Could I have allowed my computer and/or phone to be compromised?

Soldato
Joined
18 Oct 2002
Posts
4,746
Location
Kent
I would like to start out by saying that i may be overreacting despite the fact I may have also been very foolish.

Im used to getting the odd spam/fraud text message or phone call but yesterday I received maybe 5 or 6 texts and phone calls from different mobile numbers, all a load of nonsense about buy phones and accessories. I wasn’t overly concerned by this but I also got three messages in Telegram from some random person, this time about some job or other. What bothers me about this is that I’ve always had my Telegram settings set to only allow people in my contacts to message me which this person definitely isn’t. And for this to happen on the same day I received an unusually high number spam calls and texts has me a little worried.

I will now explain why I think I may have allowed this to happen. On monday someone on Reddit sent me a private message offering to send me an invite to join a site that is invite only, he did this after I started a thread on that very subject. I dont know what the OCUK forum rules are regarding discussions on this subject but the thing I’m talking about begins with a ‘T’ and ends in ‘rent’. As you will now have guessed I accepted his offer and promptly clicked the link in the invite email without considering whether or not it was safe to do so. However, I should point out that I did this on my windows PC, not my phone and that nothing else has actually happened besides the texts/calls/Telegram stuff. The reason I mention all this is because I can’t think of anything else dumb I may have done recently as I’m normally very careful about security and what I click on. I should also mention that at no point did I ever give my phone number or any other personal details to the guy on reddit or the site he invited me to.

I suffer from pretty severe anxiety at the best of times and stuff like this doesn’t help which is why I’m asking for advice despite how stupid this entire posts make me look. I haven’t yet been on my PC to run virus and malware checks and when I do Windows Defender, Malwarebytes and Superantispyware are the only ones I’m familiar with, I dont know if those three will be enough or not. As for my phone I’ve no idea how to check to see if it’s been compromised as I’ve never felt like I needed to before.

I apologise for how wordy this post is but if anyone could offer any advice id really appreciate it. Feel free to laugh me first though.

Thanks
 
Did the invite get you in to that site? Then it was probably ok

Your computer or phone doesn't have to be compromised to get spammed.
It takes one shoddyly coded shop site to leak your contact details forever.
I'm sure you know of https://haveibeenpwned.com/
A site to check if your e-mail or phone is in any known leak databases. Its legit, you can read up on it, won't collect the data you input at least.

When you should be getting worried is when you get an indication that your contacts were used in an attempt to buy something or register for something.
But so far this looks like basic spam thing. Just an excuse to change your passwords, for e-mail, telegram and whatever important.
 
As you will now have guessed I accepted his offer and promptly clicked the link in the invite email without considering whether or not it was safe to do so.


Oops. Have you checked the text of the email to ensure that the link goes to where it says it goes and not some intermediate intercept site?

You know the drill. Do a scan with Malwarebytes etc. Check your settings in Telegram. Etc.
 
@alec @Quartz

Thanks for replies.

The link did take me to the site I was expecting it to, I dont know how to determine whether or not it did something else aswell. I’ll check out the haveibeenpwned site, thanks for that.

I could take a screenshot of the email but I dont know if that would actually be of any use to anyone to try and determine if it’s dodgy or not.
 
What you need to do is look at the source text of the email and check that the URLs are the same.

The link as it appears in the email is -https://TorrentSiteName.com/sign-up?token=73ef8ad5cecd8b

When i clicked View Page Source in Chrome it appears as this - on, you have to follow this link: https:\u002F\u002FTorrentSiteName.com\u002Fsign-up?token=73ef8ad5cecd8b

I've obviously replaced the actual site name with 'TorrenSiteName'. The source text shows that 'u002F' appears in a few places and I have no idea if thats normal or not.
 
Last edited:
I'd edit that token PDQ!

But \u002F is the UTF16 for / (a solidus) which strikes me as rather odd. Why not just use the plain solidus? It makes me wonder if any of the characters in that URL are not what they appear to be. I am almost certainly being overly suspicious here.
 
I'd edit that token PDQ!

But \u002F is the UTF16 for / (a solidus) which strikes me as rather odd. Why not just use the plain solidus? It makes me wonder if any of the characters in that URL are not what they appear to be. I am almost certainly being overly suspicious here.
I’ll be honest, I didn’t understand most of what you said :(

Ive done a full secure erase on my NVME drives and reinstall of Windows, I dont store anything of any real importance on my desktop so it’s not a problem to wipe everything.
 
I would definitely say it seems strange, as most of the invite t rent sites have strict rules around not inviting people you don't know, and how you can have your own account banned if the person you invite breaches a serious rule. So for some random person to invite you on Reddit would automatically make me suspicious even if it was a legitimate link.
 
Other than formatting my drives and scanning them with Bitdefender and SuperAntiSpyware is there anything else I can do to be confident that my PC is safe to use?
 
The link as it appears in the email is -https://TorrentSiteName.com/sign-up?token=73ef8ad5cecd8b

When i clicked View Page Source in Chrome it appears as this - on, you have to follow this link: https:\u002F\u002FTorrentSiteName.com\u002Fsign-up?token=73ef8ad5cecd8b

I've obviously replaced the actual site name with 'TorrenSiteName'. The source text shows that 'u002F' appears in a few places and I have no idea if thats normal or not.
the \u002F is just a slash "/" letter which chrome sanitised from that original URL
token is the invite key

nothing suspicious here
keep calm and enjoy the torrents
 
Other than formatting my drives and scanning them with Bitdefender and SuperAntiSpyware is there anything else I can do to be confident that my PC is safe to use?
If you have to go through this level of dillydallying over an email for a website you signed up with, maybe you shouldn't be dabbling in such sites. You are the weakest link in your PCs protection, use your best judgement to decide if you're safe and what websites are worth visiting to ensure that safety.

Looks like a pretty run of the mill signup/registration token for torrent (and similar ilk) websites to me, but then i don't have the full context or original email to examine (and i don't want it, just saying).
 
Back
Top Bottom