A Word of Warning to All Scrapebox Users !

Do we know it is ScrapeBox for sure?
Posted via Mobile Device

I don't think so.
ScrapeBox will not allow downloading files automatically, and it filter direct links to executable and other kind of files.
To test this, paste a link to an executable or media file into the harvester, transfer it to the poster and try to post to it using slow poster or manual poster.
The only time SB need to use IE is for slow and manual poster. Everywhere else, SB does not download any file, and does not rely on IE.
 
Last edited:
Sounds like the hackers have devised some sort of honeypot scheme. They must have found a vulnerability in the software and they have set up special sites that detect SB users and run their exploit. I have seen this type of operation happen before with other software. Black Hatters are high value targets to hackers so I would be willing to bet that is what's going on.
 
Also, what footprint was every1 harvesting from. If you want to be safe I would harvest from custom for awhile. Or change it up a bit. BTW, has any1 contacted scrapebox about this?
 
They must have found a vulnerability in the software and they have set up special sites that detect SB users and run their exploit.

Not SB, but this would make sense: "They must have found a vulnerability in Internet Explorer".
As I wrote, SB use IE (core components) only for Slow Poster and Manual Poster. When you got malware, then your IE is not up to date, and your AV software is not able to catch the malware.
Its not a fault of SB. When something pass IE, it would happen also when you visit that site with IE.
 
This really sucks. Be careful and like mentioned above, make sure you are running in vmware.
 
Not SB, but this would make sense: "They must have found a vulnerability in Internet Explorer".
As I wrote, SB use IE (core components) only for Slow Poster and Manual Poster. When you got malware, then your IE is not up to date, and your AV software is not able to catch the malware.
Its not a fault of SB. When something pass IE, it would happen also when you visit that site with IE.
This is probably true but there are many thing that can beat even the latest version of IE so I don't know how much an update would help. But even with that in mind that does not my that SB could not create additional vulnerabilities as well. But i have not used SB so I am only guessing. Good discussion though! :)
 
Not SB, but this would make sense: "They must have found a vulnerability in Internet Explorer".
As I wrote, SB use IE (core components) only for Slow Poster and Manual Poster. When you got malware, then your IE is not up to date, and your AV software is not able to catch the malware.
Its not a fault of SB. When something pass IE, it would happen also when you visit that site with IE.

Good point. And this is why Widows must be updated.
I am using windows 7 (legit), and It gets updated at least twice a week. Atleast one of the security updates is related to IE. It must be fucked up if they update so frequently. (or maybe they just do a great job..or both).

Either you get a legit copy of windows (those who don't), or think twice about scrapebox.
 
Guys, if you read bleepingcomputer or hijackthis forums, there are many of the same issues being posted.

I run windows 7 (latest updates) with firefox. I also run IE8 with all latest updates. I run Bitdefender and Malwarebytes both in active protection mode. The honeypot post sounds the most feasible.

If SB used IE core components, then the only expalantion is that the script is so new it hasnt received a fix yet ?
 
I believe deltrum is correct on this. In the "slow poster" in scrapebox, it simulates IE and indeed integrates the OS to seem as if it's really someone browsing. The malware is likely getting in via that exploit. Disabling slow posting might fix this issue until there's a software fix from MS.
 
Are we talking about drive-by-malware? This would be a MS issue due to a possible bug in IE or its core components, not a SB issue.
If we talk about the TDSSRootkit, I do not agree that it could be installed by using SB. It is known to be installed via P2P and crack downloads, not via websites as drive-by malware.
But assumption (and the whole topic is based on assumptions) will not help anybody.
 
That is the thing mate....it was the TDSSRootkit that was downloaded from a website parsed by SB...this is the new breed of malware spreading.
 
I really don't think so. Just PM me the url of that website and I will analyze the content.
Also, this rootkit need admin rights to drop its payload... do you run your PC with admin rights?
 
Last edited:
The URL was part of a list containing over 40k urls so would be difficult to isolate the problem url....Anyway, less learnt....vmware now installed ;)
 
People telling that is not possibel is wrong. Scrapebox is using the browser, that means it loads the javascripts on the websites. So yes unless you are using an up 2 date antivirus you can get infected just by using scrapbox (because scrapebox visits the websites) I will explain more about this in 6-8 hours when i get sober ^^
 
That is the thing mate....it was the TDSSRootkit that was downloaded from a website parsed by SB...this is the new breed of malware spreading.

TDSSRootkit isn't new the first variants are a few years old, i've intentionally hit hundreds of malware URL's with ScrapeBox and yet to have one do anything with an updated system http://www.scrapebox.com/videos/test/

OP can you get the URL from your AV's logs and send it to me?
 
Not SB, but this would make sense: "They must have found a vulnerability in Internet Explorer".
As I wrote, SB use IE (core components) only for Slow Poster and Manual Poster. When you got malware, then your IE is not up to date, and your AV software is not able to catch the malware.
Its not a fault of SB. When something pass IE, it would happen also when you visit that site with IE.


why the fuck does a premium next gen bot / scraper / tool w/e use Internet explorer? you don't need IE to post comments or harvets URLs. this alone makes me think "NOOB" and amateur.
 
Sweetfunny: I will check the AV logs to see what was logged. The file downloaded was titled emusv.exe and basically, closed down av processes and prevented any exe's being run.

Nuisance security suite av was (supposedly!) installed and notifying of new viruses every couple of seconds.

Fire up firefox and there was constant redirects to kdirectory/ask plus a load of other referral ID linked domains.

My laptop was in autopilot basically !

I managed to remove by running TDSSRootkit remover in safe mode and removing registry entries.

The file trying to hit the net was emusv. e x e .
 
Sweetfunny, you are not taking messages. Send me your email.
 
Back
Top