1. SteamRep is shutting down at the end of 2024. See announcement.

Pending Report: 76561198041867794 - ([TF2] Team Fortress 2 Items)

Discussion in 'Pre-2017 Reports' started by advicebanana, Oct 28, 2014.

  1. advicebanana

    advicebanana SteamRep Moderator Friend Community

    Messages:
    1,076
    Steam:
    STEAM_0:1:11522747
    Scam Report

    Report Type: [Accomplice] Alternate account of hijacker or scammer
    Virtual item type involved: [TF2] Team Fortress 2 Items

    Accused profile: 76561198041867794

    Victim profile: 76561197983311223

    What happened? Description:
    I was in the TF2 group chat room when I saw someone spamming this:
    I've left the link since fortunately it does not work.
    Being interested, I PMd the person and asked about. When I voiced my disbelief, they suddenly produce a very expensive CSGO knife as evidence that they can really create free money, this one: http://www.tf2outpost.com/item/730,845032003,508,3
    It looks like he traded it from the second account I linked to.
    Shortly after, he traded another knife to his account and later back to his main, a ★ Karambit | Stained (FT): http://www.tf2outpost.com/item/730,845032017,507,3

    When I mentioned that he has only crap in his account, he added me with his main and continued to convince me to run his malware.
    Why do I even bother posting about this?
    This is a human, not some spam bot.​

    Provide Evidence:
    History of ★ M9 Bayonet | Fade (FN) with both the scammer's accounts in it: http://www.tf2outpost.com/item/730,845032003,508,3

    Screenshots of chat and alt account's inventories are attached. I also attached the CSGO inventory of the scammer's main account in json format.
    The screenshots of his account page are in Swedish which might point to his location.

    This message on his profile might mean that he bought it or hijacked it:
    Analysis of the binary the person linked to:
    https://malwr.com/analysis/MWQwMTA1Mzc4YWU5NDkzOWIzZmE1MDk5NDA3MzhlOWI/
    https://www.virustotal.com/en/file/...b3313d8548fc9e810aa914f32c8cf7ed81b/analysis/

    Proof that the Dropbox link he gave me actually led to this file:
    https://www.virustotal.com/en/url/3...cd2fb34b2c6041458363f076/analysis/1414514557/

    I can provide the malware if need be. I won't add it here.​

    Attached Files: