried to make a PGP key for me but got lost halfway. And I have been postponing it since coz it involves a lot of reading. But I guess I have to do it soon if I want to be safe.

 

██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
 
Get Free Bitcoin Now!
  ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦   
0.8%-1% House Edge
[/
tranzactionezlive
Sr. Member
****
Offline Offline

Activity: 261
Merit: 250


View Profile
August 02, 2017, 07:18:57 AM
 #26

If you can, please make this a sticky or make a new thread out of it, people NEED to be warned.

I got robbed of 45.8 BTC (and BCH so total = 150000$) after installing the executable from electrum-wallet.com.

I was running multisig but both on the same PC. First i ran the portable electrum.exe from  electrum-wallet.com but when it did not load my wallets *NOTE : the ones that had BTC in them ,it loaded just fine any other wallet ) - I don't want to hear opinions on my stupidity

After it didn't work i downloaded last version of electrum from electrum.org

I'm wondering how the F is it possible that after 2 years of this thread no one has taken down and/or announced the US. authorities fbi etc about it.

I'm in Romania and have no wish to deal with this legally, which will probably get me nowhere.



I  am willing to split the rights on the BTC with whoever is capable of recovering them via detective+legal means.

This is the transaction : https://www.blocktrail.com/BTC/tx/78d44db46445d3097996fc644c1221eeead31added5c35cf1b7938737e3b49db


As i said , I don't want to hear opinions on my stupidity, this is mostly a warning and hopefully a way for someone to make a healthy 75000$.





Reid
Hero Member
*****
Offline Offline

Activity: 2884
Merit: 642


View Profile
August 02, 2017, 08:09:59 AM
 #27

Only beginners will bite this one. Although it is a good warning and might come in handy for new users.
The website tells it all. It is simply electrum.org.
I guess we just need to be careful with every clicks we make.
For sure just one registry it will all end up with them. This is really bad.
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!