Scammers drop trojan on my VM

Number: 8449174888

Popup: Screenshot - 7f7d01b81f51c4b5560c8162fd6a7be8 - Gyazo

It was pretty spooky, I called them then I hung up after they connected to my vm. I wanted to see what they'd do so I just watched them while recording. I'll upload the video once I can edit everything it's about 44 minutes long. They basically transferred a program to my vm then ran it. It installed itself to the app-data folder of my computer and took a lot of my CPU & it ran in the background. They tried to get me to say my address over the phone after they called me from this number (209) 437-5578. It was pretty fucked up. I'll post the video link once I upload it to youtube.

[[3,4],[3,4,15,37]]

@LaughingSkeleton#95259 did you save the Trojan files? I would submit them to Malware Bytes ect…

[[3,4,15,37],[3,4,15,27,37]]

@drone2001#95278 I didn’t get the chance to unfortunately. I think it’s a RAT anyway.

If its just a backdoor, infect your VM (up to you, if you know what youre doing). then run a netstat to see if its connecting direct back to them, or via vpn, port forward, duc etc

It goes to voicemail.