Author

Topic: Fake Mt. Gox emails (Read 1488 times)

hero member
Activity: 868
Merit: 1000
May 26, 2012, 06:21:01 AM
#10
Thread by theymos about the e-currency conference invitation email (don't know why it's hidden away in Off-Topic).

https://bitcointalksearch.org/topic/anyone-else-get-this-malware-email-83496

It's a trojan, as per ZodiacDragon's post in the other thread.

Quote
Trojan.Generic.KDV.102762 is a trojan that captures keystrokes and steals login credentials through a method known as form grabbing. It sends captured data to a remote attacker and is capable of downloading additional malicious components.

https://bitcointalksearch.org/topic/m.920797
legendary
Activity: 1358
Merit: 1002
May 26, 2012, 03:54:03 AM
#9
I don't think so. I have my email in that leaked database and never ever got one of those  Undecided

Same, receive no spam at my gmail, word.

Ah... Mistery solved. Gmail flushes them and they don't even reach the spam folder. Mine is a gmail also.

Just curious, how did you determine that Gmail deletes them automatically?

The same way Gmail determined that I should change my password 10 minutes after the leaked MtGox database got posted.
You really think it's a coincidence that everybody who's on the leaked database gets MtGox phishing emails, except Gmail users?
And, yes, I'm sure they're not in the spam folder because I have the terrible habit of checking it every day, so they must have been deleted.
Or will you go as far as saying that the phisher skips my email(and Clipse's for that matter) just because I'm a nice guy? lol
Also, it's not cost efective to send MtGox phishing emails to emails scraped from the web, or from a completely unrelated list as it will significantly increase exposure to spam filters, thus lowering inboxing rates, while having a very low hit rate of potential victims. I can understand if they do that with paypal phishing emails, but not with MtGox.

I always got bugged why wasn't I getting those emails, but now that I see other Gmail user confirming he doesn't get those emails also I just added 2+2.
legendary
Activity: 1092
Merit: 1016
760930
May 26, 2012, 03:09:02 AM
#8
I don't think so. I have my email in that leaked database and never ever got one of those  Undecided

Same, receive no spam at my gmail, word.

Ah... Mistery solved. Gmail flushes them and they don't even reach the spam folder. Mine is a gmail also.

Just curious, how did you determine that Gmail deletes them automatically?
member
Activity: 68
Merit: 10
May 25, 2012, 08:29:45 PM
#7
So I have received two baited emails in the last two days. I am only going to guess that the crackers are using the leaked db emails from the security failure in gox from a while back, and many other people should watch out for them.

Today's email:
Code:
[email protected] via km33.hostsila.org
11:29 PM (11 hours ago)
Reply
to me
Dear Mt.Gox user,

Your account is currently pending review, please visit https://mtgox.com/forms/verification
For those users who have had their accounts marked for review, an explanation of why were are implementing these security measures can be found here:

Security Measures Explained <-- (this links to a fake login at http://f3w4twfe.tmweb.ru/)

'Verified' Accounts are eligible for monthly/daily transaction limits of up to 5 times the monthly limit and 10 times the daily limit.

In order to apply for the 'Verified' account status please attach a copy of the following documents:
- Your government issued photo ID (passport, permanent residence card or drivers license) and
- A scan of either your monthly utility bill (power, phone, TV, gas, water, etc.) or a certificate of residency issued by your local government.

Thanks,
The Mt.Gox team

And yesterday's email (if you click the link it will bring you to a page which has an auto-download for a likely infected xls file):

Code:
[email protected] via carens.websitewelcome.com
11:45 AM (22 hours ago)
Reply
to me

Invitation to ecurrency conference.

http://asiaelektronik.com/docs/processdl.html

Please let us know if you interested.

Thanks & Regards

I am sure they will send many more messages trying to infect my machine or reveal my gox password (amusingly I have never had any money in gox). Just watch out, and be suspicious of all emails.

If anyone feels semi-vigilantie, feel free to whois the domains and track down the ips to shut down these sites. I am a little geek-overloaded with other stuff today.

Hello,

Thank you for the phishing report.  We have already reported this phishing site to have it shut down.  Thank you once again for the continued support to Mt.Gox.
hero member
Activity: 2618
Merit: 548
SecureShift.io | Crypto-Exchange
May 25, 2012, 05:18:59 PM
#6
I got one these. Phishing Reported! Cool
legendary
Activity: 1358
Merit: 1002
May 25, 2012, 02:29:16 PM
#5
I don't think so. I have my email in that leaked database and never ever got one of those  Undecided

Same, receive no spam at my gmail, word.

Ah... Mistery solved. Gmail flushes them and they don't even reach the spam folder. Mine is a gmail also.
hero member
Activity: 504
Merit: 502
May 25, 2012, 02:11:32 PM
#4
I don't think so. I have my email in that leaked database and never ever got one of those  Undecided

Same, receive no spam at my gmail, word.
legendary
Activity: 1358
Merit: 1002
May 25, 2012, 01:55:26 PM
#3
I don't think so. I have my email in that leaked database and never ever got one of those  Undecided
hero member
Activity: 826
Merit: 1000
May 25, 2012, 01:21:05 PM
#2
So I have received two baited emails in the last two days. I am only going to guess that the crackers are using the leaked db emails from the security failure in gox from a while back, and many other people should watch out for them.

Today's email:
Code:
[email protected] via km33.hostsila.org
11:29 PM (11 hours ago)
Reply
to me
Dear Mt.Gox user,

Your account is currently pending review, please visit https://mtgox.com/forms/verification
For those users who have had their accounts marked for review, an explanation of why were are implementing these security measures can be found here:

Security Measures Explained <-- (this links to a fake login at http://f3w4twfe.tmweb.ru/)

'Verified' Accounts are eligible for monthly/daily transaction limits of up to 5 times the monthly limit and 10 times the daily limit.

In order to apply for the 'Verified' account status please attach a copy of the following documents:
- Your government issued photo ID (passport, permanent residence card or drivers license) and
- A scan of either your monthly utility bill (power, phone, TV, gas, water, etc.) or a certificate of residency issued by your local government.

Thanks,
The Mt.Gox team

And yesterday's email (if you click the link it will bring you to a page which has an auto-download for a likely infected xls file):

Code:
[email protected] via carens.websitewelcome.com
11:45 AM (22 hours ago)
Reply
to me

Invitation to ecurrency conference.

http://asiaelektronik.com/docs/processdl.html

Please let us know if you interested.

Thanks & Regards

I am sure they will send many more messages trying to infect my machine or reveal my gox password (amusingly I have never had any money in gox). Just watch out, and be suspicious of all emails.

If anyone feels semi-vigilantie, feel free to whois the domains and track down the ips to shut down these sites. I am a little geek-overloaded with other stuff today.

Pretty much the leaked Database has become "The" mailing list when it comes to bitcoins. I've received my fair share of fake MtGox emails, spam, and typical newsletter/PSO mail.
hero member
Activity: 533
Merit: 501
May 25, 2012, 12:38:40 PM
#1
So I have received two baited emails in the last two days. I am only going to guess that the crackers are using the leaked db emails from the security failure in gox from a while back, and many other people should watch out for them.

Today's email:
Code:
[email protected] via km33.hostsila.org
11:29 PM (11 hours ago)
Reply
to me
Dear Mt.Gox user,

Your account is currently pending review, please visit https://mtgox.com/forms/verification
For those users who have had their accounts marked for review, an explanation of why were are implementing these security measures can be found here:

Security Measures Explained <-- (this links to a fake login at http://f3w4twfe.tmweb.ru/)

'Verified' Accounts are eligible for monthly/daily transaction limits of up to 5 times the monthly limit and 10 times the daily limit.

In order to apply for the 'Verified' account status please attach a copy of the following documents:
- Your government issued photo ID (passport, permanent residence card or drivers license) and
- A scan of either your monthly utility bill (power, phone, TV, gas, water, etc.) or a certificate of residency issued by your local government.

Thanks,
The Mt.Gox team

And yesterday's email (if you click the link it will bring you to a page which has an auto-download for a likely infected xls file):

Code:
[email protected] via carens.websitewelcome.com
11:45 AM (22 hours ago)
Reply
to me

Invitation to ecurrency conference.

http://asiaelektronik.com/docs/processdl.html

Please let us know if you interested.

Thanks & Regards

I am sure they will send many more messages trying to infect my machine or reveal my gox password (amusingly I have never had any money in gox). Just watch out, and be suspicious of all emails.

If anyone feels semi-vigilantie, feel free to whois the domains and track down the ips to shut down these sites. I am a little geek-overloaded with other stuff today.
Jump to: