{"id":6360,"date":"2017-01-25T09:11:39","date_gmt":"2017-01-25T17:11:39","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/25\/news-198\/"},"modified":"2017-01-25T09:11:39","modified_gmt":"2017-01-25T17:11:39","slug":"news-198","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/01\/25\/news-198\/","title":{"rendered":"Avoid these &#8220;Free Minecraft \/ Garry&#8217;s Mod&#8221; adverts"},"content":{"rendered":"<p>Garry&#8217;s Mod is a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Garry's_Mod\" target=\"_blank\">sandbox physics game<\/a> which lets you manipulate ragdolls (effectively, static\u00a0video game characters) into certain\u00a0poses or player-made movies (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Machinima\" target=\"_blank\">Machinima<\/a>).<\/p>\n<p>If you were heavily into memes about 8 to 10 years ago, you probably saw no end of them\u00a0on <a href=\"https:\/\/en.wikipedia.org\/wiki\/YTMND\" target=\"_blank\">YTMND<\/a> created with it. However, we&#8217;re about to have the exact opposite of a wonderful time. I was browsing for mods on the popular modding site <a href=\"http:\/\/www.nexusmods.com\/games\/?\" target=\"_blank\">Nexus<\/a>\u00a0and happened to see an eye-catching advert:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/mod-advert.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16145\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/mod-advert-300x86.jpg\" alt=\"mod advert\" width=\"300\" height=\"86\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/mod-advert-300x86.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/mod-advert-600x172.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/mod-advert.jpg 763w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<blockquote>\n<p><em>&#8220;Free: Garry&#8217;s Mod. Play now!&#8221;<\/em><\/p>\n<\/blockquote>\n<p>Sounds too good to be true, especially as you need a Steam account to buy and play it. How can I get it for free?<\/p>\n<p>The answer, it turns out, is by being sent to the Chrome store via the ad. This looks emphatically like Garry&#8217;s Mod so far:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/garry-is-that-you.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16147\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/garry-is-that-you-300x271.jpg\" alt=\"garry is that you\" width=\"300\" height=\"271\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/garry-is-that-you-300x271.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/garry-is-that-you-600x541.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/garry-is-that-you.jpg 910w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>I mean, there&#8217;s zero ambiguity here. A huge picture of TF2 characters doing Garry&#8217;s Mod things, a massive GARRY&#8217;S MOD: PLAY slap bang in the middle of the screen. I am definitely, totally getting Garry&#8217;s Mod here, no doubt about it.<\/p>\n<p>I&#8217;d better read the small print before getting my Garry fill:<\/p>\n<blockquote>\n<p><em>By clicking start game to install kidsvideogame games, you hereby consent to the kidsvideogame games terms of use and privacy policy, and agree to allow the kidsvideogame games extension to serve you advertisements. All such ads are served to you while you surf the internet and are branded as kidsvideogame games ads. the kidsavideogame games extension does not collect any personally identifiable information.<\/em><\/p>\n<\/blockquote>\n<p>Well, uh&#8230;better have a look? My excitement for free Garry&#8217;s Mod action seems to have decreased by at least 3% but I&#8217;m sure everything will work out when I click the play bu-<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/installing-an-extension.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16148\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/installing-an-extension.jpg\" alt=\"\" width=\"462\" height=\"291\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/installing-an-extension.jpg 462w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/installing-an-extension-300x189.jpg 300w\" sizes=\"auto, (max-width: 462px) 100vw, 462px\" \/><\/a><\/p>\n<p>&#8230;.add Kids Videogame Advertising on the what now?<\/p>\n<blockquote>\n<p><em>* Read and change all your data on the websites you visit<\/em><br \/> <em>* Communicate with cooperating websites<\/em><br \/> <em>* Manage your downloads<\/em><\/p>\n<\/blockquote>\n<p>That&#8217;s certainly an odd name for a child-centric extension and not a Garry&#8217;s Mod in sight so far.<\/p>\n<p>Here&#8217;s the Chrome store page the extension is coming from:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/kida-video-game-advertising-extension.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16149\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/kida-video-game-advertising-extension-300x203.jpg\" alt=\"kida video game advertising extension\" width=\"300\" height=\"203\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/kida-video-game-advertising-extension-300x203.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/kida-video-game-advertising-extension-600x406.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/kida-video-game-advertising-extension.jpg 793w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<blockquote>\n<p><em>KidsVideoGame ad revenue is used to support the KidsVideoGame software. We server a fixed number of ads to our user per day and do not store any Personally Identifiable Information (PII). There are different types of ad units served by the KidsVideoGame software including new page, video ads, text link ads. We display a clear branding box along with uninstall instructions in the event that a user would like to uninstall or learn more about our advertisements.<\/em><\/p>\n<\/blockquote>\n<p>In terms of user functionality, the extension doesn&#8217;t actually let you do anything with it &#8211; it&#8217;s entirely grayed out, and we saw no adverts served during testing. At one point, we&#8217;d installed four of them simultaneously just to see if something might spur them into action but it wasn&#8217;t to be.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/grayed-out-1.jpg\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16167\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/grayed-out-1.jpg\" alt=\"not clickable\" width=\"159\" height=\"65\" \/><\/a><\/p>\n<p>I have to admit, I\u00a0was somewhat doubtful at this point that we&#8217;d be able to play a game which needs between 5 and 10GB of HDD space via a Chrome app but stranger things have happened at sea and all that. Ultimately, I detected a fatal lack of Garry, and indeed his mod, on the website kidsvideogame(dot)com which was\u00a0just a huge pile of browser-based flash games:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/videogame-site.jpg\" data-rel=\"lightbox-5\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16156\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/videogame-site-300x276.jpg\" alt=\"videogame site\" width=\"300\" height=\"276\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/videogame-site-300x276.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/videogame-site.jpg 596w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>No Garry, then, but plenty of related antics elsewhere to take a look at.<\/p>\n<p>For example, we have a &#8220;Play Minecraft for free&#8221; ad on a <a href=\"http:\/\/www.pcgamer.com\/deus-ex-human-revolution-review\/\" target=\"_blank\">Deus Ex<\/a> trailer, which is highly appropriate because I never asked for this:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/i-never-asked-for-this.jpg\" data-rel=\"lightbox-6\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16150\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/i-never-asked-for-this-300x221.jpg\" alt=\"I never asked for this\" width=\"300\" height=\"221\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/i-never-asked-for-this-300x221.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/i-never-asked-for-this-600x441.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/i-never-asked-for-this.jpg 834w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Looks familiar, right? Let&#8217;s open up the Chrome store again and we have thuggamerz(dot)com offering up a huge &#8220;Minecraft: play now&#8221; landing page and an extension called &#8220;Thug Gamerz Advertising&#8221;:<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/01\/avoid-these-free-minecraft-garrys-mod-adverts\/#gallery-16135-1-slideshow\">Click to view slideshow.<\/a> <\/p>\n<p>We&#8217;ve seen similar sites to the above and they seem to follow the same pattern &#8211; promote a cool &#8220;free&#8221; game via adverts, offer up an extension entirely unrelated to the game on display and then &#8211; depending on site &#8211; invite them to install and run an executable file (some simply stop at the extension. In terms of functionality, the extension doesn&#8217;t appear to do anything in terms of user interaction &#8211; it&#8217;s a grayed out icon on the Chrome taskbar).<\/p>\n<p>The Thuggamerz site offered up\u00a0an executable file immediately after installing the extension (unlike the site promoting free Garry&#8217;s Mod) called minecraft_download.exe (Gamisakiga setup). We detect this file as <a href=\"https:\/\/virustotal.com\/en\/file\/19fc2cd4b814056bed23dc11ef97eb84ae60aa33102b606376223279da403d31\/analysis\/1484838920\/\" target=\"_blank\">PUP.Optional.InstallCore<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/youre-almost-done.jpg\" data-rel=\"lightbox-7\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16155\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/youre-almost-done-300x201.jpg\" alt=\"you're almost done\" width=\"300\" height=\"201\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/youre-almost-done-300x201.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/youre-almost-done-600x401.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/youre-almost-done.jpg 1062w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/exe-download.jpg\" data-rel=\"lightbox-8\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16137\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/exe-download-283x300.jpg\" alt=\"exe download\" width=\"283\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/exe-download-283x300.jpg 283w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/exe-download.jpg 373w\" sizes=\"auto, (max-width: 283px) 100vw, 283px\" \/><\/a><\/p>\n<p>After running the file, we see the following splash screen, from a program called &#8220;Download Bureau&#8221; which says it&#8217;ll &#8220;download and install the software on the computer&#8221;:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/download-bureau-splash-screen.jpg\" data-rel=\"lightbox-9\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16140\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/download-bureau-splash-screen-300x234.jpg\" alt=\"download bureau splash screen\" width=\"300\" height=\"234\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/download-bureau-splash-screen-300x234.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/download-bureau-splash-screen-600x467.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/download-bureau-splash-screen.jpg 633w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The file in question is _minecraft_download.zip, weighing in at 1.86MB.<\/p>\n<p>If you&#8217;re thinking that sounds a little small for Minecraft, you&#8217;d be right. Before we get to the punchline, a 30 day trial for a PDF viewer is offered up as an optional download during the install process:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16138\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/pdf-trial-300x239.jpg\" alt=\"pdf trial\" width=\"300\" height=\"239\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/pdf-trial-300x239.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/pdf-trial-600x479.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/pdf-trial.jpg 639w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>As it turns out, that would actually be rather handy in this case as after all the hoops have been jumped, the extensions have been installed, the whirling collection of &#8220;Free Minecraft&#8221; banners have been clicked and the zip has been opened&#8230;<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/minecraft-zip.jpg\" data-rel=\"lightbox-10\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16141\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/minecraft-zip-300x209.jpg\" alt=\"minecraft zip\" width=\"300\" height=\"209\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/minecraft-zip-300x209.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/01\/minecraft-zip.jpg 354w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&#8230;the would-be player (who is probably a child eagerly awaiting Minecraft shaped goodness) is presented with nothing more than 2 PDF flyers advertising Minecraft and Minecraft Story mode.<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/01\/avoid-these-free-minecraft-garrys-mod-adverts\/#gallery-16135-2-slideshow\">Click to view slideshow.<\/a> <\/p>\n<p>Cue lots of screaming and parent reaching for the emergency earplugs.<\/p>\n<p>There is, unfortunately, no free game dancing to the tune promised by the various adverts and websites; after all that effort, being &#8220;rewarded&#8221; with two PDFs telling the person in front of the PC to effectively go to the official websites and buy the games could be considered a bit on the\u00a0underwhelming side of things. The sites we&#8217;ve seen so far which appear to be related to some or all of the above include\u00a0kidsvideogame(DOT)com, thuggamerz(DOT)com, bubblegif(DOT)com and gameshaunt(DOT)com and users of <a href=\"https:\/\/www.malwarebytes.com\/premium\/\" target=\"_blank\">Malwarebytes 3.0<\/a> will find we block these URLs. It&#8217;s possible there are others, so please advise your game-hungry children to be cautious around too good to be true freebies.<\/p>\n<p>And keep those earplugs handy&#8230;<\/p>\n<p>&nbsp;<\/p>\n<p><em>Christopher Boyd and Jovi Umawing<\/em><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/01\/avoid-these-free-minecraft-garrys-mod-adverts\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/01\/avoid-these-free-minecraft-garrys-mod-adverts\/' title='Avoid these \"Free Minecraft \/ Garry's Mod\" adverts'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2014\/10\/photodune-5889271-arcade-game-game-over-s.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>If you see ads claiming to offer up free games like Garry&#8217;s Mod or Minecraft, you may wish to think twice &#8211; you&#8217;ll definitely get an extension, you may receive an executable, but free Minecraft? Keep searching, intrepid gamer&#8230;<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/children\/\" rel=\"tag\">children<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/chrome\/\" rel=\"tag\">chrome<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/extensions\/\" rel=\"tag\">extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/games\/\" rel=\"tag\">games<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gaming\/\" rel=\"tag\">gaming<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/garrys-mod\/\" rel=\"tag\">garrys mod<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/minecraft\/\" rel=\"tag\">minecraft<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/01\/avoid-these-free-minecraft-garrys-mod-adverts\/' title='Avoid these \"Free Minecraft \/ Garry's Mod\" adverts'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[1962,10699,4503,11058,11059,1445,11060,10727,10510],"class_list":["post-6360","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-children","tag-chrome","tag-cybercrime","tag-extensions","tag-games","tag-gaming","tag-garrys-mod","tag-minecraft","tag-social-engineering"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6360"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6360\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}