Pages:
Author

Topic: Report Malware and Suspicious Links here so Mods can take Action ! - page 78. (Read 36997 times)

legendary
Activity: 2534
Merit: 6080
Self-proclaimed Genius
Bkav
W64.HfsAutoB.
Endgame
malicious (high confidence)
Invincea
heuristic
Malwarebytes
RiskWare.BitCoinMiner
Microsoft
PUA:Win64/CoinMiner
Rising
PUF.CoinMiner!8.4639 (TFE:5:HVCYVtd0IyI)
Hahah.
Those detected "Coinminer" are the usual false-positives you can get by scanning any/all Mining app using a virustotal.
Most known AVs won't even tag it as positive (check the name of the AV's with positives in your image).

If you're accustomed to mining, you will know if there's really a red flag (through actual usage/different scan results)
But doktor83's miner wasn't one of those.
It's the indirect descendant of this old thread: SRBMiner Cryptonight AMD GPU Miner V1.9.3 - native algo switching

For the second image:
That's mega.nz (url) that you've scanned.
hero member
Activity: 2548
Merit: 626
user : https://bitcointalksearch.org/user/doktor83-889929

Ann : SRBMiner-MULTI CPU & AMD GPU Miner 0.1.0 beta

Archived : http://archive.is/w1Pbq

Link Github >> Downloaded and scaning SRBminer file have : https://www.virustotal.com/gui/file/fb9378b3eaca05b3fc6bebb58ad318996600252949a41036aa4028bb697c74f8/detection
Bkav
W64.HfsAutoB.
Endgame
malicious (high confidence)
Invincea
heuristic
Malwarebytes
RiskWare.BitCoinMiner
Microsoft
PUA:Win64/CoinMiner
Rising
PUF.CoinMiner!8.4639 (TFE:5:HVCYVtd0IyI)




Link Mega : https://www.virustotal.com/gui/url/71216ea7e98991af2c7f6226d581d2ba513e14cc585f8e8d0f6cf04bf112f755/detection






What the hell man , so my topic got removed because YOU reported it as malware? What the hell moderators, is this serious ?
The binary is PACKED, every AV will report it as dangerous.
I am a miner developer for some time, already got another miner topic on this forum for a long time. Do you think i would post files that contain malware/viruses?
legendary
Activity: 2366
Merit: 2054
user : https://bitcointalksearch.org/user/doktor83-889929

Ann : SRBMiner-MULTI CPU & AMD GPU Miner 0.1.0 beta

Archived : http://archive.is/w1Pbq

Link Github >> Downloaded and scaning SRBminer file have : https://www.virustotal.com/gui/file/fb9378b3eaca05b3fc6bebb58ad318996600252949a41036aa4028bb697c74f8/detection
Bkav
W64.HfsAutoB.
Endgame
malicious (high confidence)
Invincea
heuristic
Malwarebytes
RiskWare.BitCoinMiner
Microsoft
PUA:Win64/CoinMiner
Rising
PUF.CoinMiner!8.4639 (TFE:5:HVCYVtd0IyI)




Link Mega : https://www.virustotal.com/gui/url/71216ea7e98991af2c7f6226d581d2ba513e14cc585f8e8d0f6cf04bf112f755/detection




legendary
Activity: 2324
Merit: 1604
hmph..


If you are need to track how your content engagment, you just need to create utm referral. I don't know what a link behind of your Linktree, because I don't want to take any risk. If, your link behind linktree is for your sites, why you are not just using bit.ly?

May be this tools can help you to track. https://ga-dev-tools.appspot.com/campaign-url-builder/ and edit your post, i will edit my reports. PM me if you are done

//Don't reply, just PM me//
copper member
Activity: 41
Merit: 1
[ANN][DCA] Decracy - A Global Revolution > Global ID, Privacy, Smart Contracts

Thread archives: https://archive.is/jdUWX
Thread creator: Decracy

Case: Creator using shortlink to their website, first he was using bit.ly when I check link behind, it will redirect to linktree. Screenshot https://i.ibb.co/Z2yNVZc/image.png when I scan that domain contain malicious program. Scan results can be found here https://www.virustotal.com/gui/url/2bb4560b0eb19702e6fb2270ebaf76322707e39f3f3b26dae2ffffeeafa58696/detection



Hello BitcoinTalk & Member Masulum.

We have had the opportunity of being notified of this post by a member. Though this post seems to not have been brought to our attention directly.

First, we would like to thank those who are contributing to ensure that the engagement on BitcoinTalk and the content being shared are safe and protected. Creating a safe environment that can be appreciated by the members here on BitcoinTalk.

In addressing a) the virus scan; we would like to express the common knowledge that when scanning a webpage that gathers reports of over '70' different virus defense provides that the result of there being a false-positives is one that is possible - at times even likely.

To be clear, the 'malicious' 1 flag, out of 70 green checks, was given to the service of LinkTree, not of any services owned by Decracy.

Though for the sake of also sharing that we do give detailed attention on all third-party services that we utilize, in verifying that they are of caliber, and of safe convenience for our members, I share with you public articles that show the likes of Expedia, Wix, Red Bull, and countless globally-acclaimed public figures who currently, and safely, utilize the service of 'LinkTree'. LinkTree Article.

A false-positive report was drafted and sent to 'CRDF Labs', by our team, which is the provider that flagged the service of 'LinkTree'. To place in perspective, we would like to state that the most trusted virus defense providers such as Google, Avira, Kaspersky, BitDefender, ESET, Tencent, Opera, + all marked, passed, and verified the same service provider to be safe.

In hindsight, these are things that we fully believe should be considered when reporting links to be 'unsafe', which can sway others to think negatively of certain content or the poster of such content.


Addressing b) the use of 'Bit.ly'; with our operations being on par with the operations of world corporations and entities, our goal, and the goal of our marketing team, is to uphold the most informed environment where we are in the position of better understanding our content, it's delivery, and its acceptance, within the environments that we share such content in. In this case, the same design was being utilized when we incorporated the use of Bit.ly links. It allows for a Grade A environment to be hosted where Decracy may better understand the click-through ratio, and how we may better improve Decracy's content so that it may better align with the interest of the users, in this case, BitcoinTalk users.


We hope that we have well clarified the points above.


Decracy

legendary
Activity: 2324
Merit: 1604
hmph..
[ANN][DCA] Decracy - A Global Revolution > Global ID, Privacy, Smart Contracts

Thread archives: https://archive.is/jdUWX
Thread creator: Decracy

Case: Creator using shortlink to their website, first he was using bit.ly when I check link behind, it will redirect to linktree. Screenshot https://i.ibb.co/Z2yNVZc/image.png when I scan that domain contain malicious program. Scan results can be found here https://www.virustotal.com/gui/url/2bb4560b0eb19702e6fb2270ebaf76322707e39f3f3b26dae2ffffeeafa58696/detection

Updates: User Decracy removed malicious sites already. Trying to check his official website, decracy.com, this sites is clean from virus based on virustotal.com results

Thank you.
legendary
Activity: 3136
Merit: 3213


Nice catch and finding , i already have reported this thread and looking now to the other threads he has created too !
Hope that more reporting it and the virustotal result shows that something is not right with the file .
Or have you checked already his other thread and files ? So i dont have to doing that.
legendary
Activity: 3136
Merit: 3213
Fake ANN again !

[ANN] SPECTRECOIN | Anonymous | Stealth-Staking | Tor | Ring Signatures

User : cbread  <----  Please nuke that User !


Code:
[b]Wallet Downloads[/b][/u][/size][/color]
 The development fund aims to support the long term development and value of Spectrecoin. .[/b][/i]
[url=https://www1.zippyshare.com/d/ktmuBCNS/6739/Spectrecoin.rar][size=10pt]Download[/size][/url]

Fake Download source : https_://www1.zippyshare.com/d/ktmuBCNS/6739/Spectrecoin.rar


Real Download Source : https_://github.com/spectrecoin/spectre/releases

Original ANN and thread :

[ANN] SPECTRECOIN | Anonymous | Stealth-Staking | Tor | Ring Signatures


User : XSPEC-team

Code:
[b]Wallet Downloads[/b][/u][/size][/color]
The development fund aims to support the long term development and value of Spectrecoin.[/b][/i]
[size=14pt]https://github.com/spectrecoin/spectre/releases[/size]
ONLY download wallets from the official Spectrecoin GitHub repo!!!
legendary
Activity: 2324
Merit: 1604
hmph..
[ANN]⚡️[ICO]SEKOPAY EXCHANGE  SEKOPAY POS & MASTERNODES  SEKOPAY APP⚡️[ANN]


FAKE ANN
Thrad: https://bitcointalksearch.org/topic/annicosekopay-exchange-sekopay-pos-masternodes-sekopay-appann-5184137
Creator: https://bitcointalksearch.org/user/pochy123-995704

Wallet scan result:
Zipezip: https://zipezip.com/ufiles/06ee2863318032cae1bbc1e291218f3f

Virusdesk:

Code:
[u]File name: seko-qt.exe[/u]
Scan result : threats detected
Threat name: Trojan-Spy.MSIL.Quasar.iaa
File size: 1.38 MB
File type: PE32/EXE
Scan date: Oct 02 2019 19:39:12
Databases release date: Oct 02 2019 12:31:37 UTC
MD5: 046725a7ae791f4e2129d3fd13c449fc
SHA1: d36e500677524b22f5e3b44f55dc87337910ff1c
SHA256: bd8541c72e2bee43ada2bde6abb9729d0f992b6b43b61d8f58542ce97c741721

[u]FILE NAME: seko-qt.rar[/u]
Scan result: threats detected
Threat name: Trojan-Spy.MSIL.Quasar.iaa
File size 948.08 KB
File type ARC/RAR
Scan date: Oct 02 2019 19:39:12
Databases release date: Oct 02 2019 12:31:37 UTC
MD5: 010d9c752aeaab33d2284e396a6f1c27
SHA1: 9e2ae88355e9289c763bb298d6bd1eaef3e2b42d
SHA256: 720e25d7fc1beebf8941fcf4986adc6f1e7f19361b55b6f1d46e97213cd73f5e

https://github.com/SekoPay/sekopaycoin/releases/download/v2.3.0/SekoPay-v2.3.0-WIN.zip

Screenshot: https://i.imgsafe.org/49/49b089b4ed.png
----------------------------------------------------------------------------------------------------------------
Original ANN based on Coingecko

Thread: https://bitcointalksearch.org/topic/ann-sekopaycoin-seko-masternodes-pos-mno-5046889 (No content)
Official github: https://github.com/sekopaycoin (official github username: sekopaycoin / fake github username: SekoPay)

This is the second FAKE ANN thread I found was created by pochy123.
hero member
Activity: 1764
Merit: 570
Twitter\X @AlexKosa1
i think we have new one...
https://bitcointalk.org/index.php?topic=5189336.new#new
dll file with wallet contain virus
legendary
Activity: 3136
Merit: 3213
I happened to notice that their links are getting auto-removed/flagged suspicious as of late.

They usually go for Github and Bitbucket with direct links to their fake/malicious wallets (.rar, .zip, .gz, .xz, .tar)

Were any of these files added recently to the forum anti-spam/malware detection software? Or is it something else?

I have seen that yesterday also and dont know if the links got removed from the detection software from the forum,
or that they was removed from an Moderator or Global Moderator , but i guess it was the forum software.
Maybe theymos can answer the question or an Global Moderator if they added bitbucket now to the blacklist.
If so we have done an step forward for the malware Links.
legendary
Activity: 2212
Merit: 2061
Join the world-leading crypto sportsbook NOW!
I happened to notice that their links are getting auto-removed/flagged suspicious as of late.

They usually go for Github and Bitbucket with direct links to their fake/malicious wallets (.rar, .zip, .gz, .xz, .tar)

Were any of these files added recently to the forum anti-spam/malware detection software?[1] Or is it something else?

[1] - obviously not
legendary
Activity: 3136
Merit: 3213
Fake ANN again !

[ANN] SPEROCOIN - POS/POW

User :  TheCryptoCoinsist   <-----   Please nuke that user


Code:
[url=http://https[Suspicious link removed]]QT Windows[/url]
[url=http://https[Suspicious link removed]]Daemon Windows[/url]
[url=https://github.com/DigitalCoin1/SperoCoin_Android/releases/download/SperoCoin-v.2.6.4.6-BETA/SperoCoin-v.2.6.4.6-BETA.apk]Android ARMv-7 Full Node[/url]
[url=https://sperocoin.org/files/SperoCoin-Version-LITE.apk]Android Lite[/url][/size]

The Link is or was removed from system !

Original ANN :

[ANN] SPEROCOIN - POS/POW

User : DigitalCoinBRL

Code:
[url=https://github.com/DigitalCoin1/SperoCoin/releases/download/SperoCoin-v.2.6.4.6/SperoCoin-v.2.6.4.6.exe]QT Windows[/url]
[url=https://github.com/DigitalCoin1/SperoCoin/releases/download/SperoCoin-v.2.6.4.6/SperoCoind-v.2.6.4.6.exe]Daemon Windows[/url]
[url=https://github.com/DigitalCoin1/SperoCoin_Android/releases/download/SperoCoin-v.2.6.4.6-BETA/SperoCoin-v.2.6.4.6-BETA.apk]Android ARMv-7 Full Node[/url]
[url=https://sperocoin.org/files/SperoCoin-Version-LITE.apk]Android Lite[/url][/size]

legendary
Activity: 2324
Merit: 1604
hmph..
[ANN] 🔥🔥 BELIEVE (poS+Mn) MOBILE CERTIFICATOR APP ⚡⚡ quoted on exchange

Fake Ann Thread:
https://bitcointalk.org/index.php?topic=5188943.0;topicseen (reported)

Topic starter profile: https://bitcointalksearch.org/user/pochy123-995704 [pochy123]
Thread archives: https://archive.is/jxu96

Quote
Code:
Github: https://github.com/believecorer/believe
Wallet: https://github.com/believecorer/believe/releases/tag/1.0.0.1



Original ANN
https://bitcointalksearch.org/topic/ann-believe-posmn-mobile-certificator-app-quoted-on-exchange-5165669

Topic starter: https://bitcointalksearch.org/user/etherixdevs-2024018 [etherixdevs]

Coingecko: https://www.coingecko.com/en/coins/believe

Quote
Code:
Gihub:https://github.com/believecore/believe




Added: BitcoinCash Classic

SUSPICIOUS WALLET

Thread: https://bitcointalk.org/index.php?topic=5188182.0;topicseen
Topic starter: https://bitcointalksearch.org/user/bitcoincash-classic-bcc-2632284 [BitcoinCash Classic (BCC)]

Kaspersky scan results: https://i.postimg.cc/QM9wKk8j/image.png / not-A-viruses explanation https://www.kaspersky.com/blog/not-a-virus/18015/
Zipezap scan reults: https://zipezip.com/ufiles/c2ac4bc2aeb7302a5713f6df179202e3
Virus total scan results: https://www.virustotal.com/gui/file/ccb4e5d4968d5e1eec60dfc8ef5905196b8725be83463e03d91c9d9d8de630f8/detection


legendary
Activity: 3136
Merit: 3213
Next Fake ANN !

[ANN][LCC] Litecoin Cash | SHA256 LTC fork @ block 1371111 | 10:1 claim ratio

From the User : Naoisee  <-------    Please nuke that User

Code:
[center][size=6][color=green][font=Verdana]Wallet Download[/font][/color][/size][/center]

[size=10pt][size=10pt][b][url=http://https[Suspicious link removed]]Download[/url][/b][/size][/size]

[size=6]Exchanges[/size]

The download link was already removed from the system !


Here is the Original ANN :

[ANN][LCC] Litecoin Cash | SHA256 LTC fork @ block 1371111 | 10:1 claim ratio

From the User : LitecoinCashOfficial


Code:
[url=https://github.com/litecoincash-project/]Github[/url][/center]

[center][size=6]Wallet Download[/size][/center]

[b][url=https://litecoinca.sh/#download]Download on our website[/url][/b]


Next Fake ANN here !

[ANN] KazuSilver [PoS] - A Decentralized Way of life

User : st0risk1n  <-------    Please nuke that User


Code:
[size=16pt][b]KAZUSILVER WALLET[/b][/size]

[url=https://bitbucket.org/miningmentor/kazusilver/downloads/KazuSilver-Qt.dmg]MAC[/url] & [url=https://bitbucket.org/miningmentor/kazusilver/downloads/kazusilver-qt.rar]WINDOWS Wallet[/url]


The Original ANN is here

https://bitcointalksearch.org/topic/ann-kazusilver-pos-a-decentralized-way-of-life-5115573
legendary
Activity: 3136
Merit: 3213
WOW, thank you so very much. It was a shock to me to see the fake ANN. I even reached out to the guy and made comments on my ann to try and get a responce to prove I am honest and hard working and only care to try and do some good. Thank you for all that you do !!


No problem and you dont have to be worry , your ANN is the original and it was all going about the Fake ANN .
You are not the only one that they doing Fake ANNs , a lot of other ANNs get faked by this too and we try to catch them at the beginning when they created so that no Users fall into the Trap
they are doing with there Malware software that they have in there Links !
jr. member
Activity: 131
Merit: 1
WOW, thank you so very much. It was a shock to me to see the fake ANN. I even reached out to the guy and made comments on my ann to try and get a responce to prove I am honest and hard working and only care to try and do some good. Thank you for all that you do !!
legendary
Activity: 3136
Merit: 3213
Another Fake Anns !

[MAINNET]"MimbleWimble", we cast this spell so mote it be. GRIMM was born.

User : gard508  <----   Please nuke that User


Code:
hr]
                                 [size=17pt][b][url=http://https[Suspicious link removed]]Releases Grimm Wallet Mainnet 10.1.5466 on github[/url][/b][/size]

                            ]
                              [size=17pt][b][url=http://https[Suspicious link removed]]Download from website WIN Grimm Wallet Mainnet 10.1.5466[/url][/b][/size]
[hr]
                              


Original ANN:

https://bitcointalksearch.org/topic/mainnetmimblewimble-we-cast-this-spell-so-mote-it-be-grimm-was-born-5172476



Next Fake ANN

[ANN][MTNS] OmotenashiCoin | PoW/Masternode | no ICO

User : kat35  <------  Please Nuke that user

Code:
[hr]
                                                                                                        [b][url=https://bitbucket.org/cryptoperfeckt/masters/downloads/omotenashicoin-1.7.0-win64.zip]Windows x64[/url]  ( Versioin 1.7.0 )[/b]
                                                                                                           [b][url=https://github.com/omotenashicoin-project/OmotenashiCoin-binaries/raw/master/v1.7.0/omotenashicoin-1.7.0-x86_64-linux-gnu.tar.gz]Linux x64[/url] ( Versioin 1.7.0 )[/b]



Next Fake ANN

https://bitcointalksearch.org/topic/ann-pos-coin-800-the-one-and-only-proof-of-stake-coin-with-wicked-daily-5188204

User : faisal sumroo   <----  Please Nuke that User

Code:
[b]Wallet[/b]

                                                                                                       [url=https://bitbucket.org/cryptoperfeckt/masters/downloads/pos-qt-windows.zip]Windows wallet[/url]

                                                                                                           [url=https://mega.nz/#!zUoCHQaL!uUSJGPumbBvd6RALoClojkpogmfICFYeejYOsgutDh0]MAC wallet[/
legendary
Activity: 3136
Merit: 3213
Thanks for posting and finding this fake ann, i have updated my first Post with the fake github link and tagged and reported the thread, please report them too so he get nuked and the thread gets deleted! Thank you.
Pages:
Jump to: