Showing posts with label Pastebin. Show all posts
Showing posts with label Pastebin. Show all posts

Friday, 26 June 2015

Man Mails More Than 97,000 People Their Password


With great regularity on websites like Pastebin stolen passwords and other credentials posted. The reason for a programmer named Julian alias' aTechDad 'to collect all kinds of stolen email addresses and passwords via a script and then warn the user.

For example, some Internet users use Google Alerts or other services to warn if their data appear anywhere on the internet.Most Internet users may not know such services exist and users who know there is much that their data would rather not leave you in this kind of party, said the programmer. He therefore decided to create a script, which he in a three-day period on Pastebin 97 931 combinations of email addresses and passwords collected.

Last month, he decided to warn users. Through a simple e-mail, he said that the account of the user probably was compromised, which he also co-stared the password. The nearly 98,000 sent emails yielded only nine thanked by. 100 e-mails could not be delivered, while 41 people sent back a request to be unsubscribed. Yet Julian considers the experiment a success. At this time he started a second experiment, in which he has already collected 300,000 passwords. "I might do it again," said the programmer.

Wednesday, 3 June 2015

Ransomware Maker Decrypts As Promised Infected PCs


The creator of the Locker-ransomware has promised as encrypted files on all computers he infected without charge and automatically decrypted. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.

At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files. Rich is the author therefore did not become. According to Symantec, he would total 152 euros received 22 victims.


Last week the ransomware maker on Pastebin posted a message in which he regret expressed. It was at its say never been his intention to spread the ransomware. He compiled a file with all the encryption keys available and stated that on June 2, all remaining infected computers would be automatically decrypted. And the author has fulfilled that promise, reports Bleeping Computer . For users that their computer had been disinfected, there is a unlocker tool made ​​available. How to distribute the ransomware is managed is still unknown.

Tuesday, 2 June 2015

Ransomware-Maker Repents And Gives Decryption Keys Away




Last Monday, numerous computers suddenly by a new ransomware variant called Locker hit a small amount to the victims asked for decryption, but the automaker would now regret his actions and provides all the decryption keys free of charge.

In addition, the ransomware on June 2 will automatically create all encrypted files accessible. Locker really came up out of nowhere. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files.

On Saturday put someone who "Poka Bright Minds" calls a message on Pastebin . In it he claims to be responsible for Locker. According to him it was never intended to spread the ransomware. The online storage Mega he has now a file with bitcoin addresses and keys installed. The forum Bleeping Computer confirms that the file actually contains the keys of victims. In addition, on June 2, the automatic start decryption. How the malware spread exactly is still unknown.

File Information 
Name: database_dump.csv
Size: 127.5 MB
MD5: d4d781412e562b76fe0db0977cf6279b
SHA-1: 6ba671ce2a6c256c74d7db81186b0dbddd5e2185
SHA-256: d7fd791b86615fada64fe0290aecb70e5584b9ac570e7b55534555a3b468b33f

VirusTotal Link

Mega Link

Thursday, 14 May 2015

Cisco Raises The Alarm For Advancing Macro-Malware


In half a year, the number of attacks doubled through macro-malware, network giant Cisco reason to sound the alarm. The malware is distributed via e-mail attachments that contain Word documents. Once the document is opened, the user is asked whether he wants to enable macros, because Microsoft has it turned off by default for security reasons.

According to Tim Gurganus Cisco, many people forget and turn the threat of macros then, so the malicious code in the document to download and install malware. A successful approach, as evidenced by the increase in the number of e-mail attacks macro-malware is used. The problem is compounded because most email filters and business office documents and not block the malicious macro code geobfusceerd and is very difficult to detect.

The first malicious macros were still out of 150 lines of code, which have now been there in 1500. The makers have all kinds of measures taken to avoid detection and the tactics in the field of social engineering refined. Thus allowed to open a blank page after the first copies, which could alert users that something was wrong. Since early this year "distraction Documents" displayed while in the background the infection takes place. Consequently, users will not suspect that it is malware.

It also appears that the attackers regularly hacked legitimate websites or cloud services like Dropbox, Google Drive or Pastebin.com use to host the malware. The big advantage is that the domains do not stand out in traffic and will not be blocked soon. "Macro-malware is also a good example of malware makers who respond severely becoming security measures, such as blocking zip files containing .exe files. Attackers continue to adapt their tactics, techniques and procedures," said Gurganus.

Monday, 10 March 2014

Bitcoin trading platform Mt. Gox security issue is a fraud? Hackers say!

Last month, Tokyo-based trading platform Bitcoin Mt. Gox claims to have lost because of security vulnerabilities worth nearly $ 500 million in customer bitcoins, but many users do not trust the platform to explain this Bitcoin trading platform.

Bitcoin trading platform Mt. Gox did not provide further information they are black, according to reports hackers use the trading system software vulnerabilities to steal, eventually led Mt.Gox crash. On Sunday, a group of hackers have claimed that black into Mt. Gox CEO Capet DeGeneres (Mark Karpeles) personal blog and found the number of bits stored coins and Mt. Gox claimed the number was stolen inconsistent.

According to Forbes, the hacker entered the Capet DeGeneres personal blog and Reddit account and posted a message claiming Bitcoin trading platform Mt.Gox still claiming the right to use some of Capet DeGeneres stolen bitcoins.

These hackers uploaded a series of documents, including a spreadsheet containing the anonymous user Bitcoin balances, as well as proof of residence Capet DeGeneres screenshot hacker access these data. In addition, hackers also released a file size of 716MB, saying the file containing the stolen data from the Mt. Gox server. Here is the link to the data address .

List of files
$ Tree
.
├ ─ ─ backoffice
│ ├ ─ ─ Bin
│ │ ├ ─ ─ TibanneBackOffice
│ │ │ ├ ─ ─ MacOSX
│ │ │ │ └ ─ ─ TibanneBackOffice.app
│ │ │ └ ─ ─ Windows
│ │ │ └ ─ ─ TibanneBackOffice.exe
│ │ └ ─ ─ screenshot.png
│ ├ ─ ─ Docs
│ │ ├ ─ ─ CV-Mark_Karpeles_20100325.pdf
│ │ ├ ─ ─ btc_xfer_total_summary.txt
│ │ ├ ─ ─ home_addresses.txt
│ │ └ ─ ─ trades_summary.txt
│ └ ─ ─ Exports
│ ├ ─ ─ btc_xfer_report.csv
│ └ ─ ─ mtgox_balances
└ ─ ─ trades
    ├ ─ ─ 2011-04.csv
    ├ ─ ─ 2011-04_mtgox_japan.csv
    ├ ─ ─ 2011-05.csv
    ├ ─ ─ 2011-06.csv
    ├ ─ ─ 2011-07.csv
    ├ ─ ─ 2011-08.csv
    ├ ─ ─ 2011-09.csv
    ├ ─ ─ 2011-10.csv
    ├ ─ ─ 2011-11.csv
    ├ ─ ─ 2011-12.csv
    ├ ─ ─ 2012-01.csv
    ├ ─ ─ 2012-02.csv
    ├ ─ ─ 2012-03.csv
    ├ ─ ─ 2012-04.csv
    ├ ─ ─ 2012-05.csv
    ├ ─ ─ 2012-06.csv
    ├ ─ ─ 2012-07.csv
    ├ ─ ─ 2012-08.csv
    ├ ─ ─ 2012-09.csv
    ├ ─ ─ 2012-10.csv
    ├ ─ ─ 2012-11_coinlab.csv
    ├ ─ ─ 2012-11_mtgox_japan.csv
    ├ ─ ─ 2012-12_coinlab.csv
    ├ ─ ─ 2012-12_mtgox_japan.csv
    ├ ─ ─ 2013-01_coinlab.csv
    ├ ─ ─ 2013-01_mtgox_japan.csv
    ├ ─ ─ 2013-02-12_coinlab.csv
    ├ ─ ─ 2013-02-12_mtgox_japan.csv
    ├ ─ ─ 2013-02-19_coinlab.csv
    ├ ─ ─ 2013-02-19_mtgox_japan.csv
    ├ ─ ─ 2013-02-26_coinlab.csv
    ├ ─ ─ 2013-02-26_mtgox_japan.csv
    ├ ─ ─ 2013-02_coinlab.csv
    ├ ─ ─ 2013-02_mtgox_japan.csv
    ├ ─ ─ 2013-03-05_coinlab.csv
    ├ ─ ─ 2013-03-05_mtgox_japan.csv
    ├ ─ ─ 2013-03-12_coinlab.csv
    ├ ─ ─ 2013-03-12_mtgox_japan.csv
    ├ ─ ─ 2013-03-19_coinlab.csv
    ├ ─ ─ 2013-03-19_mtgox_japan.csv
    ├ ─ ─ 2013-03-26_coinlab.csv
    ├ ─ ─ 2013-03-26_mtgox_japan.csv
    ├ ─ ─ 2013-03_coinlab.csv
    ├ ─ ─ 2013-03_mtgox_japan.csv
    ├ ─ ─ 2013-04_coinlab.csv
    ├ ─ ─ 2013-04_mtgox_japan.csv
    ├ ─ ─ 2013-05_coinlab.csv
    ├ ─ ─ 2013-05_mtgox_japan.csv
    ├ ─ ─ 2013-06_coinlab.csv
    ├ ─ ─ 2013-06_mtgox_japan.csv
    ├ ─ ─ 2013-07_coinlab.csv
    ├ ─ ─ 2013-07_mtgox_japan.csv
    ├ ─ ─ 2013-08_coinlab.csv
    ├ ─ ─ 2013-08_mtgox_japan.csv
    ├ ─ ─ 2013-09_coinlab.csv
    ├ ─ ─ 2013-09_mtgox_japan.csv
    ├ ─ ─ 2013-10_coinlab.csv
    ├ ─ ─ 2013-10_mtgox_japan.csv
    ├ ─ ─ 2013-11_coinlab.csv
    └ ─ ─ 2013-11_mtgox_japan.csv

33 directories, 80 files








Dump contains information about all the trades took place, exchange management utility, summary statistics, the authors computed hacking (archive formed by attackers to avoid the leakage of personal data of customers MtGox).

Currency: AUD Balance: 924,124.65121
Currency: BTC Balance: 951,116.21905382 <- This fat fucker lied to us! (Sic)
Currency: CAD Balance: 320,184.36558
Currency: CHF Balance: 99,487.07308
Currency: CNY Balance: 297,775.78994
Currency: DKK Balance: 112,264.56207
Currency: EUR Balance: 5,634,625.59531
Currency: GBP Balance: 921,892.96793
Currency: HKD Balance: 740,519.14894
Currency: JPY Balance: 384,885,150.13700
Currency: NOK Balance: 91,346.00305
Currency: NZD Balance: 58,224.95320
Currency: PLN Balance: 1,645,194.67364
Currency: RUB Balance: 551,162.54477
Currency: SEK Balance: 15,335.84383
Currency: SGD Balance: 43,193.59706
Currency: THB Balance: 666,464.33497
Currency: USD Balance: 30,611,805.67481
Total BTC Deposits: 19,065,241.307202
Total BTC Withdrawl: 18,563,466.149383
------------
BTC Difference: 501,775.157819


Hackers also said, saying the company's balance there bitcoin 951,116 BTC, based on current dollar terms, worth more than 600 million U.S. dollars. MtGox claiming that it lost a total of 850,000 bitcoins In announcing the bankruptcy filing, where 100,000 is the trading platform they own.

It CENT was reported that hackers published these data have not been confirmed, but some Reddit users said their personal account balances and hackers released data match.

As of press time, Capet DeGeneres and special currency trading platform Mt.Gox not yet issued a statement on the matter.