I'd be curious to know what commonality @
Peanutswar, @
mdgabrielzim, and @
Woodie have had in their browsing history. If they all clicked on a phishing link, or if they all downloaded some software, or if they all participated in an off-site give-away that asked for forum details. It would seem they all fell into the same trap.
I thought it was some of the new crypto platforms I have interacted with in the last couple of months, but unfortunately, I have ruled them out on the basis of other two accounts not being participants of service reviews or thread discussion!
I have also looked at Peanutswar and mdgabrielzim post history to try and find common ground of where this exploit might have originated from and honestly, we are three different people.
But my wild guess would be that, we all haven't changed passwords for a very long time and possibly **just assuming** maybe someone had access of the forums database and just started to act on this..and the fact that account sales might not be lucrative anymore, our accounts couldn't be sold but instead went for the loans for easy money...
And lastly, this hacker chose his/her victims based on any history of a user getting a loan and didn't use any other account that has never applied for one as this could raise suspicion ...it's my only logical explanation.
Unusual ip I found via bitcointalk.org/myips.php based on the deleted post date and time thanks to the loyce club archives.
Singapore 84.17.39.166
The loan I did not apply for as can be seen below
The myips.php page only goes back 30 days. That means you couldn't have found this IP just now.
I got that ip using myips.php page when I discovered this compromise months back not that I checked for this yesterday its also saved incase I get a hit when i search for it!
Btw, I have been doing my own investigation to see how much damage was done on my side and everything seems intact, no social media account login attempts, bank accounts login attemps just cant find this guy.