Weird message from vendor.... Are they trying to scam me or something?

Placed a small order with a vendor about a month ago, today i get this message out of the blue.... looks really suspicious as I don't see why they'd need to talk to me, or not be able to say whatever they need to say on the PM system

"Hi

I have been having a LOT of issues with Evo lately and need to speak to you urgently about your previous order.

Can you shoot me a pm on tor chat URL REMOVED AS APPARENTLY IT IS MALWARE** my id is *******"


Comments


[18 Points] al_eberia:

Don't download anything from the website, it is malware: https://www.virustotal.com/en/file/03f428b34e0c3003a789ded55af31f1c6ee629092a12c51c9779c7e84ede0d90/analysis/1422300390/

Report the vendor to the market, they must have been hacked.

Edit: you should also edit the url so that nobody from here goes to it.


[9 Points] None:

Torchat

.com

kek.


[3 Points] Theeconomist1:

That is weird, very weird. I assume you already received your order? Was it correct and everything good with the order? The PM system should be just fine, esp if you guys PGP everything. Do you have a PGP key on your Evo profile? He should shoot you a message with that and verify he is in control of his PGP key. Tread carefully...

If everything was all good with your order, I agree, not sure what there is to chat about unless he's trying to warn you about something. Probably best to ignore but if curiosity gets the better of you, you could always use PGP to communicate securely through the market's PM system.


[2 Points] Cannabun:

Yeah, don't message him.


[1 Points] pinkprincess1:

There are a few funny stories about Evo right now....it's slightly worrying.


[1 Points] None:

I'd assume that persons account is compromised and not to use their services in the future. This looks like typical malware spam.


[0 Points] Jay-__:

Came too late to see the URL, but thanks to the virustotal result above, I saw the name of the file, at least.

And Tor Chat itself seems to be legit.[1]

But I am in no way saying the file you got told to download was 100% clean! - as I said, I came too late to see the URL.

Side-question: was the order still accessable or already deleted by Evo? As they usually delete every order older than 30 days.

[1] Even the popular known German chip.de-site is listing and hosting it as a download.

www.chip.de/downloads/TorChat_30053284.html for further info.