Pages:
Author

Topic: Warning! BTC-e Voucher Email phishing alert! (Read 3464 times)

legendary
Activity: 1736
Merit: 1023
Then that password that they sent us is the key to run whats inside the file?

Yeah, it unencrypts the docx file which would allow it to run whatever malicious code is inside. Don't enter the password in or mess with the file. Just delete it is the safest course of action.
full member
Activity: 434
Merit: 105
Then that password that they sent us is the key to run whats inside the file?
legendary
Activity: 1736
Merit: 1023
So if i dont decrypt the file and just delete it, im safe?

Yeah, you should be. The file shouldn't be able to execute in its encrypted state afaik and I'm guessing the attacker encrypts it to avoid virus signature detection.
sr. member
Activity: 462
Merit: 251
I looked at the file ... it is an encrypted .doc

I have not tried opening it, but this approach is not typical for phishing, but for malware infections.

Some macro in the .doc would run (sometimes user is tricked to enable macros, sometimes an exploit is used to run macros without further user's intervention) and then the computer would get infected by some malware. Could be some ransomware, botnet, scareware, password stealer, banker, adware, but surely it will be something evil.

I am not going to examine it further to find which one it is.
full member
Activity: 434
Merit: 105
So if i dont decrypt the file and just delete it, im safe?
hero member
Activity: 1088
Merit: 531
Free Crypto in Stake.com Telegram t.me/StakeCasino
I scanned my pc with mb and mb anti-rootkit, in and out of safe mode and nothing has been found.

Here, content of the file:




You scanned them with the file still being encrypted? Then of course nothing can be detected as a virus or harmful script. DON'T DECRYPT THE FILE ! Unless you have a save environment to do it (Virtual machine and sandbox!).
full member
Activity: 434
Merit: 105
I scanned my pc with mb and mb anti-rootkit, in and out of safe mode and nothing has been found.

Here, content of the file:


newbie
Activity: 12
Merit: 0
I also received the same phishing email, even though I haven't posted here in years. 
legendary
Activity: 1484
Merit: 1026
In Cryptocoins I Trust
I don’t think even 1 person falls for this but if they do, pray for their soul man.

I guess there are a few people stupid enough to make this worth their time, otherwise they wouldn't do it. It is simply a numbers game. Send the email to a million+ BTC-e users and you are bound to find someone stupid enough.

Older people that are computer illiterate may be more likely to open the file. Which reminds me... I need to inform my mom about this. She has some funds on BTC-e. I've tried for years to get her to move her BTC and LTC to cold wallets, but she doesn't seem too worried... I think older people have too much trust in the goodness of people's intentions.
full member
Activity: 141
Merit: 100
???
same, just checked email....  what are we noobs?

Hi makngeerwork.

See attached your BTC-e vouchers.

You need to activate them within 8 hours.

The Access key is w8pKFy9KTM. You need to paste it to be able to view the document.

Thanks
William Anthony
legendary
Activity: 3304
Merit: 1128
Oh wow I feel so left out about this Cheesy I didn’t get any mails and apparently many people did, why didn’t they sent one to me too Cheesy

All kidding aside, I always thought if these worked, the “write your address here, send us the transaction fee and we will double your money” type of scams and this phishing ones look so weird to me, do they even ever work ? Who falls for these ?

I don’t think even 1 person falls for this but if they do, pray for their soul man.
hero member
Activity: 728
Merit: 500
I got this too. See: Hacked in 2014
PS Why is this posted under Altcoin Discussion? Shouldn't it be under Currency Exchange?
hero member
Activity: 633
Merit: 500
B Money Prepaid Mastercard bmoney.io
Just received the same.
My username in the email... its similar to google doc i have
for certain a database leak
hero member
Activity: 983
Merit: 502
I didnt open the file with password they gave.
Just downloaded it to my pc and tried to open but its saying its corrupted, "wordpad cant open this file".
How can they phish us if we dont give them username and password?

Just opening the attachment, and running the VB could well give the phisher enough control to send coins to himself when you open a wallet or a light client.
hero member
Activity: 1088
Merit: 531
Free Crypto in Stake.com Telegram t.me/StakeCasino
I didnt open the file with password they gave.
Just downloaded it to my pc and tried to open but its saying its corrupted, "wordpad cant open this file".
How can they phish us if we dont give them username and password?

It's a microsoft office word file..in the sent docx file is probably a script written code, it does something.I don't know what it does because I deleted the email immediately maybe someone can check what it is in a safe system (Virtual windows with sandbox).
legendary
Activity: 1484
Merit: 1026
In Cryptocoins I Trust
I also got this email and figured it to be a phishing attempt. A search on Google brought me to this thread, lol. I will delete it. No one ever sends me free money, so i knew something was up, lol.
full member
Activity: 434
Merit: 105
I didnt open the file with password they gave.
Just downloaded it to my pc and tried to open but its saying its corrupted, "wordpad cant open this file".
How can they phish us if we dont give them username and password?
newbie
Activity: 3
Merit: 0
Got the same e-mail and flagged it as phishing. I didn't open the attachment, so I shouldn't face any problem, should I?
hero member
Activity: 1088
Merit: 531
Free Crypto in Stake.com Telegram t.me/StakeCasino
LoL got the same email,too.Deleted in seconds! Anyone know what's inside? I'm mean what does the script do in the docx file?
legendary
Activity: 3038
Merit: 4418
Crypto Swap Exchange
I got this too. Kinda weird, the name I was addressed with was my account name. Probably the data leak that happened last time.
Pages:
Jump to: