@xssfox that's one of the reasons I mainly hack games from the 90s. They don't change, even as the decades do
Notices by Foone🏳️⚧️ (foone@digipres.club), page 2
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 07:02:23 JST Foone🏳️⚧️
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:25 JST Foone🏳️⚧️
other debug strings are in portuguese!? this is a very international bit of malware
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:24 JST Foone🏳️⚧️
so this seems to be associated with leetb.iwannaeatcats[.com]
it sends them the data after it steals it. usually suspects: all the passwords out of your browsers, discord & telegram, minecraft & roblox, & any wallet
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:23 JST Foone🏳️⚧️
and Growtopia. I didn't know that game existed, but apparently there's malware out there trying to steal your passwords for it
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:22 JST Foone🏳️⚧️
whenever you find the worst pits of the internet, you will find cloudflare there, quietly making money off it.
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:21 JST Foone🏳️⚧️
it also refuses to run if your external IP is one of a couple, which include a hungarian ISP, a couple IPs in moscow, and azure
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:20 JST Foone🏳️⚧️
it is also apparently dumping these stolen passwords into a discord somewhere, and if it steals your wallet password it dumps it with "🤡 Leet Stealer"
even the bad guys think you're a clown for using cryptocurrency
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:10 JST Foone🏳️⚧️
on a day with no ADHD meds, my roommate knocks on the door and is like "a friend got their discord hacked but before I knew it they sent me an EXE and I ran it. am I hacked?"
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:09 JST Foone🏳️⚧️
seems it is an electron based javascript malware that tries to steal all your passwords from all your browsers
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:09 JST Foone🏳️⚧️
I am some kind of reverse engineer/security engineer but I'm not very good at it WHEN MY BRAIN DOESN'T WORK
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:08 JST Foone🏳️⚧️
huh, one of the things it does is check your RAM speed.
I think because that's a thing real computers have, and it's trying to do a roundabout VM check?
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:07 JST Foone🏳️⚧️
it even checks against OllyDbg, a really great debugger that hasn't updated in 11 years
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:07 JST Foone🏳️⚧️
but yeah it does a bunch of checks to see if anything remotely debuggy or VMy is running or even installed, then refuses to do stuff
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:06 JST Foone🏳️⚧️
I'm looking at this disassembly from dez_ on twitter.
https://gist.github.com/joe-desimone/64b3c1044c184ffc8f26090d7bcd32b5
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:05 JST Foone🏳️⚧️
yes let me accidentally try to unpack the electron app in poland, that's exactly the kind of protection I need: geographic protection
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:05 JST Foone🏳️⚧️
there's a lot of very specific checks before it tries to do anything, I think this has been carefully designed to appear innocuous to the commonly used online sandboxes. like, it detects if it's running on virustotal and throws an error, instead of doing anything sneaky-deaky
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:04 JST Foone🏳️⚧️
god I bet there are some malware out there that checks your location on GPS before running, and errors out if you're too close to Known Antivirus companies
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:03 JST Foone🏳️⚧️
OH GOOD this is a different version that uses aes compression. so the source isn't just obfuscated, it's actually encrypted.
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:03 JST Foone🏳️⚧️
sure there's work-from-home, but you're probably still within a reasonable driving distance of the office. they could just blacklist the entire metropolitan area
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:02 JST Foone🏳️⚧️
I hope these fuckers aren't trying to obfuscate the password by abusing javascript scoping
In conversation from digipres.club permalink