Instapy: Trojan Horse detected

Created on 12 Mar 2018  路  4Comments  路  Source: timgrossmann/InstaPy

Avast picked up on a Trojan Horse just now, second time it's happened. It aborted connection on www.instagram.com because it was infected with JS:ScriptPE-inf [Trj]. InstaPy continued to run perfectly.

I can see the URL (It's some user on Instagram), and the process was chrome.exe located in my default C:Program Files (x86). Detected and aborted by Avast's Web Shield. If needed @uluQulu or @timgrossmann I will provide the URL to the account (www.instagram.com/(usernamehere)).

Another thing I have encountered (since on the topic of links in bios affecting InstaPy), I was in the room when InstaPy went to the next post in "like by tags," the account it was going to like a post from had a "linktr.ee" link in it's bio. Instead of liking their post, when it checked their profile to see if they have less than 2500 followers, I assume somehow the link sent them to another user, with another linktr.ee link. I quickly shut it down before it started liking the p0rn that was associated with it. In the logs InstaPy was working fine until it hit the account with linktr.ee in it, then every post it liked from then on was p0rn, and "chain fed" links to like I'd say. I haven't had this issue since banning linktr.ee hashtag, but I have no idea if that did it, I've been keeping a close eye on it now.

wontfix

Most helpful comment

@ShiftingKill @corriejgreen @uluQulu That is really weird and seems to be a "random" misbehaviour.
I will investigate the code part that does the "interaction" on the profile page but myself and a few others check all of the PRs to make sure that there is no such behaviour built in. (This does not means nothing can slip through, though...)

All 4 comments

Hi @ShiftingKill
It's wondrous that how it _sent_ click on a link in bio which only could bring malware into action, very interesting!
~ must investigate linktr.ee _chaining_ before the hand

Would like to bump this, PC now has malware and the only software used recently is the application. I think it clicked a link on another bots page and was malicious as i actively watched it click links in bios for a while.

@ShiftingKill @corriejgreen @uluQulu That is really weird and seems to be a "random" misbehaviour.
I will investigate the code part that does the "interaction" on the profile page but myself and a few others check all of the PRs to make sure that there is no such behaviour built in. (This does not means nothing can slip through, though...)

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. > If this problem still occurs, please open a new issue

Was this page helpful?
0 / 5 - 0 ratings

Related issues

v77v picture v77v  路  3Comments

drcyber975 picture drcyber975  路  3Comments

harrypython picture harrypython  路  3Comments

CodeMaster1 picture CodeMaster1  路  3Comments

wyvers picture wyvers  路  3Comments