Fun with Viruses
Does anyone know of any computer viruses that they would like to see demoed on a machine? Iâd like to explore some malware and share video of what it does to a computer.Â
Know a good virus?

çĽćĽ / Permanent Vacation
let's talk about Bridgerton tea, my ask is open
Keni
Stranger Things
occasionally subtle

Discoholic đŞŠ
Show & Tell
DEAR READER

JBB: An Artblog!
dirt enthusiast
Cosimo Galluzzi
styofa doing anything
almost home
Peter Solarz

â
Xuebing Du
RMH
YOU ARE THE REASON
Lint Roller? I Barely Know Her
seen from United States

seen from United States

seen from Germany
seen from Pakistan

seen from Malaysia
seen from United States

seen from Switzerland

seen from United States
seen from United States

seen from United States

seen from United States

seen from United States
seen from United States

seen from United States

seen from United States

seen from China

seen from Malaysia

seen from Canada

seen from Italy

seen from Philippines
@malwarepat-blog
Fun with Viruses
Does anyone know of any computer viruses that they would like to see demoed on a machine? Iâd like to explore some malware and share video of what it does to a computer.Â
Know a good virus?

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
so it turns out one reason why kissanimeâs been sucking ass lately in terms of load times is cause rapidvideo literally uses your browser to mine cryptocurrency???
And thatâs just like, one of the hundreds/thousands of other sketchy things the site has going on in the background by just sitting on any of its web pages without an adblocker/scriptblocker
for those like me who donât understand what this means my IT nerd partner explained it in dummyhead terms:   Basically they arent taking YOUR shit theyâre borrowing your computers horsepower and brains it should be spending on watching the video and instead dedicating half of that horsepower and brains towards their own servers. so if you need 5 pwr to make the video go the website is taking 3 pwr and making it go towards their nefarious goals and giving you only 2 pwr to watch videos.  Kind of like stealing electricity.  People should be using U-block as its far safer than addblock these days because websites can have a lot scarier stuff than this on them, at least its just using you to mine other people vs mining your own computer
Testing CPU Usage on KissAnime with several Adblock/Anti-tracking extensions in Google Chrome      Â
Environment: Windows 7 Ultimate x64 4GB RAM 1 Processor/Core (Virtualized in VMware Workstation)
Web Browser: Google Chrome Tried Extensions: -uBlock Origin -Ghostery -Privacy Badger
Post on my blog about this (basically the same thing I added to this post): https://malwarepat.tumblr.com/post/168650929622/testing-cpu-usage-on-kissanime-with-several
Have questions/tips/requests regarding malware, adware, or general information security? Contact me @malwarepat
Testing CPU Usage on KissAnime with several Adblock/Anti-tracking extensions in Google Chrome      Â
Environment: Windows 7 Ultimate x64 4GB RAM 1 Processor/Core (Virtualized in VMware Workstation)
Web Browser: Google Chrome Tried Extensions: -uBlock Origin -Ghostery -Privacy Badger
What prompted me to look into this: http://cherryflavoredtrickster.tumblr.com/post/168634049786/stupidbeecandle-wunkolo-backtornado-so-it
Tumblr Bitcoin Scam Messages Investigation
This post will contain details on my investigation into the Tumblr âBitcoinâ message fiasco.Â
Bitcoin Wallets Mentioned
ââ
Posts on my blog tagged âtumblr btc scamâ
Help the Investigation:
If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me to see the scope of what people are getting. Â
Post where I learned of the malicious activity: https://malwarepat.tumblr.com/post/168419395787/iron-thorn-this-blog-did-not-and-will-not-send from @iron-thorn
about that bitcoin thing
if you guys have received a bitcoin message from me, PLEASE tell me. it wasnât me. itâs also a virus, as it seems. pls beware with that shit. ask your followers, mutuals, friends, etc. on tumblr. or just write a message on there, on tumblr. PLEASE reblog this post to spread the word. and also, tell me if you got a message from my account saying that. i highly recommend that if that happened with your account, change you email, your password, your emailâs password, etc. if a link appears, PLEASE donât open it.
If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me in my investigation to see the scope of what people are getting. Â

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
There seem to be some kind of tumblr virus going around, where blogs will send out messages to blogs they follow asking for seemingly small amounts of bitcoin in order to buy an item (like a camera or similar), followed by a link.
I donât know if anyone has impersonated me yet, but considering @goattrain just told me he got a message from one of his long time followers Iâm putting this here anyway: I would never ask anyone to send me bitcoins, or randomly send anyone a message asking for donations either for that matter. So if you see one of these messages, please donât send them any money and let me know.
Stay safe and ensure the person messaging you are indeed the person you think it is, alright?Â
If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me in my investigation to see the scope of what people are getting. Â
âchocolate-loverâ Investigation
Links used in this campaign
Posts on my blog tagged âchocolateloverinvestigationâ
---
Help the investigation!
If you receive a message that looks like the screenshot in this post, screenshot it and send it to me!
Submit screenshots here: https://malwarepat-chocolatelover.tumblr.com/submit
if you get a message from me asking for bitcoin itâs fake because i have no idea how bitcoin works and i will only ask you for cold hard cash
MalwarePat Joins the Fray                  Â
Hello all, Iâm just a friendly white hat looking to understand where the âbitcoinâ messages are coming from and who is behind them. Â If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me to see the scope of what people are getting. Â
Thanks!
-MalwarePat
This blog did not and will not send requests for bitcoin donations.
There seems to be a virus or some sort of malware going around causing blogs to âsend outâ chat messages to blogs that they follow asking for help with the purchase of certain items through donations of seemingly small amounts using bitcoin and adds a link to the message.
The message goes as following (at least the first message I got went like this): âHi there buddy. I need help, Iâm trying to buy a laptop and I canât afford it. Iâm about 0.36$ short, and Iâd really appreciate if you could help me and transfer some money to me via bitcoin using this *link*.â
The small details in the message seems to have a few variations with the greeting, amount and purchased item showing up in different variations from formal to friendly, from 0.016 to 2$ and from a phone case to a laptop among others.
The blogs that are affected send out the messages to blogs that they follow for a long time mostly, so you are most likely to receive the message from a long time, active follower whose name you might recognize or a mutual etc. The blogs that are affected are not spam bots but actual active followers who follow the recipient for months or years and most likely the blogger who âsentâ the message is unaware of the message being sent.
DO NOT OPEN THE LINK.
Opening up the link will cause the virus to spread even more and infect your computer/mobile with any sort of malware.
If you have received a message of that sort from this blog please know that it was not sent by me or within my control and ignore/delete the message without clicking the link.
MalwarePat Joins the Fray                  Â
Hello all, Iâm just a friendly white hat looking to understand where the âbitcoinâ messages are coming from and who is behind them. Â If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me to see the scope of what people are getting. Â
Thanks!
-MalwarePat
[URLs] - Tumblr "chocolate-loverâ Messages Investigation
This post will have any links discovered in the Tumblr âchocolate-loverâ Messages campaign.
DO NOT VISIT THESE LINKS
hxxps://goo.gl/EjVK9e --> Now disabled, used to point to a scam survey site in the hxxps://www.humanverify.net domain.Â
hxxp://bit.ly/2gT9v62, hxxp://bit.ly/2gSD0Vi, hxxp://bit.ly/2uxAYPZ -> hxxps://www.humanverify.net/cl.php?id=f0a3ef4412298e6e57425a54b5327aa5&chocolate-lover15267
Completing the HumanVerify segment above redirects to hxxp://www.humanverify.net/contentlockers/u.php?id=0vhEVTB6vnEGatmzW%2Fui5smGAdBCtw7uD51YkquxrC4uuoTP4ZnMdwbrbmll09I3&r=aHR0cHM6Ly93d3cuaHVtYW52ZXJpZnkubmV0L2NsLnBocD9pZD1mMGEzZWY0NDEyMjk4ZTZlNTc0MjVhNTRiNTMyN2FhNSZjaG9jb2xhdGUtbG92ZXIxNTI2Nw%3D%3D
This long gibberish redirects to hxxps://www.tumblr.com/
The base64 encoded string aHR0cHM6Ly93d3cuaHVtYW52ZXJpZnkubmV0L2NsLnBocD9pZD1mMGEzZWY0NDEyMjk4ZTZlNTc0MjVhNTRiNTMyN2FhNSZjaG9jb2xhdGUtbG92ZXIxNTI2Nw== decodes to hxxps://www.humanverify.net/cl.php?id=f0a3ef4412298e6e57425a54b5327aa5&chocolate-lover15267 (the link from above)

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch ⢠No registration required ⢠HD streaming
[Wallets] - Tumblr Bitcoin Scam Messages Investigation
1JRynp7FjH9AKuht95Niigc7EU4GyqbnGFThis post will have any wallets discovered in the Tumblr Bitcoin Scam Messages campaign.
153PTtfzAzs4Nty8iFB1hUp9N7aCN7MQeK
1B82pfhvrgBxkqPzs1CmZVpBdK24CAD6xX
18bMAdb5x8H5VTdxSSyVyyxSnKmqpy22o2
1MdyvPQmV38njpGKtbuvA5Kxw6ah8cpLrZ
1JRynp7FjH9AKuht95Niigc7EU4GyqbnGF
First wallet Iâve seen with a transaction into it
147.17 USD @2017-12-08T12:54:37Z
...
Tumblr Bitcoin Scam Messages Investigation
This post will contain details on my investigation into the Tumblr âBitcoinâ message fiasco.Â
Bitcoin Wallets Mentioned
-----
Posts on my blog tagged âtumblr btc scamâ
Help the Investigation:
If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me to see the scope of what people are getting. Â
Post where I learned of the malicious activity: https://malwarepat.tumblr.com/post/168419395787/iron-thorn-this-blog-did-not-and-will-not-send from @iron-thorn
This blog did not and will not send requests for bitcoin donations.
There seems to be a virus or some sort of malware going around causing blogs to âsend outâ chat messages to blogs that they follow asking for help with the purchase of certain items through donations of seemingly small amounts using bitcoin and adds a link to the message.
The message goes as following (at least the first message I got went like this): âHi there buddy. I need help, Iâm trying to buy a laptop and I canât afford it. Iâm about 0.36$ short, and Iâd really appreciate if you could help me and transfer some money to me via bitcoin using this *link*.â
The small details in the message seems to have a few variations with the greeting, amount and purchased item showing up in different variations from formal to friendly, from 0.016 to 2$ and from a phone case to a laptop among others.
The blogs that are affected send out the messages to blogs that they follow for a long time mostly, so you are most likely to receive the message from a long time, active follower whose name you might recognize or a mutual etc. The blogs that are affected are not spam bots but actual active followers who follow the recipient for months or years and most likely the blogger who âsentâ the message is unaware of the message being sent.
DO NOT OPEN THE LINK.
Opening up the link will cause the virus to spread even more and infect your computer/mobile with any sort of malware.
If you have received a message of that sort from this blog please know that it was not sent by me or within my control and ignore/delete the message without clicking the link.
Edit:
To those worried because they received a message with a wallet code instead of a l8nk, thereâs nothing to worry about. Tge wallet code is essentially tge equivalent of a bank account number. So unless you actually go and actively transfer from your wallet to theurs youâre safe. Opening the messages themselves is harmless.
The best way to know if you were affected is to simply go into messages and see if you sent a message like that to anyone, it will appear in the chat.
I personally recommend changing passwords just in case, even if you werenât hit with the virus.
MalwarePat Joins the Fray                  Â
Hello all, Iâm just a friendly white hat looking to understand where the âbitcoinâ messages are coming from and who is behind them. Â If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Â Itâll help me to see the scope of what people are getting. Â
Thanks!
-MalwarePat
MalwarePat Joins the Fray
Hello all, Iâm just a friendly white hat looking to understand where the âbitcoinâ messages are coming from and who is behind them. If you receive one of these messages, please submit a screenshot of the message to https://malwarepat-btc.tumblr.com/submit. Itâll help me to see the scope of what people are getting.Â
Thanks!
-MalwarePat