Team Fortress 2

Team Fortress 2

802 人が評価
BE WARNED! New phishing bot method!
作者: ExDe707
Phishing bots have become agressive, and now can destroy your whole precious PC. Be warned about that, and DO NOT TRUST ANYONE GIVING YOU LINKS. Read more in this guide.
   
アワード
お気に入り
お気に入り
お気に入りから削除
Introduction
Now you might know this:

someone: hey my friend want add u but cant (steam error add him pls [LOLPHISH]
someone2: hey im really interested in ur items but got keys on my main ((: add my [LOLPHISH]

The [LOLPHISH] are links that look like the steam community one but are misspelt. Once you try to log in there, what you entered will be sent to the bot and he will use this information to go into your account and steal your valuable items, if there are any.

BUT, it's not harmless anyone like the above example. The phishing bots have developed another method which is WAY more agressive than the above examples:

agressor: Hi, I want swap this knife, Link to screenshot - [OMGPHISH]

The [OMGPHISH] link looks like a link to a picture sharing website. It is structured like that: picthingy(dot)numbers(dot)domain/img_numbersnumbers.png

HOWEVER: It does NOT lead to a picture or anything. More in the next section.
Where does that link lead?
So we have a new link, and we will examine it.
I will not openly share it to avoid too curious people on clicking on it. I'm dead serious about this.
Is it an image?
Well let's take a look at the image below. I used Web Sniffer for it, It's easy and reveals all details about the site, without visiting it.
Apart from some minor details like the IP of the website, it's host etc. It also reveals if it redirects to any other website. I marked the link with a red outline.
Do you recognize that? It's a direct Google Drive download link. The &confirm=no_antivirus part is where it does NOT give you a warning when you download the file. So it's not an image. But what is the file like?
The script of death
Here I used Virustotal to examine the file. I did this by visiting Virustotal, checking the URL Web Sniffer revealed me and then letting it check the file.
The results are as I expected. 18 smart Antivirus companies have reported the file as a trojan virus.
A trojan virus is like a romanian one. It's sturdy, and once it arrived at it's goal, the computer, it releases it's soldiers, the viruses.
The .scr file extension relates to "Script". It is mainly used for Screensavers, but it's one of the most abused files on any Windows OS, as it easily carries trojans. Once it's done downloading, it will wreak havoc in your PC.
I downloaded it.
Okay you're pretty much screwed right now unless you have a good Antivirus like I do (AVG 2014). If your antivirus does not immedietally recognize the virus, start a full scan of your computer as soon as possible.
My antivirus failed. What happens now?
Now? All your passwords and precious data will be stolen, mainly the steam login informations through brute force. It has the same effect as the old add my friend phish, the bot goes into your account and steals your items.
What can I do against that?
There are many things to do. I'll make a list of what you can do to protect yourself.
  • Do not click on any links. None. Absolutely. If one of your friends asks you to watch a video or something, ask them to give informations about the video so you can search it for yourself on youtube. If you do want to click on links check if they are safe with the methods I used above.
  • As a trader, if you use sites like TF2 Outpost or Bazaar.tf, inform your customers to use trade offers instead of friend adds. If someone adds you, ignore or block them. If a suspicious, dumb looking trade offer appears, report and decline it.
  • If you DO want to accept friend requests, then see if the profile is private, or if it even has the game to trade stuff for. If the profile is private, level 0 or 1, or if it doesn't have said game, ignore it.
  • You might accept a friend request from a safe looking person with a high level. If he sends you the phishing messages, then It's a victim of a phishing bot. Simply unadd him. Don't block him, as he might be a future customer.
  • It is in most cases safe to add people currently playing a game, as bots often do not play games when active. This might change in the future.
  • If you notice that you lost some items, contact Steam Support immedietally.
  • Change your password, your E-Mail, whatever, if you find out you clicked on a phishing link.
  • Always be aware of phishers.
Now they might be obvious and stuff you would do, I advise you to ALWAYS do these.
BONUS: Trolling human phishers.
Thanks for spreading this so far! I didn't really expect this to pop up in the front page of TF2 guides. And recieving an over 50 new comments notification spam.

Thus I'm sharing a well-known method of effectively using the dumbness of human phishers to get items for absolutely free. He has to be human though. It works mostly with the "add my friend" phish.
Here is the link: http://forums.backpack.tf/index.php?/topic/16506-guide-how-to-profit-from-phishers/
And if you don't trust it, check it with the methods above. I take no credit for it.
Conclusion & Feedback
tl;dr Bots use a new method, one click means death.

Feedback about this guide is appreciated. Share this to everyone you know, as it might hit them very hard.

Stay safe!
-Ex
Frequently asked questions (FAQ)
Allright, now I'm getting a handful of friend requests from thankful people. It's nice but y'know, there's a limit in my friends list. So I made this FAQ section to answer the most common questions.

Q: I clicked on a suspicious link but it didn't download anything, am I still safe?
A: I can't really tell, as there's something called browser exploits. Websites can be created in ways to abuse your internet browser features, e.g. Drive-by downloads. Google that if you don't know what that is.
Q: I downloaded something like "steam guard.exe" or "1231sy1sa.scr but deleted it quickly, am I safe?
A: I doubt you really are if you executed the files without your antivirus stopping them. .scr files however execute themselves after they dropped on your PC and do their job instantly. You better run a full computer scan after that, change your password and/ or change your E-Mail. And, most importantly, contact Steam Support within 8 days so they can further secure your account.
Q: OMG ur mah h3ruh pls can w b frwiends 4eva?????
A: You better thank me in the comments section instead of adding me. As I said before my friends list is filling. I appreciate that but don't push it too far.
Q: Can I donate you an item as a thank you?
A: ( ͡o ͜ʖ ͡o)
Q: AVG? Good antivirus? topkek lol no
A: lol yes. Google them rewards.
669 件のコメント
Go4Pro 2019年3月15日 4時50分 
sorry friend but i have to tell you something. i have seen from alot of bots that i purchased items from onbackpack.tf were infact in games. i think those official valve servers where u join and get instantly vote kicked are where these bots hang out. maybe they recognize eachother because theire from the same bot network.
yaha 2018年12月28日 15時07分 
Lol some guy tried to shark me out of an unusual
Adam [CZ] 2018年12月12日 19時22分 
Very aggresive bot!!!
Castle 2018年11月5日 14時21分 
hey so I clicked a link which I think is fucking up my trades now cuz every time I offer a trade to someone it removes the items I want from the person and it makes it a gift from me to the person
weedmancer lol 2018年3月21日 17時41分 
Question, I had a old friend for about 2 months now and he sent me a phishing link (OF COURSE I DIDNT CLICK IT) but before he wasn’t much of a bot (actually played the ga:steamsad:me and had a good inventory) but now he’s a bit, did he get hacked? Pls help
FunnyBunny 2017年12月21日 15時28分 
{リンクが削除されました}

laxative pilled shitmaxxer 2017年12月17日 12時14分 
Tips; "Dont click links from anyone". Gives a link.

Thus I'm sharing a well-known method of effectively using the dumbness of human phishers to get items for absolutely free. He has to be human though. It works mostly with the "add my friend" phish.
Here is the link: http://forums.backpack.tf/index.php?/topic/16506-guide-how-to-profit-from-phishers/
And if you don't trust it, check it with the methods above. I take no credit for it.
PureGothard 2016年11月24日 10時06分 
its says a gzip file is that bad
Mattaladøn 2016年11月1日 8時57分 
Is item.exchange safe?
Cöque 2016年8月28日 19時34分 
YEAH BOYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY