首页
Tell HN: Be aware of people trying to scam contractors
In short, I just received a nice proposal to work on a new contract, the potential customer sent me a "document" with the project specs which turned out to be a password-protected compressed file with some pictures and a ".exe" file inside.<p>I submitted the executable to virustotal which reports this as a trojan (https://www.virustotal.com/gui/file/088e2dabf218024d30e6899152b6a031dc30ae6f7d516492cb797292d6255d27/detection), seems like this takes screenshots and steals browser data which can be used for other purposes later.<p>Anyway, be cautious with proposals you receive.
18 条评论
nickfromseattle大约 2 年前
A variation of this - a fake job offer, allowed scammers to steal $540 million dollars in crypto tokens. [0]<p>I guess the scammer assumed as a contractor, you may have access to other customer systems they could exploit.<p>The internet be crazy, ya'll.<p>[0] <a href="https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game" rel="nofollow">https://www.theblock.co/post/156038/how-a-fake-job-offer-too...</a>
评论 #36024148 未加载
评论 #36026010 未加载
评论 #36025186 未加载
SoftTalker大约 2 年前
In general, beware of unexpected ".exe" files especially if they are a gateway to something you want (a contract, a payment, etc.)<p>No normal business operates like this, and if they do, you don't want to work for them.
评论 #36032872 未加载
评论 #36024586 未加载
gexla大约 2 年前
How do people not smell these from like a mile away? Must be proposals to people very new to this sort of work. To get me interested enough to even open a document, there's a lot you would have to get right before I hit that step.
评论 #36026290 未加载
评论 #36029208 未加载
评论 #36027060 未加载
jacknews大约 2 年前
There are far more actual jobs that seem like just scams, like this on Upwork I just saw:<p><pre><code> RoR developer need Urgently
Hourly: $8-$10 - Expert - Est. Time: 1 to 3 months, Less than 30 hrs/week -
Hello, I am in urgent need of RoR developer who has 5+ years of expertise for existing(ongoing) project.
To test Developer's ability we need 1 week free trail.
</code></pre>
I mean scam 1) $8/hr, and then they want a week free? lol.
评论 #36032647 未加载
zerr大约 2 年前
Do tech people execute such exe files? Doesn't seem like a novelty method, does it?
评论 #36024660 未加载
评论 #36024358 未加载
评论 #36025306 未加载
评论 #36025690 未加载
alexfromapex大约 2 年前
While we’re sending warnings, watch out for jobs which have “on-call” responsibilities as they’re essentially SRE jobs and can make you work on nights and weekends.
评论 #36024691 未加载
评论 #36024392 未加载
评论 #36024528 未加载
kepler1大约 2 年前
I don't know whether it's the general awareness of it that has been increasing or what, but it seems like job scams, bank scams, rental scams, these are all exploding in frequency lately.<p>Sometimes, it feels like we're in the middle disillusionment era of the internet and tech, where all the hope and positive potential of the new medium has now given way to just previous crappy life problems taking it over, only magnified.
评论 #36036645 未加载
评论 #36027174 未加载
NegativeK大约 2 年前
New job/contract work fits very neatly into the time sensitive and stressful setup that phishers and scammers lean on.
jusob大约 2 年前
I got something similar: a compressed file with an ISO in it: it was a CD with autorun. I guess some OS will mount it automatically and run the autorun.inf if you double click on it.
simonbarker87大约 2 年前
This happens in the content creator world as well, an agency contacts you and says to sign a contract by executing an exe file they send you. Very clearly a scam.
gfarah大约 2 年前
Talking about scams in job proposals. Lately I've been getting a lot of recruiters contacting me with sweet fake jobs opportunities, only to really try and sell me their recruitment services.
评论 #36028591 未加载
评论 #36029514 未加载
toss1大约 2 年前
Yup, just got a variant this morning:<p>Subject: "Company_Name Expired: Set for dissolution"<p>Body: "Hello My_Name, Your business registration DEADLINE has EXPIRED as of 04/01/2023. Your business, Company_Name, has an Annual... It's OK, we're here to help. Registrar agency is a business advocate..."<p>It is absolute BS as I know that I recently updated everything. Not sure if it is a click-thru-to-install-malware scam or phishing to sell me services I do not need, but I'm not finding out.<p>I also get a LOT of official-looking emails from service providers that want to "help" keep my US Govt SAM (Services Award Management) database registration up to date, when I just need to wade through some govt forms and tick a few boxes...<p>I'm used to ignoring this carp, but if you are new to business ownership, it might seem right on a day you are rushed and tired. So beware out there...
Greg433大约 2 年前
I wanna say a big big thanks to Chris Harvey from the depth of my heart, I have been through hell and storm all in the hands of brokers and fake recovery agents spreading themselves all over the internet, I got rescued by Chris , immediately I contacted him he responds and asks me to reach him via email:( chrisharvey553 @ gmail . com ) which I did and my funds got recovered within 72 hours, all thanks to him, have never seen an honest and understanding being such like him all my life. all thanks and appreciation goes to him, I pray he keeps on with the good jobs.
Nextgrid大约 2 年前
It’s clearly suspicious and I wouldn’t advise opening these files (there’s no reason it should be a self-extracting executable instead of a standard ZIP file), but the VirusTotal report could also very well be a false-positive if malware makers used the same archiver program to create a self-extracting archive with their malware and AV engines ended up associating the self-extracting archive entrypoint (benign by itself) as associated with malware.
评论 #36025674 未加载
评论 #36023966 未加载
brailsafe大约 2 年前
Once you know about PDF capabilities, you can't unsee
评论 #36028625 未加载
评论 #36026782 未加载
spacebacon大约 2 年前
I got a similar package on Upwork last Friday.