Jump to content

Lately I received messages on Whatsapp proposing a job.

So I smelled scam but wen't along for a ride.

Long story short, they had me register on a company website and enter a referal code. I did that on my desktop.

Then I confirmed the register via Whatsapp, she asked me for a screenshot, which seemed weird.

Then she asked me the code generated from the website, which I refused to give via Whatsapp.

End of story. Two days ago.

 

Today I got a message from Facebook "Somebody might have had access..."

I don't know if those 2 events are related.

I followed the Facebook recommandations and nothing suspicious came up.

 

What do you think ?

If my desktop is compromised what can I do ?

Thanks,

 

Edit: I did a quick search on internet : It seems that scam was to make me send money rather than to "misuse" my system

Edited by leclod

If you don't quote us, we won't know you answered

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/
Share on other sites

Link to post
Share on other sites

55 minutes ago, leclod said:

So I smelled scam but wen't along for a ride.

Why? You have nothing to win in such a situation. If something seems suspicious, just don't engage at all.

 

52 minutes ago, leclod said:

I followed the Facebook recommandations and nothing suspicious came up.

I would change my password regardless, just to be on the safe side. And, if you haven't already, enable 2FA.

 

53 minutes ago, leclod said:

If my desktop is compromised what can I do?

If you know it to be compromised, nuke and reinstall, with an installation media created on a known good machine. Of course that might be a bit drastic, maybe run a malware scan with something like Malwarebytes first. Though simply visiting a website should typically not pose much of a risk, provided your system and browser are up-to-date.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176535
Share on other sites

Link to post
Share on other sites

34 minutes ago, Eigenvektor said:

Why? You have nothing to win in such a situation.

I didn't know it yet. Don't you ever take a risk ?

35 minutes ago, Eigenvektor said:

I would change my password regardless, just to be on the safe side. And, if you haven't already, enable 2FA.

I could do that, but which wasspords ? all of them ?

35 minutes ago, Eigenvektor said:

If you know it to be compromised, nuke and reinstall, with an installation media created on a known good machine.

Not there yet.

36 minutes ago, Eigenvektor said:

provided your system and browser are up-to-date.

I'm very up-to-date

If you don't quote us, we won't know you answered

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176553
Share on other sites

Link to post
Share on other sites

5 minutes ago, leclod said:

I didn't know it yet. Don't you ever take a risk?

Sure. But there's a difference between a calculated risk and an unnecessary risk. If someone contacts me out of the blue with a job offer… yeah, no.

 

At the very least I'd take some precautions like opening their website inside a virtual machine, using a non-Windows OS to reduce the risk of being compromised and the amount of damage it can do.

 

8 minutes ago, leclod said:

I could do that, but which wasspords ? all of them ?

Facebook and Whatapp. Unless you used something else you didn't mention?

 

10 minutes ago, leclod said:

I'm very up-to-date

Then at the very least use something like Malwarebytes to scan your system for known threats.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176566
Share on other sites

Link to post
Share on other sites

2 hours ago, leclod said:

they had me register on a company website

What details did it have you give? That could have allowed them to search for your FB profile.

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176585
Share on other sites

Link to post
Share on other sites

16 minutes ago, Eigenvektor said:

Facebook and Whatapp. Unless you used something else you didn't mention?

I didn't use Facebook

 

17 minutes ago, Eigenvektor said:

Then at the very least use something like Malwarebytes to scan your system for known threats.

Just installed it

If you don't quote us, we won't know you answered

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176586
Share on other sites

Link to post
Share on other sites

23 minutes ago, Eigenvektor said:

Then at the very least use something like Malwarebytes to scan your system for known threats.

Just ran a scan, quarantined 2 files. But I doubt it had to do with the "scam"

If you don't quote us, we won't know you answered

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176598
Share on other sites

Link to post
Share on other sites

11 minutes ago, leclod said:

I didn't use Facebook

As you said, you received a (probably unrelated) message from Facebook about suspicious activity. Even if unrelated to the scam attempt, I'd still change my password there, just to be on the safe side.

 

6 minutes ago, leclod said:

Just ran a scan, quarantined 2 files. But I doubt it had to do with the "scam"

True. As I said, visiting their site to enter a number is unlikely to pose much of a risk. Doesn't mean you couldn't have gotten malware from some other source at the same time.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16176612
Share on other sites

Link to post
Share on other sites

Possibly, if you created a password when you registered on their website, they may have tried to log into your FaceBook using the that password. Even now, lots of people just keep reusing the same passwords everywhere so they try to get that and log in to different websites to see if they get a match.

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16177285
Share on other sites

Link to post
Share on other sites

6 hours ago, TheGreatestGazoo said:

Possibly, if you created a password when you registered on their website, they may have tried to log into your FaceBook using the that password. Even now, lots of people just keep reusing the same passwords everywhere so they try to get that and log in to different websites to see if they get a match.

Nope, not guilty.

I did create an original password.

Good idea though.

Edit : ok, "they may have tried to log into your FaceBook" indeed !

Edited by leclod

If you don't quote us, we won't know you answered

Link to comment
https://linustechtips.com/topic/1536975-scamsecurity/#findComment-16177449
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×