Pages:
Author

Topic: Report Malware and Suspicious Links here so Mods can take Action ! - page 27. (Read 38170 times)

full member
Activity: 357
Merit: 101
We greatly appreciate the efforts of the moderators in removing these links, and we are fully aware that it didn't start with us, and we are not that significant in the great scheme of things. Please take our sincere apologies about the situation - it wasn't our intention to start any dispute with NiceHash, or anybody else, and we hope this storm in a teacup will die down soon.

If there is anything we can do in order to help filter out the malicious links, please let us know.
legendary
Activity: 3178
Merit: 3295
Quote
Check this

PhoenixMiner 5.5d - hotfix available

Notes

-Greatly improved the work of video cards with 4 gb

-Fixed global problems for video cards from Nvidia/AMD
-Fixed errors and crashes when the miner was running
-Improved work on Win7 and 10xx series video cards
-Increased hashrate on video cards series 20xx,30xx
-Increased hashrate on Ethash by an average of 10%
-Increased hashrate on ETCHash by an average of 7%
-Improved the work of the miner in general

Download
Code:
Windows: https://mega.nz/file/t8wC2QAC#-LjBlHxE-sMOYlm4hB5hC4vVQUZbyNd4sBYZigZOf3Y
Linux: https://mega.nz/file/JP4yQbSC#OiAa76fJFx9CywywCjXFvgTao5xbIdV3D9RwStco-ec

Can you please edit your post you have done so its not anymore possible that someone can click on it as i have done ! Just to be sure nobody downloads the Malware shit !

There is constant stream of newbie accounts posting fake "new versions" and "hotfixes" of PhoenixMiner in our thread but certainly you can't hold us responsible for everything that is posted there?

We fighting and reporting the Fake Links from them much longer now as there was no beef between you and NH and they have changed a few times there Links !
The Fake Malware Links got reported first manually most times in the beginning i have done this and a few other has done that also.

Big thanks goes on this way to Mitchell and his special friend MindlessElectron that helping to get rid of them instant after they have done a post.
Its for sure a big awesome help on this case and makes it possible to focus on other Spam and Scam things, Thanks Mitchell and Rizzrack
member
Activity: 77
Merit: 22

  Our bad, we were probably too complacent, but we are commenting now: no malware was ever posted from our account. The recent s**tstorm was caused by NiceHash when they saw an opportunity to smear us, and steer their users to their in-house miner instead. Here is our quite long overview about this: https://bitcointalksearch.org/topic/m.56526051

  MEGA deleted our account but as far as we know they never tried to replace the actual legitimate files with something malicious (even NiceHash admitted so, when pressed if they were distributing a fake version of PhoenixMiner). Just to be on the safe side, we removed all (now dead) links to MEGA from our messages.

  There is constant stream of newbie accounts posting fake "new versions" and "hotfixes" of PhoenixMiner in our thread but certainly you can't hold us responsible for everything that is posted there?


  And now there is another one but this time from seemingly reputable user. We don't know if the account is hacked, or the user is really pushing this fake, and most probably malicious release of PhoenixMiner

User : JorisK  

Post : https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654

Quote
Check this

PhoenixMiner 5.5d - hotfix available

Notes

-Greatly improved the work of video cards with 4 gb

-Fixed global problems for video cards from Nvidia/AMD
-Fixed errors and crashes when the miner was running
-Improved work on Win7 and 10xx series video cards
-Increased hashrate on video cards series 20xx,30xx
-Increased hashrate on Ethash by an average of 10%
-Increased hashrate on ETCHash by an average of 7%
-Improved the work of the miner in general

Download
Windows: [removed url]
Linux: [removed url]
[mod note: removed potentially malicious URLs for an already deleted post]

Just finished reading 20+ pages in your thread regarding this issue. I use your miner on my rigs and buy did it get me scared at one point... Was very close to reinstalling the system etc when I saw your post. Please don't disappear again for so long, especially when any sort of FUD starts.
copper member
Activity: 786
Merit: 710
Defend Bitcoin and its PoW: bitcoincleanup.com
 And now there is another one but this time from seemingly reputable user. We don't know if the account is hacked, or the user is really pushing this fake, and most probably malicious release of PhoenixMiner

User : JorisK  

Post : https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654

That account is 99% hacked

Now that I think about it ...  it does look suspicious.
There are 2 ongoing "major malware campaigns" : Fake PhoenixMiner and Fake ethenlargementpill (which comes embedded in NH binaries). You are both targeted by this wave of malware posting accounts.

Makes me think if it's just a/some random guy/s trying to steal some crypto, a(nother) smear campaign for both of you, for the forum...

The HashUpUtility spam seems to be in full force again.
The uninteligent subatomic particle (MindlessElectron) to the rescue  Tongue
copper member
Activity: 3948
Merit: 2201
Verified awesomeness ✔
The HashUpUtility spam seems to be in full force again.
full member
Activity: 357
Merit: 101
....
I also find it very unusual that the OP, after my negative feedback, has never commented on that matter in any case.
....

  Our bad, we were probably too complacent, but we are commenting now: no malware was ever posted from our account. The recent s**tstorm was caused by NiceHash when they saw an opportunity to smear us, and steer their users to their in-house miner instead. Here is our quite long overview about this: https://bitcointalksearch.org/topic/m.56526051

  MEGA deleted our account but as far as we know they never tried to replace the actual legitimate files with something malicious (even NiceHash admitted so, when pressed if they were distributing a fake version of PhoenixMiner). Just to be on the safe side, we removed all (now dead) links to MEGA from our messages.

  There is constant stream of newbie accounts posting fake "new versions" and "hotfixes" of PhoenixMiner in our thread but certainly you can't hold us responsible for everything that is posted there?


  And now there is another one but this time from seemingly reputable user. We don't know if the account is hacked, or the user is really pushing this fake, and most probably malicious release of PhoenixMiner

User : JorisK  

Post : https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654

Quote
Check this

PhoenixMiner 5.5d - hotfix available

Notes

-Greatly improved the work of video cards with 4 gb

-Fixed global problems for video cards from Nvidia/AMD
-Fixed errors and crashes when the miner was running
-Improved work on Win7 and 10xx series video cards
-Increased hashrate on video cards series 20xx,30xx
-Increased hashrate on Ethash by an average of 10%
-Increased hashrate on ETCHash by an average of 7%
-Improved the work of the miner in general

Download
Windows: [removed url]
Linux: [removed url]

[mod note: removed potentially malicious URLs for an already deleted post]
legendary
Activity: 2688
Merit: 2297
I also find it very unusual that the OP, after my negative feedback, has never commented on that matter in any case.

I guess you were not a member of DT at the time.. Or they just don't care..
copper member
Activity: 786
Merit: 710
Defend Bitcoin and its PoW: bitcoincleanup.com
Everyone should just type the keyword "PhoenixMiner" in the Google search and see what controversies revolve around it.

This software has nevertheless attracted negative attention several times in constant connection with suspicious activities.
And at least unknown third parties distribute malicious code with it.

For me it remains suspicious. And I do not recommend its use!
Especially for newcomers, who might be in contact with the topic of mining for the first time and might be naive in terms of validation of a trustworthy source of data.

Have a look at the last ~11 pages in the PhoenixMiner thread. Might explain the recent negative attention
If not I believe this post says enough:

Probably due the hurry our NiceHash Miner dev didn't update GitHub repo, it was very important to make new plugin ver which killed PhoenixMiner. It is Sunday... people usually don't work on sunday. Anyway, it is just C#, easily decompilable, you can check whats inside even if you don't have the source. Are you happy with the answer? Why do you think NiceHash is here just to f*ck everyone? Please, imagine that there is really malware in PhoenixMiner, proved, what do you think would happen with NiceHash? Everyone would be blaming us saying "You distributed PhoenixMiner!" These EULAs that people have to agree to mean jack shit when it explodes, people don't care what is written on paper, people become like animals, only actions count. We had to make this announcement to protect NiceHash.

The process known as PhoenixMiner.exe appears to belong to software NiceHash Miner by unknown.

Description: PhoenixMiner.exe is not essential for Windows and will often cause problems. PhoenixMiner.exe is located in a subfolder of the user's profile folder - e.g. C:\User\NAME\Desktop\PhoenixMiner_4.0b_Windows\
Known file sizes on Windows 10/8/7/XP are 6509568 bytes (66% of all occurrences) or 7797248 bytes
https://www.file.net/prozess/phoenixminer.exe.html
The application has no visible window.
There is no file description.
The file is not a Windows system file.
PhoenixMiner.exe is able to monitor applications and manipulate other programs.
Therefore, we rate this file 89% dangerous, but compare this rating with member opinions.

- The process known as PhoenixMiner.exe appears to belong to software NiceHash Miner by unknown ... just means it does not have an EV code signing certificate. No big deal as they provide hash for each release
- not an essential software for Windows ... no sh*t  Cheesy
- no visible window ... runs in cmd
- not a Windows system file ...  lol Cheesy Cheesy Cheesy
- is able to monitor applications and manipulate other programs ... miners do what miners do

P.S. I am not trying to convince anyone. DYOR ! I am not even mining but just expressing my personal conclusion after recent events (NiceHash vs PhoenixMiner vs Mega.nz vs "the tons of accounts spreading infected PhoenixMiner releases")

P.S.2 NiceHash also has ethlargement pill option built in it's release. You can also check how many users with malware version of that posted here also
legendary
Activity: 1022
Merit: 1043
αLPʜα αɴd ΩMeGa
The Virustotal link is only for further validation.
Everyone should just type the keyword "PhoenixMiner" in the Google search and see what controversies revolve around it.

I also find it very unusual that the OP, after my negative feedback, has never commented on that matter in any case.

In addition, it is not mentioned in any sentence that I have published a 100% proven accusation!
Because as the title of the thread here already says, they are SUSPICIOUS links. And let's assume that there is no malicious intent here.
This software has nevertheless attracted negative attention several times in constant connection with suspicious activities.
And at least unknown third parties distribute malicious code with it.

For me it remains suspicious. And I do not recommend its use!
Especially for newcomers, who might be in contact with the topic of mining for the first time and might be naive in terms of validation of a trustworthy source of data.


The process known as PhoenixMiner.exe appears to belong to software NiceHash Miner by unknown.

Description: PhoenixMiner.exe is not essential for Windows and will often cause problems. PhoenixMiner.exe is located in a subfolder of the user's profile folder - e.g. C:\User\NAME\Desktop\PhoenixMiner_4.0b_Windows\
Known file sizes on Windows 10/8/7/XP are 6509568 bytes (66% of all occurrences) or 7797248 bytes
https://www.file.net/prozess/phoenixminer.exe.html
The application has no visible window.
There is no file description.
The file is not a Windows system file.
PhoenixMiner.exe is able to monitor applications and manipulate other programs.
Therefore, we rate this file 89% dangerous, but compare this rating with member opinions.
jr. member
Activity: 45
Merit: 1
@SiNeReiNZzz did you even read the virustotal that you posted lol? Are you going to report all miners? if you posted more reports like that they all should be canceled, who validated that report?!
legendary
Activity: 3178
Merit: 3295
And here we go !
They moved all there files and stuff to github now , the only thing i think about that there files got deleted on MEGA is that somebody has reported the files ,
as the other files with Malware got reported there also .
But anyway i think its the best solution that can be for the original files , as its hard now for other Malware links to copy them !

The Thread gots edited today
IMPORTANT! MEGA terminated our account without any explanation and we are in the process of moving to other hosting solutions. Read here for more information and for the checksums with which to check the integrity of PhoenixMiner if you have downloaded it from other location.
We are moving our binaries to github.com as a first temporary solution, and we will be setting up a few more backup hosting options in case github also caves under pressure. Here is the link to our github.com account:

     https://github.com/PhoenixMinerDevTeam/PhoenixMiner/releases/

We will be removing all MEGA links from our posts in case that MEGA goes evil and starts distribute fake binaries in the future. From now on, MEGA is no longer an official place for distribution of the past and new versions of PhoenixMiner.

@SiNeReiNZzz

I also would say you should review your Feedback on the original Thread starter for PhoenixMiner as it is unwarranted as Rizzrack have already written.
legendary
Activity: 3500
Merit: 6320
Crypto Swap Exchange

Hey @SiNeReiNZzz, could you please review your neg trust on @PhoenixMiner?

Any antivirus will accuse any miner of being.. a miner..

There is an ongoing malware campaign with fake PhoenixMiner binaries that contain malware. Most advertise "PhoenixMiner 5.5d" which is not even launched, latest one is 5.5c.

There were tens of thousands of posts with this, all deleted, that direct to a mega.nz link. Different from the OP https://bitcointalksearch.org/topic/m.26969355

I would assume this is one of the reasons the real Phoenix mega.nz folder was deleted.

Personally I don't think that the OP of the Phoenix thread has something to do with this and the negative feedback does seem unwarranted

Slightly OT but I never understood why they used mega instead of github till now. Or GitLab / BitBucket / SourceForge or any of a dozen other places.
Or I don' know, since they are charging a dev fee how about just getting their own domain and hosting it themselves.

Because in the end, not having the files on a PhoenixMiner domain really does make it easier for the malware people to post a mega (or whatever) link and have some people believe it.

-Dave
copper member
Activity: 786
Merit: 710
Defend Bitcoin and its PoW: bitcoincleanup.com

Hey @SiNeReiNZzz, could you please review your neg trust on @PhoenixMiner?

Any antivirus will accuse any miner of being.. a miner..

There is an ongoing malware campaign with fake PhoenixMiner binaries that contain malware. Most advertise "PhoenixMiner 5.5d" which is not even launched, latest one is 5.5c.

There were tens of thousands of posts with this, all deleted, that direct to a mega.nz link. Different from the OP https://bitcointalksearch.org/topic/m.26969355

I would assume this is one of the reasons the real Phoenix mega.nz folder was deleted.

Personally I don't think that the OP of the Phoenix thread has something to do with this and the negative feedback does seem unwarranted
legendary
Activity: 2688
Merit: 2297
PhoenixMiner 5.2e: fastest Ethereum/Ethash miner with lowest devfee (Win/Linux)

After I stumbled across a malware infected update earlier, I checked the link with the files in the OP again.
And behold, even though the OP took a lot of merit and is from 2017, it now leads to files that are more than full of malware! (See VirusTotal-Scan)


Thread/Post: https://bitcointalksearch.org/topic/m.26969355 <---- DELETE PLEASE

Virus Total: https://www.virustotal.com/gui/file/fb439a00e77f5735725824a97d8912955f1088ac87a5876f622659201a7d8ffc/detection

Profile Link: PhoenixMiner <---- BAN PLEASE

Archive- LINK

Code:
https://mega.nz/#F!2VskDJrI!lsQsz1CdDe8x5cH3L8QaBw

PhoenixMiner.zip


Hey @SiNeReiNZzz, could you please review your neg trust on @PhoenixMiner?

Any antivirus will accuse any miner of being.. a miner..
legendary
Activity: 2212
Merit: 2061
Join the world-leading crypto sportsbook NOW!

@logfiles, thanks for sharing!

Interesting that MindlessElectron has missed both posts from CrashX as i've found one more in the Ethereum Classic's thread which i just reported.

I also tagged the account just in case it isn't banned. it's been banned already, good work!  Wink

archive: https://loyce.club/archive/posts/5649/56491861.html
Code:
Download
Windows: https://mega.nz/file/Y0gGGRxC#qaza0p8IS1oe4XdBBMUmwJBgnZC3RMOIHCQ1bZ742VE
Linux: https://mega.nz/file/JP4yQbSC#OiAa76fJFx9CywywCjXFvgTao5xbIdV3D9RwStco-ec
copper member
Activity: 2198
Merit: 1837
🌀 Cosmic Casino
<...>
Looks like we have reduced for a long time now the Scam on this cases with the Malware Links .
Thanks to the Bot from Mitchell as they get deleted realy fast and quick, and its nearly impossible to report them when they show up.
Here is another one with a similar pattern. The person first makes a normal reply onto a post and then edits it into malware links a day or hours after.

Thread: https://bitcointalksearch.org/topic/ann-ethereum-welcome-to-the-beginning-428589
Poster: CrashX <---- Please report.

PhoenixMiner 5.5d - hotfix available

Notes

-Greatly improved the work of video cards with 4 gb

-Fixed global problems for video cards from Nvidia/AMD
-Fixed errors and crashes when the miner was running
-Improved work on Win7 and 10xx series video cards
-Increased hashrate on video cards series 20xx,30xx
-Increased hashrate on Ethash by an average of 10%
-Increased hashrate on ETCHash by an average of 7%
-Improved the work of the miner in general

Code:
Windows: https://mega.nz/file/Y0gGGRxC#qaza0p8IS1oe4XdBBMUmwJBgnZC3RMOIHCQ1bZ742VE
Linux: https://mega.nz/file/JP4yQbSC#OiAa76fJFx9CywywCjXFvgTao5xbIdV3D9RwStco-ec

legendary
Activity: 2072
Merit: 4265
✿♥‿♥✿
legendary
Activity: 3178
Merit: 3295
The bot was down for a while yesterday/this morning, but should be back in full force now Smiley
Looks like its working fine and well again !
As i have seen the post and was on the way to report it and then it was gone already .
Does the bot catching up after it has restarted and runs again with older posts and such things ?
I guess it does or ist just checking the new posted ones ?
Anyway as long it works again all is good .
copper member
Activity: 3948
Merit: 2201
Verified awesomeness ✔
[...]

Thanks to the Bot from Mitchell as they get deleted realy fast and quick, and its nearly impossible to report them when they show up.
The bot was down for a while yesterday/this morning, but should be back in full force now Smiley
legendary
Activity: 3178
Merit: 3295
This post is just for the records so we got the Link and everybody can read it !
The link is a download Malware Link.

User : reme.mks 

Post : https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654  Post is already deleted

Thats what they are posting lately to catch Users to download there Shit

Quote
PhoenixMiner 5.5d - hotfix available

Notes
-Fixed global problems for video cards from Nvidia/AMD
-Fixed errors and crashes when the miner was running
-Improved work on Win7 and 10xx series video cards
-Increased hashrate on video cards series 20xx,30xx
-Increased hashrate on Ethash by an average of 15%
-Increased hashrate on ETCHash by an average of 10%
-Improved the work of the miner in general

Code:
Download
Windows: https://mega.nz/file/mdhiFZAB#cLm0_x93o4KKWRcrKJi48v9as8FOCnWuIavXENcmYiA
Linux: https://mega.nz/file/fMAwHJ6Y#asnB3mIBvZd7W5KrDqFO9Xpkybz_8MkL6IJExtf-xuY

Looks like we have reduced for a long time now the Scam on this cases with the Malware Links .
Thanks to the Bot from Mitchell as they get deleted realy fast and quick, and its nearly impossible to report them when they show up.
Pages:
Jump to: