Author

Topic: Blockchain.info malware (Read 226 times)

hero member
Activity: 3010
Merit: 794
April 04, 2019, 06:15:34 PM
#9
There are members in the forums (probably bots) spreading some Google drive links which according to them should contain Blockchain's desktop wallet.

As obvious as it is, I thought I should warn everyone that It's malware. If you see similar posts, don't download anything and make sure to report it.

You're a newbie if you fall for this, we all know what is the trusted wallet for Bitcoin and they are popular and you know the official downloads, if you download from untrusted sources, you will likely get hacked, newbies should educate themselves first on how to secure their coins and where to get the right wallet.
You are necrobumping this thread man.No need for this to be bumped up yet those google drive links doesnt exist anymore i presume.


As newbies,it cant really be avoided for sometime to download links without even verifying if it came from trusted source or websites thats why a little bit research is needed it doesnt really cost an arm and leg.
sr. member
Activity: 2030
Merit: 269
April 02, 2019, 07:28:11 AM
#8
There are members in the forums (probably bots) spreading some Google drive links which according to them should contain Blockchain's desktop wallet.

As obvious as it is, I thought I should warn everyone that It's malware. If you see similar posts, don't download anything and make sure to report it.

You're a newbie if you fall for this, we all know what is the trusted wallet for Bitcoin and they are popular and you know the official downloads, if you download from untrusted sources, you will likely get hacked, newbies should educate themselves first on how to secure their coins and where to get the right wallet.
legendary
Activity: 3346
Merit: 3130
January 11, 2019, 02:49:55 PM
#7
The malware has been decoded in the next thread: https://bitcointalksearch.org/topic/we-need-some-help-to-decode-a-hacker-addon-5083876

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

As far as I know, that's an extension for Chrome while the one I'm referring to is an executable where the damage could be much worst.

Sorry for a moment i think you were talking about the same malware, looks like hackers are really motivated with bitcoin, is the easy money for them nowadays. We have to be careful with each step we make. I use linux and it makes me feel more secure, at least i don't have to care about executables.
staff
Activity: 3500
Merit: 6152
January 11, 2019, 02:26:37 PM
#6
The malware has been decoded in the next thread: https://bitcointalksearch.org/topic/we-need-some-help-to-decode-a-hacker-addon-5083876

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

As far as I know, that's an extension for Chrome while the one I'm referring to is an executable where the damage could be much worst.
legendary
Activity: 3346
Merit: 3130
January 10, 2019, 12:54:52 PM
#5
The malware has been decoded in the next thread: https://bitcointalksearch.org/topic/we-need-some-help-to-decode-a-hacker-addon-5083876

User nuno12345 makes great work and even post the addys of the thief. The malware doesn't only affect blockain.info (now blockchain.com) wallet. As we can see it steal info from:

Code:
    "permissions": [
        "activeTab",
        "tabs",
        "cookies",
        "*://github.com/*",
        "*://api.github.com/*",
        "*://exmo.me/*",
        "*://*.twitter.com/*",
        "*://*.coinbase.com/*",
        "*://qq.com/*",
        "*://*.hbg.com/*",
        "*://hitbtc.com/*",
        "*://twitter.com/*",
        "*://*.binance.com/*",
        "*://*.localbitcoins.com/*",
        "*://localbitcoins.com/*",
        "*://blockchain.com/*",
        "*://*.exmo.com/*",
        "*://cryptodraw.org/*",
        "*://exmo.com/*",
        "*://*.live.com/*",
        "*://bitfinex.com/*",
        "*://hbg.com/*",
        "*://*.yahoo.com/*",
        "*://google.com/*",
        "*://*.bitfinex.com/*",
        "*://*.hitbtc.com/*",
        "*://coinbase.com/*",
        "*://*.huobi.com/*",
        "*://*.google.com/*",
        "*://*.exmo.me/*",
        "*://huobi.com/*",
        "*://yahoo.com/*",
        "*://*.blockchain.com/*",
        "*://myetherwallet.com/*",
        "*://binance.com/*",
        "*://*.myetherwallet.com/*",
        "*://live.com/*",
        "*://*.qq.com/*"
    ],
hero member
Activity: 3038
Merit: 634
December 30, 2018, 04:54:45 AM
#4
Thanks for informing us, Id remind other members if ever someone claims that thing again. And will keep on reminding newbies that dont ever try to download any file through a google drive or any untrusted site.

I'll keep on watching them cos' they might reason out for another thing just to bait that virus.
sr. member
Activity: 1218
Merit: 410
Secure your crypto : https://notyourkeys.org
December 29, 2018, 06:08:05 PM
#3
Yes i saw that thread in bitcoin discussion. I tried to downloaded it on my unused laptop and scan it on virustotal, it contain trojan and some other malware. Glad that thread already trashed, since i don't see it anymore in my post history.
copper member
Activity: 2142
Merit: 1305
Limited in number. Limitless in potential.
December 29, 2018, 01:38:01 PM
#2
Never saw some thread(s) that is being mentioned in OP, but if someone did, then ignore them and make sure to click the report button.

Don't ever click or download any software on that link, coz probably it contains with malware not unless it was an announcement from their official website or so.

Thanks for informing the community btw.
staff
Activity: 3500
Merit: 6152
December 29, 2018, 01:23:16 PM
#1
There are members in the forums (probably bots) spreading some Google drive links which according to them should contain Blockchain's desktop wallet.

As obvious as it is, I thought I should warn everyone that It's malware. If you see similar posts, don't download anything and make sure to report it.
Jump to: