Avoid these “Free Minecraft / Garry’s Mod” adverts

Garry’s Mod is a sandbox physics game which lets you manipulate ragdolls (effectively, static video game characters) into certain poses or player-made movies (Machinima).

If you were heavily into memes about 8 to 10 years ago, you probably saw no end of them on YTMND created with it. However, we’re about to have the exact opposite of a wonderful time. I was browsing for mods on the popular modding site Nexus and happened to see an eye-catching advert:

mod advert

“Free: Garry’s Mod. Play now!”

Sounds too good to be true, especially as you need a Steam account to buy and play it. How can I get it for free?

The answer, it turns out, is by being sent to the Chrome store via the ad. This looks emphatically like Garry’s Mod so far:

garry is that you

I mean, there’s zero ambiguity here. A huge picture of TF2 characters doing Garry’s Mod things, a massive GARRY’S MOD: PLAY slap bang in the middle of the screen. I am definitely, totally getting Garry’s Mod here, no doubt about it.

I’d better read the small print before getting my Garry fill:

By clicking start game to install kidsvideogame games, you hereby consent to the kidsvideogame games terms of use and privacy policy, and agree to allow the kidsvideogame games extension to serve you advertisements. All such ads are served to you while you surf the internet and are branded as kidsvideogame games ads. the kidsavideogame games extension does not collect any personally identifiable information.

Well, uh…better have a look? My excitement for free Garry’s Mod action seems to have decreased by at least 3% but I’m sure everything will work out when I click the play bu-

….add Kids Videogame Advertising on the what now?

* Read and change all your data on the websites you visit
* Communicate with cooperating websites
* Manage your downloads

That’s certainly an odd name for a child-centric extension and not a Garry’s Mod in sight so far.

Here’s the Chrome store page the extension is coming from:

kida video game advertising extension

 

KidsVideoGame ad revenue is used to support the KidsVideoGame software. We server a fixed number of ads to our user per day and do not store any Personally Identifiable Information (PII). There are different types of ad units served by the KidsVideoGame software including new page, video ads, text link ads. We display a clear branding box along with uninstall instructions in the event that a user would like to uninstall or learn more about our advertisements.

In terms of user functionality, the extension doesn’t actually let you do anything with it – it’s entirely grayed out, and we saw no adverts served during testing. At one point, we’d installed four of them simultaneously just to see if something might spur them into action but it wasn’t to be.

not clickable

I have to admit, I was somewhat doubtful at this point that we’d be able to play a game which needs between 5 and 10GB of HDD space via a Chrome app but stranger things have happened at sea and all that. Ultimately, I detected a fatal lack of Garry, and indeed his mod, on the website kidsvideogame(dot)com which was just a huge pile of browser-based flash games:

videogame site

No Garry, then, but plenty of related antics elsewhere to take a look at.

For example, we have a “Play Minecraft for free” ad on a Deus Ex trailer, which is highly appropriate because I never asked for this:

I never asked for this

Looks familiar, right? Let’s open up the Chrome store again and we have thuggamerz(dot)com offering up a huge “Minecraft: play now” landing page and an extension called “Thug Gamerz Advertising”:

Click to view slideshow.

We’ve seen similar sites to the above and they seem to follow the same pattern – promote a cool “free” game via adverts, offer up an extension entirely unrelated to the game on display and then – depending on site – invite them to install and run an executable file (some simply stop at the extension. In terms of functionality, the extension doesn’t appear to do anything in terms of user interaction – it’s a grayed out icon on the Chrome taskbar).

The Thuggamerz site offered up an executable file immediately after installing the extension (unlike the site promoting free Garry’s Mod) called minecraft_download.exe (Gamisakiga setup). We detect this file as PUP.Optional.InstallCore.

you're almost done

exe download

After running the file, we see the following splash screen, from a program called “Download Bureau” which says it’ll “download and install the software on the computer”:

download bureau splash screen

The file in question is _minecraft_download.zip, weighing in at 1.86MB.

If you’re thinking that sounds a little small for Minecraft, you’d be right. Before we get to the punchline, a 30 day trial for a PDF viewer is offered up as an optional download during the install process:

pdf trial

As it turns out, that would actually be rather handy in this case as after all the hoops have been jumped, the extensions have been installed, the whirling collection of “Free Minecraft” banners have been clicked and the zip has been opened…

minecraft zip

…the would-be player (who is probably a child eagerly awaiting Minecraft shaped goodness) is presented with nothing more than 2 PDF flyers advertising Minecraft and Minecraft Story mode.

Click to view slideshow.

Cue lots of screaming and parent reaching for the emergency earplugs.

There is, unfortunately, no free game dancing to the tune promised by the various adverts and websites; after all that effort, being “rewarded” with two PDFs telling the person in front of the PC to effectively go to the official websites and buy the games could be considered a bit on the underwhelming side of things. The sites we’ve seen so far which appear to be related to some or all of the above include kidsvideogame(DOT)com, thuggamerz(DOT)com, bubblegif(DOT)com and gameshaunt(DOT)com and users of Malwarebytes 3.0 will find we block these URLs. It’s possible there are others, so please advise your game-hungry children to be cautious around too good to be true freebies.

And keep those earplugs handy…

 

Christopher Boyd and Jovi Umawing

https://blog.malwarebytes.com/feed/