Skip to content

Instantly share code, notes, and snippets.

@jyap808
Last active August 29, 2015 14:22
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save jyap808/3212c08145175bc20e0d to your computer and use it in GitHub Desktop.
Save jyap808/3212c08145175bc20e0d to your computer and use it in GitHub Desktop.
Dracula Coin.. Quick notes

TLDR summary: Dracula Coin dev posted the link to a "clean" wallet scan in Virus Total. The actual download link in the ANN has malware.

BCT ANN: https://bitcointalk.org/index.php?topic=1076331.new#new

Virus Total report from the ANN: https://www.virustotal.com/en/file/2cfad746a21e8468979c01fdcf187f7423fbc47e70358a910e7c324f2dcb4703/analysis/1433107106/

Reported SHA256 hash:

2cfad746a21e8468979c01fdcf187f7423fbc47e70358a910e7c324f2dcb4703

Wallet link in ANN: https://mega.co.nz/#!kU5BBS4L!AkcgGgqrkfHILRzGuvNKRDICP1zPcK2jQA62M9t7Qq4

Actual SHA256 hash:

$ shasum -a 256 Dracula-qt32.exe 
bc68743e7b609d704bcad2106f398114ce938706cf5e9512104c917ff5e265e0  Dracula-qt32.exe

Actual Virus Total report: https://www.virustotal.com/en/file/bc68743e7b609d704bcad2106f398114ce938706cf5e9512104c917ff5e265e0/analysis/

Actual results:

ESET-NOD32	a variant of MSIL/Kryptik.CBK	20150602
Fortinet	W32/Zapchast.AAXNS!tr	20150602
Kaspersky	Trojan.MSIL.Zapchast.aaxns	20150602
Panda	Generic Suspicious	20150601

Compared to a clean wallet made by me (Jumbucks developer):

Virus total report: https://www.virustotal.com/en/file/ad7f151a540057c5d3b3ecbe45817e6fceedf9e52192e5e57f26cd68c2e22408/analysis/1433271521/

Reported SHA256 hash:

ad7f151a540057c5d3b3ecbe45817e6fceedf9e52192e5e57f26cd68c2e22408

Matches:

$ shasum -a 256 Jumbucks-1.8-win32.exe 
ad7f151a540057c5d3b3ecbe45817e6fceedf9e52192e5e57f26cd68c2e22408  Jumbucks-1.8-win32.exe

ANN screen shot

DRA ANN

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment