1. SteamRep is shutting down at the end of 2024. See announcement.

Accepted 76561198050747310 ( Gitler )

Discussion in 'Archived Reports' started by ›Segata_Sanshiro, Sep 13, 2012.

  1. ›Segata_Sanshiro

    ›Segata_Sanshiro New User

    Messages:
    6
    Steam:
    STEAM_0:1:18164691
    Victim:
    steamID: › Segata_Sanshiro|Backpack.tf
    steamID32: STEAM_0:1:18164691
    steamID64: http://steamcommunity.com/profiles/76561197996595111
    customURL: http://steamcommunity.com/id/Segata_Sanshiro
    steamrepURL: http://steamrep.com/profiles/76561197996595111

    Scammer:
    steamID: Gitler
    steamID32: STEAM_0:0:45240791
    steamID64: http://steamcommunity.com/profiles/76561198050747310
    customURL: http://steamcommunity.com/id/stalinkaput
    steamrepURL: http://steamrep.com/profiles/76561198050747310

    Screenshots:
    - Pictures of chat (required) <attached. includes the file in the bottom left of my browser>


    Description: This person added me on steam after I posted I was selling a Vintage Lugermorph on outpost and tf2tp. He added me and linked me a very strange URL with the word download in it, telling me to click it and look at it cus its a screenshot of 3 seperate offers on a different account or something like that. I have been scammed many times in my youth and took classes on Social Engineering and stuff so I immediatly assumed he wanted to put a trojan on my computer to steal my steam account information or something like that.... I reluctantly clicked the link and immediately it downloaded a file called item_list.exe with a little blue icon i have never seen. I obviously did not open the file but I could only assume if I did open it, my computer would immediately BSOD... heh. He claimed to be a 13 year old when I said he was probably a social engineer.... THEY ALL DO!
    Anyway... I might have over reacted on him but i don't take kindly to cyber criminals of that line of work.



    He has yet to remove me from his friends list at this point and time.

    Attached Files:

  2. Casty

    Casty New User

    Messages:
    1
    Steam:
    STEAM_0:0:38473841
    Victim:
    steamID: [CST] Casty
    steamID32: STEAM_0:0:38473841
    steamID64: http://steamcommunity.com/profiles/76561198037213410
    customURL: http://steamcommunity.com/id/blazemastery
    steamrepURL: http://steamrep.com/profiles/76561198037213410

    Scammer:
    steamID: Gitler
    steamID32: STEAM_0:0:45240791
    steamID64: http://steamcommunity.com/profiles/76561198050747310
    customURL: http://steamcommunity.com/id/stalinkaput
    steamrepURL: http://steamrep.com/profiles/76561198050747310

    Description:
    Put up a trade of a Stormy Drills, this guy adds me. I check his inventory before adding him, and find he's f2p with 75 hours logged into tf2.
    After adding him, he posts a similar link to a suspected virus. (I later run it in a sandbox environment and confirm it's a trojan injector written
    2 weeks ago on 29 August in MSIL) He tries to perform social engineering as the person above said, this time he claims he's 14. Guess this concludes that.


    He has yet to respond, but he's currently still on my friends' list.
    The injector can be found here: (I reuploaded it)
    http://www.MALWARE-SUSPECTED-mediafire-.com/?ktt3yrilba9nz86
    And here is a virustotal scan showing proof of its illegitimacy:
    https://www.virustotal.com/file/443...311a11d5ceb3c318c6c3bcaa/analysis/1347644590/

    Attached Files:

    dawo5010 likes this.
  3. Bacon

    Bacon Retired Staff Partner Community

    Messages:
    749
    Steam:
    STEAM_0:0:28694608
    Thank you for your report. A steamrep admin will look at this shortly.
  4. CanadianInvasion

    CanadianInvasion Retired Staff

    Messages:
    2,389
    Steam:
    STEAM_0:1:11860924
    Tagged. Thanks for the report.