{"id":7191,"date":"2017-03-31T08:10:03","date_gmt":"2017-03-31T16:10:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/31\/news-982\/"},"modified":"2017-03-31T08:10:03","modified_gmt":"2017-03-31T16:10:03","slug":"news-982","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/31\/news-982\/","title":{"rendered":"Steam spammers have a night at the movies"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 31 Mar 2017 15:00:17 +0000<\/strong><\/p>\n<p>Users of gaming platform <a href=\"http:\/\/store.steampowered.com\/\" target=\"_blank\">Steam<\/a>\u00a0have the ability to upload images from games, post messages, and more besides, into their social network stream. They also have the option\u00a0to <a href=\"https:\/\/support.steampowered.com\/kb_article.php?ref=4506-DGHX-5190\" target=\"_blank\">upload game-related artwork<\/a>. Spammers occasionally make use of this feature to sling some spam at the gaming masses.<\/p>\n<p>We&#8217;ve spotted one such example in the wild, in the form of a profile claiming to be IMDB offering up free movies. Below you can see they&#8217;ve uploaded six decidedly non-game related images, all of which claim a movie is but a click away.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-steam.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17086 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-steam-600x486.jpg\" alt=\"movie spam on steam\" width=\"600\" height=\"486\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-steam-600x486.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-steam-300x243.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-steam.jpg 871w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>There&#8217;s also some spam text accompanying the various pictures in an attempt to gain some search engine juice and also to provide a link for would-be movie watchers to click on.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-image.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17088 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-image-600x578.jpg\" alt=\"movie spam image\" width=\"600\" height=\"578\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-image-600x578.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-image-300x289.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-image.jpg 786w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Some of the links are in the flavor text, a few are only viewable if you enlarge the image, and more still are posted as standalone comments underneath the original picture.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-open-image-to-see-link.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17091 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-open-image-to-see-link-600x296.jpg\" alt=\"movie spam\" width=\"600\" height=\"296\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-open-image-to-see-link-600x296.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-open-image-to-see-link-300x148.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-open-image-to-see-link.jpg 627w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-comment.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-17092\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-comment.jpg\" alt=\"movie spam comment\" width=\"692\" height=\"72\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-comment.jpg 692w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-comment-300x31.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-comment-600x62.jpg 600w\" sizes=\"auto, (max-width: 692px) 100vw, 692px\" \/><\/a><\/p>\n<p>As for where they go, it&#8217;s worth noting that Steam&#8217;s link filter will warn people that they&#8217;re about to move away from Steam (generally, this is there to try and help deter phishing but also serves as fair warning for any other scam you can think of).<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-steam-warning.jpg\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17093 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-steam-warning.jpg\" alt=\"movie spam steam warning\" width=\"574\" height=\"585\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-steam-warning.jpg 574w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-steam-warning-294x300.jpg 294w\" sizes=\"auto, (max-width: 574px) 100vw, 574px\" \/><\/a><\/p>\n<p>Should they continue on with their journey, they&#8217;ll end up in a variety of locations.<\/p>\n<p>We looked at three links, which were:<\/p>\n<p style=\"padding-left: 30px\"><em>movies.putlockervideos(dot)com\/movie\/127380\/finding-dory(dot)<\/em>html<br \/> <em>free-movies-streaming(dot)com\/movie\/321612\/beauty-and-the-beast(dot)<\/em>html<br \/> watchstv<em>(dot)<\/em>xyz<em>\/?do=play&amp;id=65854-3-3-60-Days-In-Watch-Online-Series<\/em><\/p>\n<p>Of the three links, all of them initially land on a &#8220;Watch this movie&#8221; page with what appears to be a movie player embedded\u00a0and various pieces of movie-related text scattered about the place.<\/p>\n<p>After that, though:<\/p>\n<p>1.\u00a0One of our links took us to a survey page, which asks the visitor to fill in personal info on offers in return for &#8220;something&#8221;. It&#8217;s fair to say we&#8217;d be very cautious about doing this, as more often than not you never receive the desired prize(s) after handing over a bunch of PII.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-survey.jpg\" data-rel=\"lightbox-5\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17094 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-survey-600x309.jpg\" alt=\"movie survey spam\" width=\"600\" height=\"309\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-survey-600x309.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-survey-300x154.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-on-survey.jpg 1115w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>2.\u00a0Another link took us to a movie site which says &#8220;sign up for free&#8221;, but also wants you to pay a monthly billing fee to continue membership (we looked at the Terms &amp; Conditions, but we couldn&#8217;t pin down an exact number).<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-beast-sign-up-link.jpg\" data-rel=\"lightbox-6\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17098 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-beast-sign-up-link-600x322.jpg\" alt=\"movie spam sign up link\" width=\"600\" height=\"322\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-beast-sign-up-link-600x322.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-beast-sign-up-link-300x161.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-beast-sign-up-link.jpg 914w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-sign-up-via-steam.jpg\" data-rel=\"lightbox-7\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17099 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-sign-up-via-steam-462x600.jpg\" alt=\"movie site sign up via steam\" width=\"462\" height=\"600\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-sign-up-via-steam-462x600.jpg 462w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-sign-up-via-steam-231x300.jpg 231w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-sign-up-via-steam.jpg 622w\" sizes=\"auto, (max-width: 462px) 100vw, 462px\" \/><\/a><\/p>\n<p>3.\u00a0Possibly the worst of the bunch, this one suggests Finding Dory is available to watch.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/dory-spam.jpg\" data-rel=\"lightbox-8\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17100 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/dory-spam.jpg\" alt=\"dory spam\" width=\"539\" height=\"523\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/dory-spam.jpg 539w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/dory-spam-300x291.jpg 300w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/a><\/p>\n<p>Clicking the box, however, takes visitors\u00a0to an Ad rotator URL which drops us off at a variety of non-child friendly links. Various adult webcams, surveys, and related sites all lie in wait.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-webcam.jpg\" data-rel=\"lightbox-9\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17101 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-webcam-445x600.jpg\" alt=\"movie spam webcam\" width=\"445\" height=\"600\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-webcam-445x600.jpg 445w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-webcam-222x300.jpg 222w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-spam-webcam.jpg 689w\" sizes=\"auto, (max-width: 445px) 100vw, 445px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-2.jpg\" data-rel=\"lightbox-10\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17102 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-2-600x471.jpg\" alt=\"Outdated Flash popup\" width=\"600\" height=\"471\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-2-600x471.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-2-300x235.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-2.jpg 617w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater.jpg\" data-rel=\"lightbox-11\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17103 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-600x542.jpg\" alt=\"webcam site\" width=\"600\" height=\"542\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-600x542.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater-300x271.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/movie-webcam-rotater.jpg 793w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>So, you know, whoops.<\/p>\n<p>Accounts such as the one pushing the above links tend to get deleted or cleaned up (if it&#8217;s been hijacked) fairly quickly. Don&#8217;t make life easier for the spammers &#8211; ignore all of their attempts to give you a night at the movies and report them to Steam. With any luck, they&#8217;ll be\u00a0ejected from the cinema before the trailers are over.<\/p>\n<p>&nbsp;<\/p>\n<p><em>Christopher Boyd<\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/\">Steam spammers have a night at the movies<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 31 Mar 2017 15:00:17 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/' title='Steam spammers have a night at the movies'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/popcorn-movie-party-entertainment_small.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We take a look at a spammer pushing what are claimed to be free movies on Steam&#8217;s videogame artwork section. Spoiler: they&#8217;re not movies, and you may want to get a refund for those tickets.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/faker\/\" rel=\"tag\">faker<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/imdb\/\" rel=\"tag\">IMDB<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/movie\/\" rel=\"tag\">movie<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/steam\/\" rel=\"tag\">steam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/survey\/\" rel=\"tag\">survey<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/surveys\/\" rel=\"tag\">surveys<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/webcams\/\" rel=\"tag\">webcams<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/' title='Steam spammers have a night at the movies'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/\">Steam spammers have a night at the movies<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,11834,11835,1449,3924,10510,10518,11227,887,11836,11837],"class_list":["post-7191","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-faker","tag-imdb","tag-movie","tag-phishing","tag-social-engineering","tag-spam","tag-steam","tag-survey","tag-surveys","tag-webcams"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7191"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7191\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7191"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}