AmberCutie's Forum
An adult community for cam models and members to discuss all the things!

MFC models be very cautious of Links in PM/Mail !!

  • ** WARNING - ACF CONTAINS ADULT CONTENT **
    Only persons aged 18 or over may read or post to the forums, without regard to whether an adult actually owns the registration or parental/guardian permission. AmberCutie's Forum (ACF) is for use by adults only and contains adult content. By continuing to use this site you are confirming that you are at least 18 years of age.
Status
Not open for further replies.
Oct 11, 2013
130
141
73
So i was watching a MFC model, and she mentioned in public chat that someone send her a link in PM and said that they had recorded her.
She said that she opened the link and something started downloading, i quickly told her to STOP the download !

So i got her to message me the username and the link of the person who send her it.

The username was - amelyie
and the link was - www.tiny.cc / recordcams

** SHORT VERSION **
Turns out the link is to a website, that automatically downloads a file called video.rar which contains a file called video.msi, which is an installer for LogMeIn, LogMeIn is a program used for Remote administration. e.g. if you want to fix someones computer/laptop but they live miles away, you can use this tool to connect to their computer and then control their computer from yours. Typically the user must install it on their computer before you can do this, but there is installers which will silently install it in the background without the user having to go through the installation. Which is what happens in this case.
Whenever it is opened, it is secretly installed, and auto connects to the person who wants to control the model's pc.


** Time to investigate ** :evil:

the link is a shortened link, which they have used to hide the real link and to try and make things more convincing, e.g. they have chosen to make the shortened link recordcams
to try and make the model curious as to whether they really have been recorded or not.
Using a website called http://www.getlinkinfo.com, we can enter the link and find out that the original link is http://www. radyonisan .com/video.rar
It seems to be some random indian website, looks like someone made it themselves, very amateur looking. ( Don't go to it )

So anyway if you opened the tiny.cc link, the sceenshot below is what you will see, a blank page and the video.rar file will automatically start downloading, this is what is known as a drive-by download.
You are not asked if you want to down the file or anything, no popups or messages are shown either.
So this file is a rar file, definitely not a video file :naughty: most people will now just delete the file, but for those still curious, they will extract the contents of the rar file, and if we do, we can see we get a file called video.msi This is not a video file either but as you can see from the explorer window, it is an installer for something !! :snooty:
jtY6JE7l.png


If we open the video.msi file, we get a weird message, and at the top we see LogMeIn, BINGO !!!
And using a program for looking at running program, i can see that the program opened is called msiexec.exe ( often installers are called this)
LogMeIn is a program used for Remote administration. e.g. if you want to fix someones computer/laptop but they live miles away, you can use this tool to connect to their computer and then control their computer from yours.
c3toZJ7l.png


So we close the popup message or hit ok like a normal user would do, and everything seems normal, There is nothing oncreen, nothing in the windows list, or in the tray down to the right of the desktop. So are we OK ? :think:

Eventually after a couple of minutes, we are asked to run the video.msi again but this time with administrator rights, ( this allows the installer to install stuff and do more things to the computer)
So we accept and still nothing is shown onscreen :think:
** Users who aren't tech savvy or nerdy lol , will probably just assume everything is OK and just go about using their computer like they usually would.

If i look at the connections to and from the computer, i can see a process called LogMeIn and it is connected !!!
My test computer is Test-PC and it is connected to a LogMeIn server. Meaning i am now connected to the LogMeIn service, allowing the person who created the video.msi the ability to connect to my computer if they want to !!.
FCRNqx2l.png


I only stayed connected for a couple minutes, before resetting everything before i ran the video.msi file.
But i am guessing that whoever is on the other site of the connection could now control my pc if they wanted to.
Also they could now send files to my computer without me knowing of course,
these files could be viruses, keyloggers for logging what i type, password stealers for stealing passwords stored in Browsers and they can also send files from my pc to theirs.

** Most models & users will be aware not to open links that look suspicious, but there are those who won't be, and when someone posts a link like this, it can be very easy to fall for it out of curiosity.
So please be careful ladies and make other models aware of this :)
 
I would appreciate if those who read this made other models aware, e.g. tweet a link to this post.

The amount of scammers on MFC and other cam sites is crazy, but sadly, it is hard to stop and some new models especially
can easily fall for them.

Note - Your antivirus / security software, won't detect this because to it, nothing malicious is happening.

It just thinks someone is connecting to your computer to help you, like any normal user of LogMeIn or any other remote adminstration tool ( like teamviewer) would do.
 
Wait a minute here. Are you folks saying that links sent by random people are no longer to be clicked on? And once clicked on, we should no longer let any old site install any software they like on our computers?

Why hasn't anyone brought this up before? I'm gonna have a few cocktails, go for a drive and give this some thought.
 
If anyone wants to stop Chrome from auto-downloading files, see the info below.

I tried Firefox and it came up with a download window, asking me whether i wanted to save the file or not, rather than just auto-downloading it, like Chrome did.

For Chrome Users


Click the 3 bars to the top-right of chrome (used to be a wrench) and click Settings
in the new window, click Show advanced settings (at the bottom) look for Downloads and then tick the tickbox beside Ask where to save each file before downloading
 
JessieWolfe said:
:rkg

You are awesome. Thank you for letting us all know

:hug


IT'S JESSIE !!! :-D
*hugs back*

It seems someone mentioned it before in Random Discussion thread, but they didn't go all nerdy like me haha

I saw a tweet where someone wrote @Koolguy321 instead of @_Koolguy321_ , whoever is @Koolguy321 will be wondering what is going on :lol:
 
Sevrin said:
Wait a minute here. Are you folks saying that links sent by random people are no longer to be clicked on? And once clicked on, we should no longer let any old site install any software they like on our computers?

Why hasn't anyone brought this up before? I'm gonna have a few cocktails, go for a drive and give this some thought.

Your sarcasm actually has me in tears of laughter. :)

:clap: :clap: :clap:
 
I got the same thing, today. I'm newish. How do I report a username to MFC for that kind of thing?
 
Sevrin said:
Koolguy321 said:
JennaForReal said:
I got the same thing, today. I'm newish. How do I report a username to MFC for that kind of thing?

I think you just need to send a email about it to models@myfreecamsmail.com
Some models hold their breath while expecting a reply. Don't do that.

Done and not done, respectively. Thank you both.
 
Thank you so much for this post!
Yes I received as well an email on MFC "i recorded you, do you want to see? www.bit.do/recordcams". Good thing I'm not a curious person and I didn't click.

I will tweet this news

Have a nice day!
 
  • Like
Reactions: Koolguy321
I generally agree with what has been posted in this thread. However, it's important to note that the person you think sent the message to you probably had his or her account hacked. It makes sense to report the incident to MFC Support, but their response should be to alert rather to kick the sender. I'm new to this forum and posted my notes under a new topic. It would appear that this thread is where my remarks should have been added. They follow:

Models - If you receive a PM or MFC Mail with the following message, ignore it. The URL contains a link to a file containing spyware that will steal your MFC account password:

"i recorded you, do you want to see? http://www.bit.do/recordcams"

This came to my attention last week when a model told me she received this message as a PM from a model who uses the screen name Sugar. I chatted with Sugar last week, and she had no idea who was sending the messages. She also told me a lot of people had complained to her about the same message. About an hour ago, another performer sent me a PM to indicate that she had just received the same message from a performer named WetCandy22. Out of curiosity, I tried to follow the link. I assumed it would just go to some webcam site that was trying to recruit new members. Instead, that link prompts the user to save a file. I canceled that operation and came to the following conclusion: saving that file would have placed spyware on my computer that would have allowed the originator to steal my MFC premium account password. This is the most logical explanation for why these messages have been coming from performers instead of strangers.

In theory, this would also pose a hazard to a premium member, since the hacker could burn through all of his unspent tokens. For that reason, I tried to post an abbreviated version of this warning in Lounge1000. The moment I pressed the Enter key, my premium account was deactivated. Hopefully, that means MFC support is already aware of this and is trying stop anyone from posting that link on any chat board. Serves me right for trying to play White Knight, eh? :p

Anyway, if you received this message and made the mistake of downloading the file, your first line of defense should be to change your account password immediately. I just don't have enough information to advise you on whether to run a virus scan. Putting it another way, I don't know if the spyware is a one-off or if it would continue to expose future passwords.
 
  • Like
Reactions: Jupiter551
Ah, thank you! I JUST got one of these into my inbox today, but I'm a tech nerd too so I knew immediately it wasn't real. Ugh.
 
  • Like
Reactions: Koolguy321
EmmEffCee said:
I generally agree with what has been posted in this thread. However, it's important to note that the person you think sent the message to you probably had his or her account hacked. It makes sense to report the incident to MFC Support, but their response should be to alert rather to kick the sender.

Yeah I think this is also what is happening, because i'm a little surprised if models, have set their PM's setup to allow anyone to PM them.

They are probably targetting premium members, so that way they can then PM a model that they know that member is close to, and instead of just posting the same message, they could try and act as the member would, then post the link, and say something like "omg i just found a recording of you" "i'll get the link for you babe"

What would be really annoying apart from them spending tokens, would be they could also go into the Archives and clear any Private Shows that have been recoreded. :-x

I think if a MFC member or model does get their MFC login details stolen, MFC could maybe reset the password then email a new password to the email address associated with the account. ( though if you let Firefox or Chrome save your password, the person who has control over your pc, can easily steal those passwords)

EmmEffCee said:
Anyway, if you received this message and made the mistake of downloading the file, your first line of defense should be to change your account password immediately. I just don't have enough information to advise you on whether to run a virus scan. Putting it another way, I don't know if the spyware is a one-off or if it would continue to expose future passwords.

Remember people to NOT change your password from the SAME computer, because there is a good chance that if you did open the file, the person can just record the new password as you are typing it in.
You can't really call it spyware because it is a legit program, just being used for malicious intent, bit like a kitchen knife can also be used to attack someone.

If you run a malware scan, you probably won't find anything related to this at first, seeing as it only starts off as LogMeIN being used, but if you are correct about it being used to steal login details for MFC, then the attacker's next step whenever they get control is to put a keylogger onto your computer,
If you are lucky then your security software might detect this, although the attacker will have ways of trying to bypass any security and stuff.

So far it seems no one has replied here, who have opened the video.msi file, I would be interested to take a look at someones computer who has, and see if anything else has happened after the attacker has gotten access to their computer.
If i was the attacker, i would probably be after
Login details ( MFC, facebook, video hosting sites)
Personal information - Real info of a MFC models
Images & Videos
 
KittyWilde said:
FYI...

Not great news for people who use it to do good, but I'm happy to see that people using it to "do bad" will no longer have free access. :)

http://gigaom.com/2014/01/21/another-fr ... te-access/
Hackers stuck in 2005 are about to be furious. Seriously tho, good news.

Koolguy321 said:
If i was the attacker, i would probably be after
Login details ( MFC, facebook, video hosting sites)
Personal information - Real info of a MFC models
Images & Videos
Highly doubt they want any of that and if they do, man they are basic/small time. Probably just want credit card info and to spread it around as far as they can.
 
PunkInDrublic said:
Highly doubt they want any of that and if they do, man they are basic/small time. Probably just want credit card info and to spread it around as far as they can.
Guess it just depends on whether they have access to a model's computer or a member's.
 
If any model or member is still getting PMed with this,

I would appreciate it, if you could let me know, so new links can be reported :thumbleft:

The quicker new links are reported, the less chance of people fallen for this.
 
Status
Not open for further replies.