@
Room42Dus de inlogpogingen waren zelfs 100% succesvol?
nee, want de aanvaller heeft mijn mobieltje niet.
Ik dacht dat het om mailtjes met de Steam Guard code ging!
klopt!
Ook geen verdachte mails in je prullenbak over geresette wachtwoorden?
nee, behalve een email met "ik weet dat je wachtwoord xxxxxx is" (een oud insecure wachtwoord dat ik inderdaad gebruikte, maar niet voor Steam), met daarin een vals verhaaltje om geld van me af te troggelen.
Geen gekke websites/hacks waar je je wachtwoord voor steam in moet vullen?
nope
Ik neem aan dat je wachtwoord een random string aan (vreemde) tekens is?
idd, autogenerated, maximum tekens dat steam toelaat.
Geen trainers/cracks/etc. in gebruik?
ik heb cheat-engine gebruikt, waar je eigenlijk je eigen trainer maakt. dat was voor een epic-store-spel.
Weet je 100% zeker dat die mails legitiem zijn?
looks legit:
Delivered-To: xxxxx@gmail.com
Received: by 2002:a67:ee45:0:0:0:0:0 with SMTP id g5csp1490552vsp;
Wed, 28 Aug 2019 16:14:04 -0700 (PDT)
X-Google-Smtp-Source: APXvYqxEWdyJ6o12/Bsl/f2wDJ5Y8nVTwRykZ1EVdp4gtLGrt7djmn4NojVCc39/nYpCpwkFA1dr
X-Received: by 2002:a63:3281:: with SMTP id y123mr5476457pgy.72.1567034043879;
Wed, 28 Aug 2019 16:14:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1567034043; cv=none;
d=google.com; s=arc-20160816;
b=Eoj2KG4GZifFS7YB1r9o3Artw4wWhx8hkIrI92f0fz7KxzvMLIN5cRqJdd8MOTyJPH
gePIl9KLCToRuRfk1tE+JQ6EFUVAJhTKteQKLEuYKgU7wdqb1PY7Xxpgensu9ybQjcx7
Ol5U9NVzIX9fCFGvYMBPtNwa9UOVqxDXtXH6Q8vHRz/QwNu2tDm3EQasQY6tMpXDO9Nm
75c87Zvoop/aKzFDUM6HvOSQbADGrFWPr8LfrobX1xDmlS1xVVlhXd/kzUe9NONVrMhN
Oh2TSETrLe3hm+xa2I9PvWmEBuGPC0Cy3xJcrRzPi7qRHNoe8HtfPPAlXo6gYhck6k0s
LD4g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
h=date:message-id:subject:mime-version:reply-to:from:to
:dkim-signature;
bh=7A367QUoJ2OdISCGTPUBQ58cEbDiZUgNezR5XPR/O2c=;
b=rnCmW/144KHANywV1ONlQkQi5ZWU3+hunDZHZJR4AlAajRNlDjQafbu2rRLSwkt6D7
LuSMceO1IV30CtrRHpL88g7/QEw9I4P1L9XYden1Sfy9HM5r9/DLVtgL4DIegg/r4Pxp
gGaimd2y13hx5ZnWQiDmvbh8VN8Itjlnjk+PZ40/2Cw5SDBCjI8rJBESJWAR8AvE7dwM
w98O08URl3zAwE5YZ7Q93g/1hpwdpQjihtotpSumJrLmk8CT8tidO6w5bzBMIsp93Qer
XhCQVhKPVYWxhbN5THoRfn8Lc21lFE3lBJIZ0q4LM9gT5HKJ8m1cRpUo9ZQho9g6dYzS
1Wzw==
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@steampowered.com header.s=smtp header.b=lK9khlJl;
spf=pass (google.com: domain of noreply@steampowered.com designates 208.64.202.44 as permitted sender) smtp.mailfrom=noreply@steampowered.com
Return-Path: <noreply@steampowered.com>
Received: from smtp-44.steampowered.com (smtp-44.steampowered.com. [208.64.202.44])
by mx.google.com with ESMTPS id z11si539657pjq.102.2019.08.28.16.14.03
for <xxxxx@gmail.com>
(version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);
Wed, 28 Aug 2019 16:14:03 -0700 (PDT)
Received-SPF: pass (google.com: domain of noreply@steampowered.com designates 208.64.202.44 as permitted sender) client-ip=208.64.202.44;
Authentication-Results: mx.google.com;
dkim=pass header.i=@steampowered.com header.s=smtp header.b=lK9khlJl;
spf=pass (google.com: domain of noreply@steampowered.com designates 208.64.202.44 as permitted sender) smtp.mailfrom=noreply@steampowered.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=steampowered.com; s=smtp; h=Date:Message-Id:Content-Type:Subject: MIME-Version:Reply-To:From:To:Sender:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=7A367QUoJ2OdISCGTPUBQ58cEbDiZUgNezR5XPR/O2c=; b=lK9khlJl5TByveZZmoYLhOHGsM ps+KpGOsY8cvqN663hKWgMrpOFRtmXbYSWKfEmEdYF6RcUrhIYAHq1B7ZkpbsYe9CUUyBLuSp69lL XttkyTzVR1m6bWxACKngBg+mQstIYdyJ46k75+qU6FbL8HJPEW8upcYhhNAYZD3cFdSY=;
Received: from [208.64.202.21] (helo=valvesoftware.com) by smtp-01-tuk1.steampowered.com with smtp (Exim 4.90_1) (envelope-from <noreply@steampowered.com>) id 1i378d-0008VP-HK for xxxxx@gmail.com; Wed, 28 Aug 2019 16:14:03 -0700
To: xxxxx@gmail.com
From: Steam Support <noreply@steampowered.com>
Reply-To: <noreply@steampowered.com>
X-Steam-Message-Type: Account Information Confirmation
MIME-Version: 1.0
Subject: Your Steam account: Access from new computer
Content-Type: multipart/alternative; boundary="------------060908020109090601040503"
Message-Id: <E1i378d-0008VP-HK@smtp-01-tuk1.steampowered.com>
Date: Wed, 28 Aug 2019 16:14:03 -0700
--------------060908020109090601040503
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Dear xxxx,
Here is the Steam Guard code you need to login to account zabinko:
xxxxx
This email was generated because of a login attempt from a computer located at 201.182.146.14 (BR). The login attempt included your correct account name and password.