I was checking the same thing with AgatioX via PM. Let me quote his PM
Yes. After the hackers hacked me, I sent the remaining tokens to my best friend
TBH I find it hard to believe that you will send tokens worth more than $500 to friend while you can create a new wallet from other device you own.
And BTW, was he hacked as well at some point? and he trusted you to hold his coins?
and this where you both sent tokens to the same address: https://etherscan.io/address/0x4056e027207b9be48904b20956d307968b37aec1#tokentxns
and on top of that: I believe this comment is made by you on both the addresses which you think are hacker's address
Write me PM
(Source: https://etherscan.io/address/0x894cc8fc2c1d4837516ef981309b2fed3a7ddd96#comments )
(and same comment posted for 0x10b6ba730c590d48f9e736896589d783da25b545 as well : https://etherscan.io/address/0x10b6ba730c590d48f9e736896589d783da25b545#comments)
and @heisenberg88_q is a telegram ID used by polonez (negged by Vod for merit begging) as well
Btt name: polonez
Btt link: https://bitcointalksearch.org/user/polonez-1092091
My video link: https://youtu.be/ANAISkJb3vU
My Telegram: @heisenberg88_q
ETH address: 0xcB302E835f7063e3724547A47470dc859cbB0B0e
(Archive: http://archive.is/PI82p#selection-5529.13-5529.28)
So thats that which connects you to polonez. Better admit than lying.
Regarding the hacking case, you won't find anything from 0x10b6ba730c590d48f9e736896589d783da25b545 as its a newly created address to transfer the tokens from the address hacked.
Here is the pattern : He obtains address private key(somehow)> Sends some ETH from 0x894cc8fc2c1d4837516ef981309b2fed3a7ddd96 for gas to transfer tokens from the hacked address> And sends to newly generated address .
For example:
He sends some ETH from 0x894cc8fc2c1d4837516ef981309b2fed3a7ddd96 to the address he hacked: 0xd48544dc6014c336b22e5e16030478565d75d62e
and then moves out tokens from that address with three transfers:
[1] https://etherscan.io/tx/0x04250635c64d4a69b1531dd69b0118bb75017b2f1e517bdc8e6fc05250f0ee08
[2] https://etherscan.io/tx/0x8eaaf68a7374d3dc22688e911fb5d8b9d1668c098e0abdfdc5affc17ad948b90
[3] https://etherscan.io/tx/0x2ca3463f6fc35e7145d44acfe9e2fdb9c0ebc0d9018a4ceaf83fea7d7472b70b
Seems to me like he obtains it through keylogger as marlboroza said or maybe through a phising site.
You can contact others who were hacked in the same way for background process running and check if there is a common suspicious process that has been running . There is a possibility you might find the source assuming that they haven't made a fresh installation of OS again.
Otherwise we can find a hit but right now it leads to nothing since only thing that turns out that the address from which he sends ETH is the address he uses for mining at NanoPool and rest of addresses to which he sends are newly generated tokens in which case we can find something if he moves the tokens.