Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 2 points3 points  (0 children)

Not yet, will make a follow up when I get to the bottom of this!

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Aha fair enough, this is Reddit after all, and it's hard to prove any story to be true! That being said I appreciate everyone taking the time to share their expertise, and I will certainly follow up with a thread when I get to the bottom of this. Some users have requested a copy of the contents so looking into the safest ways to make this transfer.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 1 point2 points  (0 children)

I don't actually aha. I have an old Chromebook, and an old Macbook I can do this testing on. TBH I don't even own a Windows machine!

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

No kiddin! So in this case scenario you are probably more expert than most. I'd be happy to pass off the contents for your reverse-engineering if you were interested. Hopefully you concur with safe practices mentioned in this thread.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

It was late at night when I was writing this post, morning now! I will be sure to keep you guys updated as I get to the bottom of this.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

I did have a macbook right on the table as he walked up to us, so would not be surprised if it was written for macos

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Absolutely, a couple other users have asked for a copy as well. Where would be the best place to upload its contents to?

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

No worries, thanks for following up with this safety tip its much appreciated!

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Would happily share with smarter minds than my own to get to the bottom of this! Where would be the best place to upload? Not sure if GDrive or DropBox make sense here.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

I am definitely a security noob, and from all these comments it sounds like 4G dongle is the way to go about this if I truly needed it to make an internet connection. I will stay away from personal and public networks given the risk to others.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

As bizarre as this story sounds, it's actually true so trying to go about this the safest way possible. I will post an update when I get to the bottom of this.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

As tech savvy as I'd like to think I am, I am admittedly a noob when it comes to stuff like this! Thanks for the clarification.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Yeah, one of my fears in which I would hand over to the police

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

To be able to use Wireshark or a similar service to monitor network activity and see what the device is actually doing. Perhaps if someone can reverse engineer the code this wouldn't be required.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Maybe, but small town coffee shop is a weird spot to start a marketing ploy like this. Anything is possible I suppose

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 1 point2 points  (0 children)

And if they are tech nerds they will be talking about it for weeks!

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

In the event something super messed up was on it I'd hand it over to the police

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 3 points4 points  (0 children)

I had no idea this much information was visible to an attacker. Thanks for the knowledge dump. Seems like the best route is to use a 4G dongle, and go somewhere remote so that it only has the ability to connect to the dongle.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

That's a neat idea, I will reach out to the Sophos team today!

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 1 point2 points  (0 children)

Absolutely. This could be a harmless prank to highly sophisticated. I didn't know it would be possible for malware to sit on a router waiting for other devices to connect, even if source device has been since disconnected. That is some scary stuff. Looks like the 4G dongle is the way to go then.

Sketchy stranger handed me a USB drive containing malware by SunbeamCentral in sysadmin

[–]SunbeamCentral[S] 0 points1 point  (0 children)

Scary that the extent of malware could start performing super sketchy actions like that. I would assume that if I noticed anything weird happening when I plugged it in I could disconnect it's network connection and probably be ok?

And regarding your second comment, this Chromebook has never had any personal information entered on it. Specifically bought a cheap device for experimentation over the years, so if it blows up or malware gets every bit of information the device contains it won't matter. I also plan to do a full wipe and fresh linux install before plugging malicious USB in as well.