Pages:
Author

Topic: Report Malware and Suspicious Links here so Mods can take Action ! - page 44. (Read 34697 times)

legendary
Activity: 2996
Merit: 3114
Next Fake ANN !

Thread : [ANN] DEURO [SCRYPT][POW] Digital EURO

User : ynsmrnyn  <-----  Please Ban that User

Thread is selfmoderated

Last post was from that User was done in May 24, 2019

Archive : https://archive.fo/wip/PBCao

Code:
[b]WALLETS[/b]

WINDOWS

[url=https://github.com/Deuro-official/source/releases/download/Wallet/Deuro-win10-x64.zip][b]Download[/b][/url]

Fake Github : https_://github.com/Deuro-official/source/releases/download/Wallet/Deuro-win10-x64.zip

Real Github : https_://github.com/Devkon69/Digitaleuro/releases

Original ANN

Thread : [PRE-ANN][POW][SCRYPT] Digital EURO - DEURO

User : digitalica

Code:
WALLETS

WINDOWS / LINUX / MAC

https://github.com/Devkon69/Digitaleuro/releases

copper member
Activity: 769
Merit: 702
Defend Bitcoin and its PoW: bitcoincleanup.com
Here is another proof and Information what this Software is doing and thats it Malware and a trojan !

When you install the file and run it :....

Fair enough !

After further investigation, i found out two users who have direct links to the same malware zip file in their signatures.
Screenshots:
https://i.ibb.co/StbqMXp/asgsg.jpg
https://i.ibb.co/tXvF07r/sdfvg.jpg

Accounts:
https://bitcointalksearch.org/user/brotherwood12-1079480
https://bitcointalksearch.org/user/bitcoinfriends-507542

Solved !

Seems our buddies took the red pill and got a dose of reality



Fake Qitmeer Miner : https_://github.com/Qitmer (letter "e" missing)

Original Qitmeer Miner: https_://github.com/Qitmeer/

Nice catch and work on that !

Good find ! Not the first evil miner from our friendly malware spreaders and clearly not the last. Thx guys Wink
legendary
Activity: 2996
Merit: 3114
Fake Qitmeer Miner : https_://github.com/Qitmer (letter "e" missing)

Original Qitmeer Miner: https_://github.com/Qitmeer/

Nice catch and work on that !

Archived the thread again : https://archive.fo/wip/AMcv5

Havnt checked more on it when i saw the Thread and post .
It was just a bit Suspicious to me as i looked at the Account and post history.
i wasnt quiete sure and thought we got a fake miner from Qitmeer already in the past , but have got no time to check it.
Thanks for checking it  Cool
legendary
Activity: 2212
Merit: 2061
Join the world-leading crypto sportsbook NOW!
^ I think our guys are re-allocating efforts to spam their malware in the Mining (Altcoins) board now.

I urge you all to bookmark this link and check regularly for new miners, pills etc:

https://bitcointalk.org/index.php?board=160.0;sort=first_post;desc


Lafu caught one today, i've tagged the account, report to mods will come shortly:

Virustotal Result :
https://www.virustotal.com/gui/file/816c8ce592a25f4c8b71e4812f954b625febd2a17c17110de52d2d5fcce0070b/detection

Before you started posting a few days ago the last post was on November 12, 2018 !
What happend in the rest of the time between ?

Joined on github 2 days ago and after nearly 2 years you come back with a Miner Software .

Just asking because it looks a bit strange to me .

Archived : https://archive.fo/wip/JDg3n

Fake Qitmeer Miner : https_://github.com/Qitmer (letter "e" missing)

Original Qitmeer Miner: https_://github.com/Qitmeer/

legendary
Activity: 3500
Merit: 6320
Crypto Swap Exchange
Suspicious Link with malware posted in 2 posts  !

User : Acex29

ethpillan/PillForETH

^I confirm that this is indeed malware and posts have to be deleted, user banned.
After further investigation, i found out two users who have direct links to the same malware zip file in their signatures.
Screenshots:
https://i.ibb.co/StbqMXp/asgsg.jpg
https://i.ibb.co/tXvF07r/sdfvg.jpg

Accounts:
https://bitcointalksearch.org/user/brotherwood12-1079480
https://bitcointalksearch.org/user/bitcoinfriends-507542




What is interesting is that the last 2 posts of both those accounts are withing minutes of each other.
And in the last 2 or 3 posts of both those accounts the posting style and language changed.
Guessing they were sold / compromised.

I'll tag them when I get to a PC, it's a pain on the tiny mobile screen I am on now. (while remoting into a PC)

-Dave
legendary
Activity: 2996
Merit: 3114
I confirm that this is indeed malware and posts have to be deleted, user banned.

Here is another proof and Information what this Software is doing and thats it Malware and a trojan !

When you install the file and run it :

mstsc.exe - a utility for working with remote desktops using the RDP protocol, establishes a connection with the Dutch server 46.249.62.235 to transfer stolen data;

Based on the analysis of the file's behavior, in no case should you run ETHpillAN on your computer. In addition, it is worth blocking the network addresses listed in the article that are used by hackers.

Source : https://www.cryptoprofi.info/?p=6834

Would be great if a Moderator or Global Moderator delete the posts from the Users that posted that and maybe ban that Users posted in the earlier Posts.

Edit :

Just archived the Information Webpage here : https://archive.fo/wip/5PtCU
legendary
Activity: 2212
Merit: 2061
Join the world-leading crypto sportsbook NOW!
Suspicious Link with malware posted in 2 posts  !

User : Acex29

ethpillan/PillForETH

^I confirm that this is indeed malware and posts have to be deleted, user banned.
After further investigation, i found out two users who have direct links to the same malware zip file in their signatures.
Screenshots:
https://i.ibb.co/StbqMXp/asgsg.jpg
https://i.ibb.co/tXvF07r/sdfvg.jpg

Accounts:
https://bitcointalksearch.org/user/brotherwood12-1079480
https://bitcointalksearch.org/user/bitcoinfriends-507542


legendary
Activity: 2996
Merit: 3114
Suspicious Link with malware posted in 2 posts  !

User : Acex29

In his post he says that the software change the Mining hashrate for eth and that increase it very much

Post 1 : https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654

there is another tablet for miners - https_://github.com/ethpillan/PillForETH/releases/tag/1.0.0

Archive : https://archive.fo/9ApAs#30%

Post 2: https://bitcointalksearch.org/topic/phoenixminer-62c-fastest-ethereumethash-miner-with-lowest-devfee-winlinux-2647654

The Github Account was created 2 days ago !

New pill for to increase the hashrate, most well-known miners are supported
Github: https_://github.com/ethpillan/PillForETH

Archive : https://archive.vn/S2jcZ#60%

He was catched from this User !
SecureAge APEX
Malicious
Cybereason
Malicious.cef5e8
eGambit
PE.Heur.InvalidSig
Ikarus
Trojan.BAT.Agent
K7AntiVirus
Adware ( 0051044f1 )
K7GW
Adware ( 0051044f1 )
MaxSecure
Trojan.Malware.300983.susgen

https://www.virustotal.com/gui/file/ce69344f24f438ba6d407575c23b38720a5c15c448b345ba53c30b8bcc209167/detection

Virustotal : https://www.virustotal.com/gui/file/ce69344f24f438ba6d407575c23b38720a5c15c448b345ba53c30b8bcc209167/detection

Just posted it for the records and please delete the posts  !
legendary
Activity: 2996
Merit: 3114
Hmm... so this means their vacation ended I guess. Was good while it lasted tho.
Hunting season has officially restarted!

Yeah it looks like they are back , sadly !
Was realy hoping that they have given up on that as there was a nearly 2 weeks break now without any Thread they have done.
But i have and already watching every day for them as you never know what kind of trash they posting next.
Let them come , i am always ready to kick there Ass and Accounts.
copper member
Activity: 769
Merit: 702
Defend Bitcoin and its PoW: bitcoincleanup.com
Hmm... so this means their vacation ended I guess. Was good while it lasted tho.
Hunting season has officially restarted!
legendary
Activity: 2996
Merit: 3114
And here we go again , Next Fake ANN !

Thread : [ANN] RadiumX . Algo x16s

User : Jayjayzian

This user recently woke up from a long period of inactivity.

Last post from this User was done in June 20, 2018

Possible sold or hacked Account

And the Thread is Locked so nobody can post in there and can give a warning

Archive : https://archive.fo/wip/VdKmE

Code:
Wallets
Windows(beta): https://github.com/radium-x-core/radium/releases/download/v.1.0.2.0/radium-x.v.1.0.2.0.zip

Fake Github : https_://github.com/radium-x-core/radium/

Same Fake github as in the other posted RadiumX Fake ANNs in the past.
legendary
Activity: 2212
Merit: 2061
Join the world-leading crypto sportsbook NOW!
legendary
Activity: 1722
Merit: 5937
Looks like the Fake ANNs Crew and Gang lost intrest or is on holiday as we got no new Anns the last 9 days!
Or hopefully they have given up on that we dont will see them again ( Fingers Crossed ) .
Same thing crossed my mind few days ago. I guess they went on summer holiday or simply got bored of it for now and thinking about new approach.

To be honest, I doubt that they completely gave up from that scheme as those type of scammers don't give up easily, they usually keep coming back as they obviously don't have anything better to do.

I hope we didn't jinx it now and they show up soon.
legendary
Activity: 2996
Merit: 3114
Looks like the Fake ANNs Crew and Gang lost intrest or is on holiday as we got no new Anns the last 9 days!
Or hopefully they have given up on that we dont will see them again ( Fingers Crossed ) .

So for now i just wanted to say a Big Thank You to ALL that have and looking for this kind of Threads and post and reported them.
You have all done and doing an great job to keep the forum clean and safe some Users money and there Accounts.

Thank you
legendary
Activity: 2996
Merit: 3114
There was Fake ANN and a phishing link thread with Fake Github !

Thread : [ANN] GxMiner v0.2.2 - CLI miner for RandomX series algo (Windows/Linux)

He has changed the Titel already with Del now after he got catched

User : CommandRX  <----- Please Ban that User

I just have changed thread archived here : https://archive.fo/ct2tB

But i have the Quoted whole ANN here with the Malware or Phishing links , they are not clickable :

About miner

GxMiner is a highly optimized miner for random-x series algorithm.
GxMiner acts as an application of library go-randomx which based on C and golang. In this framework, we can mine all cryptocurrencies with random-x series algorithm.
This repo is currently not fully open-sourcing, but its core part, the project go-randomx is open-sourcing.

As everyone know, xmrig & xmr-stak is the leader of monero miners. But soon monero is not cryptonight algorithm cryptocurrency any longer, it would be the centry of random-x
Comparing to the leaders, GxMiner is younger and modern, without any historical burden. And GxMiner is not slower even sometimes slightly faster than the xmrig.
And if you are a developer, it would be much easier to intergrate your random-x fork into miner.

Features
-Support Windows/Linux system
-Dev fee 0%
-Open source code
-Self-integration capability RandomX fork in miner
-Stable high hashrate on par with Xmrig, on some algo even higher

Download
Windows/Linux
RandomX: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-x.zip
RandomXL: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-xl.zip
RandomARQ: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-arq.zip
RandomSFX: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-sfx.zip
RandomWOW: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-wow.zip
RandomYADA: https_://github.com/COMM4ND/GxMiner/releases/download/v0.2.2/random-yada.zip


Source: https_://github.com/COMM4ND/GxMiner

Fake Github : https_://github.com/COMM4ND/GxMiner/releases/

Real Github : https_://github.com/C0MM4ND/GxMiner/releases/

They changed the 0 to an O

Credits goes to the Users : sxemini and alucard20724

PHISHING SOFTWARE

actually it is phishing... the original site is:
https://github.com/C0MM4ND/GxMiner/releases
this scammer changed the 0 in C0MM4ND to an O... he changed it from a zero to the letter O.   his original post had links to the page from last year, and now he's changed the link...
legendary
Activity: 1722
Merit: 5937
Another fake  Rtidcoin ANN with malware, with all the classic signs that are pretty much standard now:
  • recently awoken account
  • self moderated thread
  • fake github account sith same name as already existing project.


Please delete the ANN and nuke that user before someone downloads it.

User Shavlidz
ANN ✅[ANN][RTID] Rtidcoin 🔥 EXCHANGE&POOL AVAILABLE!✅
github https://github.com/rtidcoin-core
Archive https://archive.fo/IvnZq

Code:
https://github.com/rtidcoin-core/elicoin/releases/download/RtidWallet.v.1.0.2/RtidWallet.zip

Original Github : https_://github.com/Rtid-Platform/



One more fake ANN with malware, this time they are copying Pyrk, another popular choice.

User sakhaowat017
ANN ✅[ANN][PYRK][POW-MULTI]👾[SHA][SCRYPT][X11]⚡️[MASTERNODES][EXCHANGE]🔥
Archive https://archive.fo/6piP5

Code:
https://github.com/pyrkcommunitycore/pyrk/releases/download/PyrkWallet.v.1.0/PyrkWallet.zip

Original ANN  [ANN][PYRK][POW-MULTI][SHA][SCRYPT][X11][MASTERNODES][COMMUNITYFUND][EXCHANGE]
Original Github: https://github.com/pyrkcommunity



Another fake ANN

User skayvoker11
ANN 🔵 [ANN][XFS] 🔵 PoW X16RV2 + PoS + XFSNODE
Github  https://github.com/ProjectcFTS
Archive https://archive.fo/I2XD5

Code:
  https://github.com/ProjectcFTS/FTS_COIN/releases/download/FTSCoin.v2.0.2/xfs-qt-win64.zip


Original ANN 🔵 [ANN][XFS] 🔵 PoW X16RV2 + PoS + XFSNODE
Original github https://github.com/ProjectFTS
legendary
Activity: 2996
Merit: 3114
Next Fake ANN !  

Thread : 🔥 [ANN] SorachanCoin SORA – Hybrid PoW / PoS CryptoCurrency

User : Jblastmp  <-----  Please Ban that User

Selfmoderated thread

Possible hacked Account , maybe

Archive : https://archive.fo/wip/aolQw

Code:
[size=14pt][b]Wallet: [/b][/size]
https://github.com/SorachanCoin/SorachanCoin-qt/releases/download/1.1.6/SorachanCoin-qt_1.1.6.zip

Fake Github : https_://github.com/SorachanCoin/SorachanCoin-qt/releases/

Real Github : https_://github.com/FromHDDtoSSD/SorachanCoin-qt/releases/

Original ANN

Thread : [ANN] SorachanCoin SORA – Hybrid PoW / PoS CryptoCurrency

User : sora_meetino

Code:
[b]Github:[/b]
https://github.com/FromHDDtoSSD/SorachanCoin-qt/releases/download/1.1.6/SorachanCoin-qt_1.1.6.zip




Next one !

Thread :  ✅[ANN][PYRK][POW-MULTI]👾[SHA][SCRYPT][X11]⚡️[MASTERNODES][EXCHANGE]🔥

User : kasowinwin  <----  Please ban that user

Last post from that user was in December 28, 2018

Archive : https://archive.fo/wip/AYHjq
Code:
[size=16pt][b]Wallet:[/b][/size]
[b]Windows:[/b]  https://github.com/pyrkcommunitycore/pyrk/releases/download/Wallet.v.1.0.3/PyrkWallet.zip

Fake Github : https_://github.com/pyrkcommunitycore/

Real Github : https_://github.com/pyrkcommunity

Original ANN

Thread : [ANN][PYRK][POW-MULTI][SHA][SCRYPT][X11][MASTERNODES][COMMUNITYFUND][EXCHANGE]

User : Mike-O

Code:
Github: [url=https://github.com/pyrkcommunity]https://github.com/pyrkcommunity[/url]




Next one with pyrk!

Thread :  ✅[ANN][PYRK][POW-MULTI]👾[SHA][SCRYPT][X11]⚡️[MASTERNODES][EXCHANGE]🔥

User : JasonLeavers  <----  Please ban that user

Last post from that user was in September 09, 2018

Archive : https://archive.fo/wip/dlyW6
Code:
[size=16pt][b]Wallet:[/b][/size]
Windows: https://github.com/pyrkcommunitycore/pyrk/releases/download/PyrkWallet.1.0.0/PyrkWallet.zip

Fake Github : https_://github.com/pyrkcommunitycore/

Real Github : https_://github.com/pyrkcommunity

Original ANN

Thread : [ANN][PYRK][POW-MULTI][SHA][SCRYPT][X11][MASTERNODES][COMMUNITYFUND][EXCHANGE]

User : Mike-O

Code:
Github: [url=https://github.com/pyrkcommunity]https://github.com/pyrkcommunity[/url]




Next Fake ANN !

Thread : ✅[ANN][RTID] Rtidcoin 🔥 EXCHANGE&POOL AVAILABLE!✅

User : Lolprok  <-----  Please Ban that User

Last post from that User was done in August 20, 2019

Archive : https://archive.fo/wip/4KJbx

Code:
[b]Windows:[/b]  https://github.com/rtidcoin-core/elicoin/releases/download/RtidWallet.v.1.0.1/RtidWallet.zip

Fake Github : https_://github.com/rtidcoin-core/elicoin/

Real Github : https_://github.com/Rtid-Platform/

You can find the real github on there Webpage

Webpage : https://rtid-platform.web.id/coin.html
legendary
Activity: 2996
Merit: 3114
Next Fake ANN !

Thread : ✅[ANN][PYRK][POW-MULTI]👾[SHA][SCRYPT][X11]⚡️[MASTERNODES][EXCHANGE]🔥

User : gordienkos815   <-----  Please Ban that User

Possible hacked or sold Account !

Archive : https://archive.fo/wip/Vii4Y

Code:
[size=16pt][b]Wallet:[/b][/size]
[b]Windows:[/b] https://github.com/pyrkcommunitycore/pyrk/releases/download/Wallet.v.1.0.2/PyrkWallet.zip

Fake Github : https_://github.com/pyrkcommunitycore/pyrk/releases/

Real Github : https_://github.com/pyrkcommunity

Original ANN

Thread : [ANN][PYRK][POW-MULTI][SHA][SCRYPT][X11][MASTERNODES][COMMUNITYFUND][EXCHANGE]

User : Mike-O

Code:
Github: [url=https://github.com/pyrkcommunity]https://github.com/pyrkcommunity[/url]
legendary
Activity: 1722
Merit: 5937
Reported Thread is marked as Good  but not deleted
So it looks like it is the same type of fake ANN like I reported a bit earlier, same githubt used, just another bitcointalk account. I just reported that ANN as well, let's hope it gets deleted this time.



One more fake ANN,same one like in previous attempts earlier today, but  this time in Korean local board. I guess they think they will have more success if they shared in local boards, that it will take more time for that ANN to get deleted.

User jjude80
ANN 🔥 [SCAM] [ALERT] ↓↓↓ ScamCoins이 주제에 대해 ↓↓↓ [LOOK] [AT] [ME] 🔥
Archive https://archive.fo/6Ob8v

Code:
https://github.com/QTminingAssist/-QTminingAssist/releases/download/QTminingAssist/QTminingAssist.zip
legendary
Activity: 2996
Merit: 3114
Suspicious ANN and Thread !

Thread : 🔥[SCAM][ALERT] ↓↓↓ScamCoins are under this topic↓↓↓ [LOOK][AT][ME]🔥

User : log0530 <------   Please Ban that User

Possible hacked Account

Joined 3 hours ago on Github !

Code:
I created wallet analyze program.
https://github.com/QTminingAssist/-QTminingAssist/releases/download/QTminingAssist/QTminingAssist.zip

Fake Github : https_://github.com/QTminingAssist/-QTminingAssist/releases/

Archive : https://archive.fo/wip/9TGRX

I tried to download this file but my browser stoped it and alerts me instant for Malware and Virus !



My warning i have written in this thread got already deleted from the User !

Edited

Reported Thread is marked as Good  but not deleted

Deleted now
Pages:
Jump to: