Author

Topic: Eaglecoin wallet is heavily infected with trojans!! (Read 759 times)

legendary
Activity: 1638
Merit: 1013
Thanks for advice,  This guys now could are moving on new coins. Anyway always backup you wallets and lock it, When you have noted that you wallet was stolen, Try of use another computer to unlock you wallet and transfer funds to another adress more safe, it will give less time to an attack of brute force to found the pass.

My advice would be:

1) Always install all wallets for coins on a standalone system or in a sandbox environment.
2) Always move coins to offline wallets (cold storage) and keep only a minimum in a hotfile. A Hotfile is the wallet.dat currently on your PC in the normal location ..\roaming\coinname\wallet.dat | ~/.coinname/wallet.dat. Offline or cold storage is when you copy your main wallet.dat with your coins in it to a USB stick/(s) and remove the wallet.dat from your PC. Offline or cold storage is also sending your coins to a paper wallet. This is problematic through for staking coins and that is why I prefer POW coins. if you do have staking coins, put them on a dedicated Raspbery Pi that runs Linux.
3) If you are uncomfortable with a Windows wallet then don't use a Windows wallet but compile and use a Linux wallet.
4) If anyone quotes a wallet download link, make sure that the quoted link still matches and that the checksums are the same.
5) Always first run the wallet through Virustotal.com to get some level of assurance.
6) After 2 days or so run a wallet through Virus total again and re-analyse to see if the scan engines pick anything up after having worked since.
7) Install software that scramble the data between your keyboard and the operating system so that keylogging malware records garbage and attackers cannot steal your coins because they cannot unlock your wallet.dat with the "garbage" password.
8.) Always encrypt your wallet.dat with a long password of 20+ characters consisting of uppercase and lowercase letters, digits and non-alphabetic characters like * or &.

What is interesting is that this particular Eaglecoin wallet only had one obscure detection of a suspicious file on Virustotal when it released a few days back. It was strange enough though to raise the alarm bells with me. After first submission, the AV scan engines then started working on it and by 2 days later, almost half of them have classified the Trojan/(s) and were able to detect it accurately. This could happen because it is possible to obfuscate a virus or to change it slightly so that attack signatures do not pick it up. Sometimes malware can also fool a sandbox behavior analysis. It is important though to get a file into Virustotal asap so that the code is logged.
legendary
Activity: 938
Merit: 1000
Thanks for advice,  This guys now could are moving on new coins. Anyway always backup you wallets and lock it, When you have noted that you wallet was stolen, Try of use another computer to unlock you wallet and transfer funds to another adress more safe, it will give less time to an attack of brute force to found the pass.
hero member
Activity: 851
Merit: 1000
Do You Even Onion Bro?
This happen to me 2 weeks ago got link to get 1 week of free mining on cloud mining 5 minutes after i downloaded it all my coin from my computer wallets were stolen even the coins i had on the exchanges where stolen i had sent coins to local bitcoin they took those to ........these people are low life steeling of people that have invested money into this miners  the cost of electricity and are time  im really tiered of it now you can't even trust some Dev it getting pretty bad......this just make crypto currency look bad...Make sure before you download something to check for TROGANS .......WE NEED MORE PEOPLE LIKE.... JC12345....THANKS FOR THE WARNING.....
sr. member
Activity: 247
Merit: 250
more positives dont necessarily mean its more infected, just easier detected   Wink
legendary
Activity: 1638
Merit: 1013
Wow if that is the real virustotal upload, that goes way beyond any false positive I have ever seen.

It is probably the most infected I have seen so far.
sr. member
Activity: 296
Merit: 251
Wow if that is the real virustotal upload, that goes way beyond any false positive I have ever seen.
legendary
Activity: 1638
Merit: 1013
NBGH keep deleting my warning posts in the Eaglecoin thread and has now locked the thread at the point just after he says there is a new wallet and big news is coming. He is obviously hoping that unsuspecting people will download the infected wallet and then he steals their passwords and wallet.dat files.

Here is the Virustotal link to the wallet he posted on 25 August and judge for yourself. Be very careful of the Eaglecoin wallet and compare the SHA256 checksum to the Virustotal checksum to see if you are running an infected wallet.

Wallet updated.Big news coming for eagle very soon

https://www.virustotal.com/en/file/0f56e64231cbccdae04476b1f8e0426574e8a1908d330e0defa2212ff152a3d1/analysis/1440815970/

Original (now locked) thread. https://bitcointalksearch.org/topic/anneaglecoineapowsha256launchedyobit-1104710
Jump to: