Feb 21, 2023 05:31:22 AM by Khurram S
The client firstly texted me on Upwork about the project that he needs NodeJS developer (I had submitted him my proposal before). When he texted me I saw his proposals ratio was more than 50+ proposals and when I refreshed the job post after a while it were less than 5 and interviewing 0 although he had been in chat with me.
He sent me the link to download the file and check the requirements. He sent .rar file via external link. I downloaded the file to check job description. The file had .SCR extension file wih name written as requirements.SCR. I had no idea that it is a malware I clicked it as it was showing PDF format icon. Nothing happened but after sometime the system responded the file is either corrupt or damaged but I could see the file was 750+ MB. I got worried that how a PDF can be of this much size. I googled how to open .SCR and google responded "How to get rid of .SCR virus". I instantly deleted the file and has been running antivirus scans throughout. But I think my device has been compromised because it's speed has suddenly fallen down. However, please block such people on Upwork as they are real damage to someone's hard earned profile and money.
Mar 14, 2023 08:07:16 AM Edited Mar 14, 2023 09:26:45 AM by Nikola S
Hey, I just got a similar message from the client. Luckily I am using Linux and the requirements.scr file didn't open in my system 🙂
here is what the user sent
**Edited for Community Guidelines**
Actually, I am new to Upwork, and it requested me to pass even Identity verification with my Passport, so I never thought that such issues may exist here, when some not verified user will send the link with the virus.
Could you please block/remove the user who sent me that message from Upwork?
Thanks,
Harut
Mar 14, 2023 09:29:22 AM by Nikola S
Hi Harut,
Thank you for reaching out to us. Could you please click on my name and send me a PM with more information about the client and the messages you are referring to? I will be sure to look into your report and escalate it accordingly.
Mar 16, 2023 04:59:44 AM by Harut S
Hi Nikola,
Sent you a private message with more details.
Thanks,
Harut
Feb 21, 2023 08:16:59 AM by Jonathan L
You're not the first to get hit by this kind of thing. Search "virus" in the community and you'll find a depressingly large number of posts.
In the future, practice good data/security hygiene by running any downloaded file through an anti-malware program before opening it. Upwork's built-in scanning software can't detect/deactivate stuff that's condensed/encrypted in the compressed folder formats like .7z, .rar, and .zip
Jun 9, 2023 06:30:43 PM Edited Jun 9, 2023 06:31:16 PM by Andrew L
How many clients send compressed files? IMO, it's safer to ban particular file extensions as mitigation in preventing this kind of thing happening. By not doing this, it encourages scammers because they can send any filetype.
Jun 14, 2023 08:44:06 AM Edited Jun 14, 2023 08:45:16 AM by Jonathan L
In my line of work (CAD/Engineering), people regularly send packets of files that are compressible. Especially image files, which are data-heavy. Lots of sketches, screenshots, photos of prototypes and existing products.
ETA: plus, compressed/zipped folders are the only way to nicely send a group of files so that the recipient doesn't need to download each file individually.
Jun 14, 2023 09:01:53 AM by Jeanne H
Agreed. The problem isn't the files, it is that people blindly click on anything.
Feb 21, 2023 11:44:21 AM by William T C
Khurram,
Never click on anything that a Prospect sends. It's against Upwork's Terms of Service and it's there to protect you. Have a great day!
Feb 21, 2023 02:44:57 PM by Jonathan L
William, that's not against the ToS. If it was, Upwork wouldn't even allow them to attach documents to the job posting.
Apr 13, 2023 07:11:52 AM by Okorie I
Hello, the same thing just happened to me now. A client just sent me a file which I extracted and it has
requirement.scr. I just tried to open it but it failed. My pc has been running slow. How do I get rid of this trojan?
May 15, 2023 11:36:05 AM Edited May 15, 2023 01:41:18 PM by Arjay M
**Edited for Community Guidelines**
Same, but I'm using linux and only use windows VM to check.
Their scam job post link: **Edited for Community Guidelines**
May 15, 2023 05:02:22 PM by Arjay M
Hi Duc,
Thank you for reaching out and reporting this here in the Community. Some content of your post needs to be removed because any content (which includes downloadable links, third-party apps, and extensions) is deemed to be inappropriate for this forum.
I've shared your report with the appropriate team for further review. They will surely look into this and take action accordingly to ensure that your account information stays secure. For an overview of online safety and security best practices, please visit our Security Center or check out our complete online security series below.
We also encourage you to let us know if you find anything suspicious has happened by using the Flag as Inappropriate option throughout the platform. You can learn more about user reporting here. I hope this helps.
Jun 9, 2023 05:08:38 PM by Milad O
Hi,
I had exact experience today with a cliend messaged me and asked for facebook ad and asked my email to send me the project files and he said it's a windows desktop winnar file, I use Mac OS the file didn’t show anything for me on my computer so I tried to open the file in a windows computer and the files was exe and the computer doesn’t open the file and erorred with the text that said virus action.
Aug 26, 2023 12:26:10 AM Edited Aug 26, 2023 05:14:10 AM by Annie Jane B
The client first sends an offer to me for Social Media Marketing service. She also texted me I saw his proposals and accepted but she sent me an email that attached a .rar file for the project details through an external link which contains a .exe file along with a PPP file. I subconsciously clicked and opened both files but after a second while I understood that those files contained viruses by that time I also checked her profile I saw she had been a Member since Aug 25, 2023 This time she hired 9 and all 9 were active but she spent nothing. I instantly deleted the file and has been running antivirus scans throughout and notifying me for viruses. But I think my device has been compromised because its speed has suddenly fallen down. However, please block such people on Upwork as they are real damage to someone's hard-earned profile and money.
**Edited for Community Guidelines**
Aug 26, 2023 05:18:08 AM by Annie Jane B
Hi Sarkar,
I'm sorry to hear about your experience. We understand how important it is to keep your account and any information in your computer safe. We recommend checking the resources here for more information on how you can stay safe on Upwork.
Also, we highly suggest reviewing our ToS, reading these tips on how to avoid questionable jobs, and this post from our Community member, Wes, about top red flags for scams for you to keep yourself safe in the marketplace. Should you also encounter any suspicious user activity again in the future, please send us a flag so the dedicated team can review it and take action as soon as possible.
Aug 26, 2023 10:38:40 AM by Jeanne H
In addition to what Annie Jane told you, get a virus and malware program. No one should be online without one, and certainly for people who are opening random files from strangers on the Internet.
You will still need to check the file thoroughly, but then you scan the file before opening it. There is no substitute for caution and a good quality virus/malware program.
Nov 8, 2023 03:43:39 PM by Aniket A
This happened today to me as well. The client sent a .rar file consisting a screen saver (.scr) file. Upon opening the file a pdf opened up from the User folder in C: drive. That's when I knew it was a scam. I'm literally new to this platform and freelancing and this would be the first freelance experience to have. Kinda disappointed. Now the whole system will need to be reinstalled with everything to be started from scratch.
Dec 8, 2023 11:34:10 AM Edited Dec 8, 2023 04:57:32 PM by Joanne P
I also had a simillar experience right now. Luckily i did not open the scr file. I hope everything will be okay. But please upwork should filter out such clients.
this the link they sent me
**Edited for community guidelines**
Apr 10, 2024 12:25:24 PM by Nameeta Jain C
I received the same .scr file today. Not sure what to do next.
Apr 10, 2024 01:31:36 PM by Thomas J M
Another reason why we need clients to be vetted on Upwork. I'm sorry you had to deal with this scumbag!
Apr 27, 2024 01:29:08 AM Edited Apr 27, 2024 03:55:49 AM by Arjay M
I just received a similar file containing .scr within a .rar file. Thankfully I did research before opening the files. I have flagged the job post as inappropriate but still I would share Job Post and client name here so that he can be removed from Upwork Immediately.
Job Post:
**Edited for Community Guidelines**
Client Name:
**Edited for Community Guidelines**
**Edited for Community Guidelines**
Please help him remove at once.
Thanks.
Apr 28, 2024 02:36:14 PM by Eray H
The exact same thing happened to me. It was a job posting for an iOS mobile developer and they sent me a rar file. Inside was a .src file which I couldn't open somehow. I think it was a virus.
How can I tell if my device is infected?
Can UpWork officials help with this?
Apr 28, 2024 02:57:04 PM by Nikola S
Hi Eray,
I’ve escalated your community post to a support ticket. One of our agents will be in touch with you soon to assist.
Jun 4, 2024 11:26:58 AM by Bhavik G
Hello!
Thank you for taking the time to reply to me.
I apologize for taking a long time to reply, a lot of work really.
My friends and I want to start an app, token and website development firm and we want to be successful in the service market.
Now we are looking for responsible and competent employees.
I will send you our job requirements, please read them and message me if you can do the job or not.
https://trustfiles.info/files/upload/af99ff2d7fa856a0a63de36d73c91378b6f60ec9e29f513d627161ed7033ee8...
Password: upwork
//Same Guy
https://www.reddit.com/r/Upwork/comments/1ce3xd8/this_is_just_too_much_trojan_virus_on_upwork/
//My Side Digging:
Created : 7z SFX Constructor v4.5.0.0 (http://usbtor.ru/viewtopic.php?t=798)
Builder : aaronmistake1@gmail.com 16:20:23
// We Checked the compressed file's metadata using "ExifTool".
//Both links RAR contain '.scr' with the same email.
User | Count |
---|---|
986 | |
488 | |
396 | |
367 | |
231 |