Account hacked

Account or connection issues

Account hacked

by Thimerol » Mon Oct 26, 2015 5:54 pm

Hello! I logged in earlier (PvP server) only to find that my gold was mssing. I was left with only some silver. I have a mage 36, but I used to play the retail since 2005. So before opening a ticket to GM and posting this, I already checked my alt ( a warrior I'm leveling too). I started selling almost everything on the auction house since around level 10 and managed to get around 40 gold. I was trying to get enough for my mount when i would hit 40.

So, as i was saying, I logged in and found only 54 silver 38 copper in my bag. The only thing that might be suspicious is that I downloaded some addons yesterday night. Is there a possibility that there is some keylogging in them or anything? (I have no idea how these things work). I have already opened a ticket in-game and as I am waiting for a response, i thought I should ask the forum and see if this has happened to anyone else, or if anyone can help me with it.

Thanks in advance for your answers!
Thimerol
Tester
 

Re: Account hacked

by Thimerol » Mon Oct 26, 2015 6:00 pm

And I forgot to mention, that i dont share my account with anyone
Thimerol
Tester
 

Re: Account hacked

by zonejones » Mon Oct 26, 2015 6:33 pm

You gotta be careful where you get your addons. In the terms of service i believe it states that you will NOT be compensated in the event your account gets hacked. So basically, GG. Dont worry 40g isnt shit if you grind money making mobs then you should have no problem getting 100g by 40.
Last edited by zonejones on Tue Oct 27, 2015 12:13 am, edited 1 time in total.
zonejones
Private
Private
 

Re: Account hacked

by Thimerol » Mon Oct 26, 2015 6:42 pm

This is where i got my addons from: viewtopic.php?f=63&t=605

From a sticky post in nostalrius forum. The links i used are the ones provided by Aquane that posted that thread. The addons i downloaded are the three first (atlas + atlas loot, KTM threat meters, Damage meters).

I know i can get my 100 gold. It's not about the money. It's about if there is malicious softwere in these links, we should investigate it and report it, so that others' accounts don't get rekt. So did anyone else had such problem after downloading one or all of these addons?
Thimerol
Tester
 

Re: Account hacked

by zonejones » Tue Oct 27, 2015 12:13 am

Yeah im gonna go ahead and NOT click that link.
zonejones
Private
Private
 

Re: Account hacked

by Mopar » Tue Oct 27, 2015 4:10 am

That link is a forum link to the Addons thread. The link itself is perfectly safe.

In most cases, an addon from that forum will not be problematic. Many people use addons from there, including myself (and i'm also the author of SpamThrottle). An addon cannot steal your password information.

But there was ONE case where someone built an addon (it was an auction helper) that provided the functionality it said it did, plus a trojan to send gold to another player when you clicked on a mailbox. The code was obfuscated so difficult to know right away (although the obfuscation itself is a huge red flag).

Can you say what exact addons you downloaded? And did they come from Git repositories or were they somewhere on Mega (for example)? If you can provide a list of what they are, it's possible to take a quick look to see if there is another addon that is stealing gold.

I'd say it's more likely you got hacked with a keylogger or with an easy to guess password, or via someone hacking your E-mail. But i'm happy to help see if there is an addon causing it.
The pizza level in my bloodstream is dangerously low.
User avatar
Mopar
Sergeant Major
Sergeant Major
 

Re: Account hacked

by Thimerol » Tue Oct 27, 2015 11:53 am

Thanks for caring Mopar. As i said above, the only addons I use are those 3 from the link i gave, (atlas + atlas loot, KTM threat meters and Damage meters). You can find them by clicking the above link and check the 3 first links that the author of that thread gives.

(viewtopic.php?f=63&t=605 > Aquane's post >
http://www.mediafire.com/download/4mr4a ... _Atlas.zip for Atlas + Atlas loot,
http://www.mediafire.com/download/qopz2 ... Meters.zip for the KTM threat meter,
http://www.mediafire.com/download/aj265 ... v5.3.1.zip for the damage meter.)

I dont know what git repositories are, but the links send you to mediafire.
Thimerol
Tester
 

Re: Account hacked

by Thimerol » Tue Oct 27, 2015 11:55 am

And btw, i know an addon itself can't steal your apssword, but isn't it possible that by downloading one of these i got a trojan as you said, or a keylogging program? I mean, even if I did, I would't recognize it, as I have no idea about these things :(
Thimerol
Tester
 

Re: Account hacked

by Mopar » Tue Oct 27, 2015 1:13 pm

Hi Thimerol - I took a close look at all of this.

1) These are the actual addons. They are identical to the versions I personally use, except for DamageMeters (which I abandoned, but it looks clean), and KLHThreatMeter, for which I use a later version, 17.35. There is no malicious code in the ones you linked.

2) No, you cannot get a trojan or unintended malware install from these zip files. They are all clean. They are .zip files, and keylogging programs would usually install something (they would be some kind of installer or .exe file).

This looks like you were just hacked one way or another. Another possibility is that you got hit by a COD scam and didn't realise it (Did you get any 'gifts' from the administration, that would be a key thing to note. Did you get sent any Deathcharger's Reins? Any "sorry for the inconvenience, here's 100g?"). Via in-game mail.

I suggest you change your password via the Nostalrius main web site, make sure it's 15 chars or less, and relatively complex. Check your computer for malware, and also change your password on your E-mail as well. (If they hacked your E-mail, then they could have reset the password, but you were able to log in so not likely.)

If there is anything else suspicious or out of the ordinary that you can think of that happened, regarding E-mail, programs you downloaded, or anything else, mention it and maybe it will be a clue.
The pizza level in my bloodstream is dangerously low.
User avatar
Mopar
Sergeant Major
Sergeant Major
 

Re: Account hacked

by Thimerol » Tue Oct 27, 2015 1:40 pm

Ok, so all these are clean, I haven't got any mail lately so i can't be scammed with COD, my e-mail is fine, and I haven't downloaded anything else.

There's only one thing left and it is my stupidity. I just remembered I bought something from the AH that should cost 4g. In my rush I might bought it costing 40g (you know, those ppl that put low bid prices but high buyout prices to fool ppl like me). I am sure I didn't check my gold after that, until the next day that i saw i was missing my 40g. So i might went for something that should cost 4g and paid 40g. Oh what a fool I am!

If that is the case, then sorry for your time! But, at least, we now know for sure that these addons are clean, and I am more than confident that my pc is still clean :)

Thank you for your time and care!
Best wishes!
Thimerol
Tester
 

Next

Return to Support