CryptoBudha
    Demo
    What's Hot

    Litecoin price analysis: LTC breaks above $55 as bulls try to climb $60

    June 25, 2022

    Why trusted execution environments will be integral to proof-of-stake blockchains

    June 25, 2022

    Beware of NFT scams: Rewarding, but highly risky

    June 25, 2022
    Facebook Twitter Instagram
    • ABOUT US
    • CONTACT US
    • TERMS OF SERVICES
    Facebook Twitter Instagram
    CryptoBudha
    • Home
    • Cryptocurrency

      A String of 200 ‘Sleeping Bitcoins’ From 2010 Worth $4.27 Million Moved on Friday – Bitcoin News

      June 25, 2022

      Bitcoin Saylor Speculative Attack – Bitcoin Magazine

      June 25, 2022

      USA finance and payments live updates: mortgage rates, Bitcoin prices, S.S dissability, unemployment benefits. – AS USA

      June 24, 2022

      Crypto and Defi Could Pose ‘Real Risks’ to Financial Stability – Regulation Bitcoin News

      June 24, 2022

      USA finance and payments live updates: mortgage rates, Bitcoin prices, S.S dissability, unemployment benefits. – AS USA

      June 23, 2022
    • Blockchain

      Top 10 Crypto Whales on Wall Street By DailyCoin

      June 25, 2022

      Understanding Crypto Liquidation, Margin Calls and Bots

      June 25, 2022

      Is HIVE Blockchain Technologies Ltd (HIVE) a Winner in the Financial Services Sector?

      June 24, 2022

      Namibian University Set to Offer Master’s Degree in Blockchain Technology in 2024 – Bitcoin News

      June 24, 2022

      Bitcoin, Ethereum, Crypto News and Price Data

      June 23, 2022
    • ICO

      ALL BEST ICO (ALLBI) What Does the Chart Say Saturday?

      June 25, 2022

      Recover The Crypto Crash With Filecoin (FIL) And Parody Coin (PARO)

      June 25, 2022

      CRYPTOSTONE launches a crypto payment gateway in their anonymous financial ecosystem.

      June 24, 2022

      Coinbase Launching ‘Nano’ Bitcoin Futures via Derivatives Exchange

      June 24, 2022

      IDO and ICO promotion agency Baden Bower quadruples their blockchain clients year on year – CryptoMode

      June 23, 2022
    • NFT

      Beware of NFT scams: Rewarding, but highly risky

      June 25, 2022

      The Notorious B.I.G. Collection And The Marketing Of NFT Campaigns

      June 25, 2022

      Fanpage Drops Omaha NFT Series | News

      June 24, 2022

      Bentley Motors gears up to drop its Genesis NFT collection on Polygon

      June 24, 2022

      Bored Ape NFT Holders Love Physical Bored Ape Toys: Teen Sells $700K

      June 23, 2022
    • Metaverse

      Sweet Tooth: Mars Inc. Submits Applies For Crypto, NFT, Metaverse Trademarks For M&Ms

      June 25, 2022

      What Metaverse Standards Forum Means For the Space

      June 25, 2022

      China’s Metaverse Is Dystopia

      June 24, 2022

      This Week In The Metaverse: NFT.NYC And Meta’s New VR Headset Prototypes

      June 24, 2022

      Digital Quality in the Metaverse

      June 23, 2022
    • More
      1. Analysis
      2. Regulations
      3. Mining
      4. View All

      Litecoin price analysis: LTC breaks above $55 as bulls try to climb $60

      June 25, 2022

      Bullish momentum continues as AVAX prices hit $21.47

      June 25, 2022

      What Does a Risk Analysis Say About Swace (SWACE) Friday?

      June 24, 2022

      Litecoin price analysis: LTC recovers to $56 as bulls carry on their lead

      June 24, 2022

      UAE a trendsetting country in cryptocurrency regulation: European academic

      June 25, 2022

      Sri Lankans Turn to Unregulated Crypto Amid Crisis; India Moves To Regulate It

      June 25, 2022

      Australian Crypto Exchange BTC Markets Receives Finance Service License

      June 24, 2022

      Swiss Regulator Urges Financial Watchdogs to Protect Crypto Investors – Regulation Bitcoin News

      June 24, 2022

      Why trusted execution environments will be integral to proof-of-stake blockchains

      June 25, 2022

      Miner Capitulation Means Bitcoin Bottom Is Near: CryptoQuant

      June 25, 2022

      How is Bitfarms holding up amidst the market crash? – The Coin Republic

      June 24, 2022

      WeChat Bans All Crypto-Related Content Following ToS Update

      June 24, 2022
    CryptoBudha
    Home»NFT»Fake Pixelmon NFT site infects you with password-stealing malware
    pixelmon-header.jpg
    NFT

    Fake Pixelmon NFT site infects you with password-stealing malware

    adminBy adminMay 15, 2022No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The fake Pixelmon NFT site attracts fans with free tokens and collectibles while infecting cryptocurrency wallet-stealing malware.

    Pixelmon Popular NFT project Its roadmap includes creating an online Metaverse game where you can use Pixel Monpet to gather, train and fight other players.

    With nearly 200,000 Twitter followers and over 25,000 Discord members, the project has received a lot of attention.

    Impersonate a Pixelmon project

    To take advantage of this interest, the threat actor copied the legitimate pixelmon.club website and created a fake version with pixelmon.[.]Pw for distributing malware.

    This site is almost a replica of the legitimate site, but the malicious site provides an executable file that installs password-stealing malware on the device instead of providing a demo of the project’s game.

    Fake Pixelmon website
    Fake Pixelmon website
    Source: Bleeping Computer

    This site provides a file called Installer.zip that contains executable files that appear to be corrupted and do not infect users with malware.

    However, MalwareHunterTeam, First discovered This malicious site has made it possible to find other malicious files distributed by the site and see which malware is spreading.

    One of the files distributed by this malicious site is setup.zip, which contains the setup.lnk file. Setup.lnk is a Windows shortcut that runs a PowerShell command to download the system32.hta file from pixelmon.[.]pw.

    Contents of Setup.lnk
    Contents of Setup.lnk
    Source: Bleeping Computer

    When Bleeping Computer tested these malicious payloads, the System32.hta file downloaded Vidar. This is password-stealing malware that is not as commonly used as it used to be.This has been confirmed by security researchers Fumik0_I have analyzed this malware family before.

    When executed, the attacker’s Vidar sample connects to the Telegram channel and obtains the IP address of the malware’s command and control server.

    Telegram channel containing C2IP address
    Telegram channel containing C2IP address
    Source: Bleeping Computer

    The malware then gets a configuration command from C2 and downloads more modules used to steal data from the infected device.

    Vidar malware can steal passwords from browsers and applications, search your computer for a file that matches a particular name, and upload that file to an attacker.

    As you can see from the malware configuration below, C2 tells the malware to search for and steal various files such as text files, cryptocurrency wallets, backups, codes, password files, and authentication files.

    Configuration commands obtained from the C2 server
    Configuration commands obtained from the C2 server
    Source: Bleeping Computer

    Since this is an NFT site, visitors are expected to install a cryptocurrency wallet on their computer. For this reason, threat actors emphasize finding and plagiarizing files related to cryptocurrencies.

    The site is not currently distributing a working payload, but Bleeping Computer has confirmed evidence that threat actors have been changing the site for the past few days as the payload that was available two days ago is no longer available. ..

    Due to the activity on the site, this campaign will continue to be active and it is expected that functional threats will be added soon.

    NFT projects are overwhelmed by scams designed to steal cryptocurrencies, so you should always make sure that the URL you are visiting is actually related to the project you are interested in.

    In addition, do not run executables from unknown websites without first scanning with or without antivirus software. VirusTotal..

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Beware of NFT scams: Rewarding, but highly risky

    June 25, 2022

    The Notorious B.I.G. Collection And The Marketing Of NFT Campaigns

    June 25, 2022

    Fanpage Drops Omaha NFT Series | News

    June 24, 2022

    Bentley Motors gears up to drop its Genesis NFT collection on Polygon

    June 24, 2022
    Add A Comment

    Leave A Reply Cancel Reply

    banner
    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo
    About Us:

    Your source for the serious news. cryptobudha is crafted specifically to exhibit the lest crypto related News. Visit our main page for more News or contact us

    Email : timeaustralian@yahoo.com

    We're social. Connect with us:

    Facebook Twitter Instagram
    Latest Posts

    Reggie Fils-Aime discussed the Metaverse, blockchain technology, and more

    April 29, 2022

    Creating your first NFT | Creative Bloq

    June 11, 2022

    RENNSPORT sim’s digital ownership “not an NFT”

    May 27, 2022
    Get Informed

    Subscribe to Updates

    Get the latest creative news about the crypto world .

    Facebook Twitter Instagram Pinterest
    • ABOUT US
    • CONTACT US
    • TERMS OF SERVICES
    © 2022 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Subscribe
    Get the latest creative news about the crypto world.

    We are using cookies to give you the best experience on our website.

    You can find out more about which cookies we are using or switch them off in settings.

    CryptoBudha
    Powered by  GDPR Cookie Compliance
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

    Strictly Necessary Cookies

    Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

    If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.