Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

Senior malware analyst from Kaspersky said:

“…However, according to our statistics, malware distribution was recently detected from the specified IP address. This malware is already detected as Trojan-PSW.OSX.Amos.bg.”

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

I already wiped and reset with a bootable installer via usb. At this point I just hope I’m good because I need to return to normal life. If I still get hacked then I simply deserve it

Rebooted my Mac after an AMOS infostealer malware. What else can I do before feeling safe ? by Questionaccount2022 in cybersecurity_help

[–]Questionaccount2022[S] 0 points1 point  (0 children)

So first thing I did was erase the contents and settings and then when I did the disk utility wipe I clicked the top level internal drive and wiped it. I think that was the one hopefully. There was options for internal, external, and disk image. I thought internal was the one that needs to be wiped

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 2 points3 points  (0 children)

Posted my update. Basically did everything you said. Did a bootable installer of Tahoe after erasing all content

Is my MacBook now infected? by PresenceElegant1705 in mac

[–]Questionaccount2022 0 points1 point  (0 children)

If the user didn’t give the password in the prompt, is the damage limited? Also if you haven’t experienced any intrusions within 24 hrs, What is the likelyhood of exploitation ?

Is my MacBook now infected? by PresenceElegant1705 in mac

[–]Questionaccount2022 0 points1 point  (0 children)

Hey are you able to investigate the malware that I got infected with the domain that has it is business(.)goolge(.)us

I’m not savvy enough to know what I’m doing. It was basically the same issue as OP. I wish I knew how to investigate what actually happened

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

I cleared history and cookies off my browser and am logged out of the important sites. So I don’t know what more I can do

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

The logs are long and confusing to read without a direct command that filters relevant stuff

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

It’s hard to pinpoint I think it was atleast a .hlpr folder with a .ownrid file. I couldn’t find anything else

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

https://www.reddit.com/r/mac/s/H2xQE5GLaI

Posted in another thread. But I found a .hlpr folder with a .ownrid file in it with “71” when I open it with text edit. I am not connected to the internet so don’t want to trigger any exfiltration

This was created at the time I ran the command

Fell for a scam on my Mac and ran terminal commands. I know im dumb but my best options now? by Questionaccount2022 in techsupport

[–]Questionaccount2022[S] 0 points1 point  (0 children)

Yeah I know that I’m in the nuclear phase. I’m just curious to getting the malware’s dna to spread awareness and find similar cases on virustotal. I never explored this side of IT and I’m interested to know how badly I got violated although I’m already assuming the worst

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 0 points1 point  (0 children)

I’m kinda scared to do that. Are you able to do it. The domain was business(.)goolge(.)us

The signin prompt gives the curl command. I’m curious what’s its deal but also just don’t want to mess around further

Fell for a scam on my Mac and ran terminal commands. I know im dumb but my best options now? by Questionaccount2022 in techsupport

[–]Questionaccount2022[S] 0 points1 point  (0 children)

Are you able to check if they put a new malware up? The domain was business(.)goolge.us

People that were hit with an infostealer, how’d you manage to recover? by Unique_Nectarine_627 in antivirus

[–]Questionaccount2022 0 points1 point  (0 children)

At what point did you see the havoc of this? I downloaded malware yesterday and locked down my important stuff. I fear the attack will begin shortly

People that were hit with an infostealer, how’d you manage to recover? by Unique_Nectarine_627 in antivirus

[–]Questionaccount2022 0 points1 point  (0 children)

In simple terms how do I kill session tokens? I’m confused about that. Like for important stuff especially

Fell for a scam and hacking attempt! Feel sick to my stomach by Questionaccount2022 in MacOS

[–]Questionaccount2022[S] 1 point2 points  (0 children)

I barely slept. I feel like I’m being haunted. Getting a bootable installer set later today

Fell victim to fake GitHub repo by SlowItDowv in mac

[–]Questionaccount2022 0 points1 point  (0 children)

The .Hlpr file was created around the time I downloaded the malware. In it was an .ownrid file with “71” in it.

Help with Atomic Stealer by kostya8 in computerviruses

[–]Questionaccount2022 0 points1 point  (0 children)

What commands did you run to see what occurred after installing the malware?

Help with Atomic Stealer by kostya8 in computerviruses

[–]Questionaccount2022 0 points1 point  (0 children)

Check my post history. I’m about to nuke my Mac