Forum Home
    • Register
    • Login
    • Search
    • Recent
    • Tags
    • Popular

    \[SCAM\] Fishing email

    Off-Topic
    4
    5
    1031
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      Kevlar Spammer last edited by

      I recieved an email that looks like this:

      [img]http://blog.logrhythm.com/wp-content/uploads/2014/01/BLOG-1.png[/img]

      I understand I’m not the only one.

      Now, you all know me… I’m not going to turn away someone in need. So this is a pretty effective way of targeting people.

      After taking a closer look, this is a pretty sophisticated attack.

      Only Passwords.txt.lnk and wallet.dat are visible unless ‘show hidden files’ is turned on in Windows, and there’s an aditional file, Password.txt.

      The Password.txt.lnk file launches cmd.exe and runs the password.txt. You see, the Passwords.txt file is actually an exe file with the wrong extension. And when you run Passwords.txt.lnk, you end up running that exe. Running this file launches a blank command prompt window, followed by a program masquerading as notepad, then a the real notepad application, which displays the ‘password’ to the wallet.dat file.

      In reality, this program launches a two files, one notepad.exe to display the fake password, and another file ‘Password.txt’ which appears to actually be a trojaned version of EditPlus.

      The trojan lays quiet until you launch the Bitcoin QT wallet, and then it sends your coins.

      It’s clever, it’s inventive, and it will suck your BTC out of your wallet faster than you can blink. Don’t fall for it.

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User last edited by

        pin this.

        In fact. I call again for a Category named Known Scams and whatever we think is appropriate.

        1 Reply Last reply Reply Quote 0
        • T
          Tuck Fheman last edited by

          You’re like a unicorn slayer or something.

          [img]http://25.media.tumblr.com/3c85cd995b35d126f4e48cd078ec423a/tumblr_mz2m6voW4d1rtef2wo1_1280.jpg[/img]

          1 Reply Last reply Reply Quote 0
          • T
            Tuck Fheman last edited by

            .hk is always full of surprises.

            1 Reply Last reply Reply Quote 0
            • P
              Pryderi Regular Member last edited by

              But do they actually sell a rod to fish with?! Love your investigations.

              /edit [url=http://blog.logrhythm.com/uncategorized/emerging-bitcoin-theft-campaign-uncovered/]http://blog.logrhythm.com/uncategorized/emerging-bitcoin-theft-campaign-uncovered/[/url]

              1 Reply Last reply Reply Quote 0
              • First post
                Last post