Jump to content
  • 0

WARNING -- Phishing/Hacking Attempts


Yamagata 1st MRB

Question

Hello All,

It looks like SSgt. Marchese's steam account has been compromised. If you receive a message "WTF Dude?" with a link to a "screen-pictures" site, DO NOT FOLLOW IT. You will download a virus, if not some sort of keylogger or malicious software. Steam community says it steals all your trade-able DLC and resends the virus to your friends list.

omithacked_zps9d32ca43.png

I can PM the URL if anyone feels like getting hacked and/or wants to debug it! :lol:

If you did download or follow the link, run a virus scan and change your steam password ASAP!

Being in IT has taught me to be wary of unknown links from others, and to NEVER download unknown files. When I saw the link, I immediately googled the site for legitimacy and the list of warnings and infection reports on the Steam Community threw up the red flag. Please be cautious and browse safely! If anyone has issues, please post a request for help and our MSO team will help you out!

Thanks,

Lt. Col. Yamagata

Edited by Candy 1st MRB
Link to comment
Share on other sites

23 answers to this question

Recommended Posts

  • 0

Hello all. I knows it's been a while but I am quite aware of the situation and will confirm. Apparently someone from my friends list had this virus and like a dope I fell for it and I am sorry for any problems this might of caused. I have changed my password to my steam account and am running antivirus I would advise you do the same. I did run antivirus on the file before opening it and it revealed no malware so that why I launched the fake jpeg. Ya think I would know better being in IT but guess I had a brain fart.

Edited by Marchese 1st MRB
Link to comment
Share on other sites

  • 0

SSgt. Grant seems to have been affected by this as well. If ANYONE sends you this message DO NOT CLICK ON IT!!!!!

Also post who you get these messages from, that way we can contact them on the forum about there compromised account.

Edited by Griswold 1st MRB
Link to comment
Share on other sites

  • 0
What if you clicked the link with your phone, but it didn't open the website because its not a real website or download anything.

I would say you would be good, probably built for a different operating system. But just make you pay attention to when/if you plug your phone into your computer next time. Make sure nothing fishy starts happening.

Link to comment
Share on other sites

  • 0

Anti-viruses work off of databases of "known" malware, that's why you need to update your protection so often, there are set definitions of viruses. In addition, it's using steam and your browser as a means to infect your computer, these are already "green-lit" by all your anti-virus programs. If it's new, it's not going to flag it as a known threat, this is where you, the user, needs to be diligent and check the source. Before I even clicked the link, I googled screen-picture or whatever the site hosting this "wtf dude" image. That's where I hit the "unknown site certificate" and pre-existing steam community posts results.

Google is your friend!

Link to comment
Share on other sites

  • 0

Smart people have already debugged the virus! In case anyone was curious:

The method form the code is thus..

Hook into steam,

steal cookies,

get auth token,

get friends list,

send all items etc as per line + (753:gift;570:rare,legendary,immortal,mythical,arcana,normal,unusual,ancient,too

l,key;440:unusual,hat,tool,key;730:tool,knife,pistol,smg,shotgun,rifle,sniper rifle,machinegun,sticker,key) ,

send message to all friends = ("WTF Dude? http://♥♥♥♥♥♥♥♥♥♥♥♥♥♥♥.com/DELETEDFORSAFTEY/")

Nothing thing else is mentioned in the code... Wanted to check to make sure it never got my password for steam..

Note* it uses the steamapi to send authenticated requests with the stolen cookies, for the trade transactions*

Well it steals the cookie which means the attacker can change the password on you in theory.

It's prudent to deauthorize your SteamGuard computers and change your password as a precaution.

Link to comment
Share on other sites

  • 0
Smart people have already debugged the virus! In case anyone was curious:

The method form the code is thus..

Hook into steam,

steal cookies,

get auth token,

get friends list,

send all items etc as per line + (753:gift;570:rare,legendary,immortal,mythical,arcana,normal,unusual,ancient,too

l,key;440:unusual,hat,tool,key;730:tool,knife,pistol,smg,shotgun,rifle,sniper rifle,machinegun,sticker,key) ,

send message to all friends = ("WTF Dude? http://♥♥♥♥♥♥♥♥♥♥♥♥♥♥♥.com/DELETEDFORSAFTEY/")

Nothing thing else is mentioned in the code... Wanted to check to make sure it never got my password for steam..

Note* it uses the steamapi to send authenticated requests with the stolen cookies, for the trade transactions*

Well it steals the cookie which means the attacker can change the password on you in theory.

It's prudent to deauthorize your SteamGuard computers and change your password as a precaution.

I was going to ask if someone could pm me the file url (or dropbox the file to me if the site has already been taken down) so that I could run it through IDA, but it looks like someone on the steam forums has already decompiled and analyzed it. I would still be interested in looking at it anyways, so if someone could hook me up with the file, that would be awesome.

Link to comment
Share on other sites

  • 0

Today i recieved a PM from a friend of mine, While i neglected to take a screenshot it read as "Hey, I want to trade with you! Check My trade inventory @ *Link Removed*" then he logged out" I wont post the link, But research done on it says its not a trusted site and is most likely a scam / Phisher link.

Link to comment
Share on other sites

  • 0
Why do people suck so bad?

Real question should be why did it take so long for someone to look for a way to do this to someone? Steam for a long time had been a really good platform, why steal someones digital shit?

Steam is just like any other digital platform, why did it take so long for viruses that specifically target Steam to come out?

Link to comment
Share on other sites

  • 0
Why do people suck so bad?

Real question should be why did it take so long for someone to look for a way to do this to someone? Steam for a long time had been a really good platform, why steal someones digital shit?

Steam is just like any other digital platform, why did it take so long for viruses that specifically target Steam to come out?

Hats.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Recent Posts

    • Name:  Brascal Steam I.D:  STEAM_0:1:11514748 Date & Time of ban: 01-23-16 15:32 Admin who banned you: Johnson 1st MRB   It has been years since of my ban and I would like to request the admins to take a second look of the ban. As Im not cheating and due the long years of competitive gaming. So please hopefully you could give me a second chance?
    • As we have discussed before your actions in the server and to our public community is not something we take lightly. As stated previously the ban stays. Sorry for any inconvenience this may cause you for the time being. Maybe later down the road (Not guaranteed) things can change but for now the ban will stay in place. Enjoy the rest of your evening. Signed, WO. S. Belcher  Platoon Commander, 1/A-CO
    • Name: Pfc. A. Sheffer |8th ID| Steam I.D: STEAM_0:0:57506334 b]Date & Time of ban:[/b] 04/10/2024 b]Admin who banned you:[/b] Unsure Reason we should Unban: I apologize for my actions on that day. It was a mistake and it will never happen again. I understand to respect all members on the server. This month has given me time to reflect upon my actions. I miss playing with everyone on the server and promise i will not make the same mistake twice. Thank you for your time and have a wonderful day.
    • 2nd Platoon Weekly Attendance   Week of 05MAY2024   P = Present | E = Excused | A = Absent   Platoon Staff WO. A. Pitteway - Present MSgt. J. Candy - Present TSgt. A. Yoder - Present   1st Squad Squad leader:  Cpl. R. Fielding - Present Cpl. B. Grande - Present Pfc. R. Smith - Present Pfc. X. Hocker - Present Pvt. B. Niles - Excused* Resigned Pvt. M. Noel - Present   2nd Squad Squad leader:  Cpl. C. Dilley - Present Cpl. H. Nielsen - Present Cpl. S. Holquist - Present Pfc. R. Mcspadden - Excused Pfc. T. Scary - Present Pfc. C. Marsh - Present Pvt. K. Bradley - Present   Reserves: Pvt. T. Mongillo - Excused, Pfc. M. Oake - Excused   Helpers: CWO. R. Martinez, Ret. G. Werner, GySgt. S. Larson   Attendance Policy    1. Each Week you must submit a TDR through Perscomm on the website before practice starts     2. If you do not submit a TDR you will get an Unexcused absence    3. Three (3) Unexcused absences in a row you receive an Infraction Report with a possible demerit with Command Staff approval.    4. Five (5) Unexcused absences in a row will result in being moved from Active duty to Reserves   If you need any assistance learning how to fill out a TDR contact your Squad Leader or your Platoon Sergeant.
    • Talking about identifying as a woman to get cheaper car insurance Small: Yeah we had that here but they banned it Pitteway: What? Woman driving? Everyone starts dying
×
×
  • Create New...