Author Topic: media.rockstargames.com serving malware?  (Read 1277 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
media.rockstargames.com serving malware?
« on: July 26, 2017, 02:35:14 AM »
https://virustotal.com/domain/media.rockstargames.com/information I did a scan for this domain this after visiting Steam's offical GTA V group and scanning an URL of one of the group's offical news message's image, and somehow it appears to be connected to (downloaded file analysis) couple of years old .exe.htm file that users claim to be malicious:

https://virustotal.com/url/6c2b4bc3e2dba7d72e09edf15264c9a08634689e9d4c8b8f0716ace6d130912e/analysis/1501027676/

EDIT: after performing another scan for the same link with adding https:// instead of http, it suddenly showed up different result however when I tried to copypast the VT result page on my mobile, I got 404 Not found alert for some reason. However, point is that where as it gave me http version when I copied the image's link from the Steam client itself, as when I visited GTA V Steam group on mobile Firefox, it showed the copied link of the image as https. Just copy the original scanned link into VT but switch http to https and you'll probably get the same result as I did where it shows the result being completely clean image file without any downloads with alerts.
« Last Edit: July 26, 2017, 03:23:32 AM by Pernaman »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: media.rockstargames.com serving malware?
« Reply #1 on: July 26, 2017, 09:33:23 PM »
Hi Pernaman,

Probably been taken down because of this as I get:
Quote
Content. 1:  File not found."
See: http://toolbar.netcraft.com/site_report?url=https://media.rockstargames.com
and
http://searchdns.netcraft.com/?host=*.rockstargames.com
This might be an outdated report: https://reports.adguard.com/en/rockstargames.com/report.html

polonus
« Last Edit: July 26, 2017, 09:36:01 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!