{"id":2688,"date":"2020-04-16T01:02:59","date_gmt":"2020-04-15T13:02:59","guid":{"rendered":"http:\/\/www.talkcrypto.org\/blog\/?p=2688"},"modified":"2020-06-10T01:03:59","modified_gmt":"2020-06-09T13:03:59","slug":"your-site-has-been-hacked","status":"publish","type":"post","link":"https:\/\/www.talkcrypto.org\/blog\/2020\/04\/16\/your-site-has-been-hacked\/","title":{"rendered":"Your Site Has Been Hacked"},"content":{"rendered":"\n<p>I received the following email recently and initially was very worried. I scrolled down and saw the demand for USD $2000 in Bitcoin! They wanted it sent to this address &#8220;<em>1Q1DF9rJS6fNDSpiV2iEA46BS1mNEaELtC&#8221;.<\/em> (FYI: The address is empty).<\/p>\n\n\n\n<p>Firstly, the site in question has no sensitive information there. In fact, it is just a new blogging site with only 4 or 5 blog posts so this made me raise my eyebrow and not be too concerned. However, if it was a more important website, I would have been a lot more nervous only to calm down having seen <a rel=\"noreferrer noopener\" aria-label=\"this (opens in a new tab)\" href=\"https:\/\/www.google.com\/search?q=PLEASE+FORWARD+THIS+EMAIL+TO+SOMEONE+IN+YOUR+COMPANY+WHO+IS+ALLOWED+TO+MAKE+IMPORTANT+DECISIONS!&amp;rlz=1C5CHFA_enAU892AU892&amp;oq=PLEASE+FORWARD+THIS+EMAIL+TO+SOMEONE+IN+YOUR+COMPANY+WHO+IS+ALLOWED+TO+MAKE+IMPORTANT+DECISIONS!&amp;aqs=chrome..69i57j0.210j0j7&amp;sourceid=chrome&amp;ie=UTF-8\" target=\"_blank\">this<\/a> Google search.<\/p>\n\n\n\n<p>I then sent an email to my hosting provider and they confirmed that this was a scam.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Thanks for getting in touch regarding this. Unfortunately we\u2019ve been<br>seeing an increase in these type of scam attempts but rest assured it is<br>just scam. A security scan shows there is no indication that your site is<br>vulnerable or that it has been compromised. As such you can safely ignore<br>the threat message.<\/em><\/p><\/blockquote>\n\n\n\n<p>What the scammers do is use a template and automate the email replacing the website URL for each site. They typically use the contact us form websites usually have and shame on me for not having a form capture mechanism. ie the confirm I&#8217;m not a robot check box or what is 2+3 or select all the boxes with street lights (a Google favourite). <\/p>\n\n\n\n<p>What you can do is file a Bitcoin Abuse Report at www.bitcoinabuse.com. <a rel=\"noreferrer noopener\" aria-label=\"Here (opens in a new tab)\" href=\"https:\/\/www.bitcoinabuse.com\/reports\/1DQ2F5YsTGSEgvAeJSgjydb5i4jvPKDBW1\" target=\"_blank\">Here<\/a> is a sample.<\/p>\n\n\n\n<p><strong>What the email actually looked like:<\/strong><\/p>\n\n\n\n<p>So if you get an email demanding $2000 USD worth of Bitcoins<\/p>\n\n\n\n<p><em>From: Jorge Bethune &lt;hacker@4ybw.wang><br>Subject: Your Site Has Been Hacked<\/em><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Message Body:<br>PLEASE FORWARD THIS EMAIL TO SOMEONE IN YOUR COMPANY WHO IS ALLOWED TO MAKE IMPORTANT DECISIONS!<\/p><p>We have hacked your website\u00a0<a rel=\"noreferrer noopener\" href=\"http:\/\/www.futurecoders.com.au\/\" target=\"_blank\">http:\/\/www.mysitehere.com<\/a>\u00a0and extracted your databases.<\/p><\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>How did this happen?<br>Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.<\/em><\/p><p><em>What does this mean?<\/em><\/p><p><em>We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site\u00a0<\/em><a rel=\"noreferrer noopener\" href=\"http:\/\/www.futurecoders.com.au\/\" target=\"_blank\"><em>http:\/\/www.mysitehere.com.au<\/em><\/a><em>\u00a0was at fault thusly damaging your reputation and having angry customers\/associates with whatever angry customers\/associates do. Lastly any links that you have indexed in the search engines will be de-indexed based off of blackhat techniques that we used in the past to de-index our targets.<\/em><\/p><p><em>How do I stop this?<\/em><\/p><p><em>We are willing to refrain from destroying your site&#8217;s reputation for a small fee. The current fee is $2000 USD in bitcoins (BTC).<\/em><\/p><p><em>Send the bitcoin to the following Bitcoin address (Copy and paste as it is case sensitive):<\/em><\/p><p><em>1Q1DF9rJS6fNDSpiV2iEA46BS1mNEaELtC<\/em><\/p><p><em>Once you have paid we will automatically get informed that it was your payment. Please note that you have to make payment within 5 days after receiving this notice or the database leak, e-mails dispatched, and de-index of your site WILL start!<\/em><\/p><p><em>How do I get Bitcoins?<\/em><\/p><p><em>You can easily buy bitcoins via several websites or even offline from a Bitcoin-ATM. We suggest you\u00a0<\/em><a rel=\"noreferrer noopener\" href=\"https:\/\/cex.io\/\" target=\"_blank\"><em>https:\/\/cex.io\/<\/em><\/a><em>\u00a0for buying bitcoins.<\/em><\/p><p><em>What if I don\u2019t pay?<\/em><\/p><p><em>If you decide not to pay, we will start the attack at the indicated date and uphold it until you do, there\u2019s no counter measure to this, you will only end up wasting more money trying to find a solution. We will completely destroy your reputation amongst google and your customers.<\/em><\/p><p><em>This is not a hoax, do not reply to this email, don\u2019t try to reason or negotiate, we will not read any replies. Once you have paid we will stop what we were doing and you will never hear from us again!<\/em><\/p><p><em>Please note that Bitcoin is anonymous and no one will find out that you have complied.<\/em><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>I received the following email recently and initially was very<\/p>\n","protected":false},"author":1,"featured_media":2690,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":["post-2688","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bitcoins"],"featured_image_urls":{"full":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"thumbnail":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked-150x103.jpg",150,103,true],"medium":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"medium_large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"1536x1536":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"2048x2048":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"chromenews-featured":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"chromenews-large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false],"chromenews-medium":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2020\/06\/hacked.jpg",194,103,false]},"author_info":{"info":["seandotau"]},"category_info":"<a href=\"https:\/\/www.talkcrypto.org\/blog\/category\/bitcoins\/\" rel=\"category tag\">Bitcoins<\/a>","tag_info":"Bitcoins","comment_count":"0","_links":{"self":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/2688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/comments?post=2688"}],"version-history":[{"count":1,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/2688\/revisions"}],"predecessor-version":[{"id":2689,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/2688\/revisions\/2689"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/media\/2690"}],"wp:attachment":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/media?parent=2688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/categories?post=2688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/tags?post=2688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}